pt
services

Software, architecture and security audit

Code, architecture and infrastructure review that finds the failure nobody found: the race condition in the payment, the permission that leaks data, the backup that was never restored. From Toledo and Cascavel, for clients across Brazil and abroad.

What an audit finds

Across more than 600 projects the pattern never changed: the failure sits in a boundary someone trusted. The bank call that is not idempotent. The query that returns another customer's data when the filter is forgotten. The API key in the repository. The certificate that expires on a Saturday. The job that runs twice. The password stored wrong. The server nobody has updated since 2019.

None of these is exotic. All are found by method: read the code where money and data pass, follow every boundary, test what happens when the network fails halfway, and check whether what the documentation says is what the infrastructure does.

Scope

Code audit: quality, security, error handling, concurrency, dependencies. Architecture audit: boundaries, data, scalability, single points of failure. Infrastructure audit: servers, cloud, network, backups, secrets, access, updates. Application security audit: authentication, authorisation, injection, data exposure, headers, configuration. One of them or all of them.

What you receive

A written report with each finding, the evidence, the impact, the likelihood and the recommended fix, ordered by priority. A read-through meeting with the team. And, if you want, follow-up on the fixes until each item is closed. No automated tool presented as an audit: tools help, but the failure that matters is found by someone who reads.

When to do it

Before a launch that cannot fail. After an incident, to understand the cause and what else is waiting to happen. Before buying or investing in a company whose value is in its software. When the team changed and nobody knows what the system does any more. Or once a year, as maintenance, which is what companies that sleep well do.

Frequently asked questions

How long does a software audit take?

One to four weeks, depending on system size and scope. An application security audit of a medium system takes around two weeks, with the report at the end.

Does the audit stop the system or operations?

No. It is done in read-only and staging environments. Nothing is changed in production without authorisation, and tests that could have impact are agreed beforehand.

Do you audit systems you did not build?

That is the normal case. An audit is for the system the company already has, built by whoever built it, including vendors who are no longer around.

Does it help with data protection compliance (LGPD, GDPR)?

The technical audit shows where personal data is, who accesses it, how it is protected and where it leaks, which is the part of compliance that depends on engineering. The legal part stays with your lawyer, and the report gives them a base.

Let us talk

Describe the system, the problem and the deadline. I reply within one business day.

write to me contato@fgxdev.com

Other lines of work