Production Readiness Review
Someone has to say whether you can launch.
The audit hands you findings and leaves the decision where it belongs, with you. This is the other thing. I test the system, talk to the people who depend on it, and write down an answer.
from €1,800 + VAT. It starts with a call, because a scope this size cannot be settled by a form.
The answer
There is no fourth answer.
Not a score out of ten, and not a colour. A number that stands in for a decision lets everyone avoid making it.
Ready
No known blockers inside the agreed scope, the critical flows verified to the depth they warrant, and enough detection in place that you would find out if something broke.
Ready with conditions
You may proceed once named actions are done, or once you have knowingly accepted a specific risk for a stated period. The conditions are written down, and so is who accepted them.
Not ready
There is plausible material risk to data, access, revenue, or your ability to recover and investigate. This is the answer nobody wants and the one worth paying for.
This answer exists here and nowhere else I sell. The audit reads code and reports what it finds; deciding whether a business can depend on the result takes testing the system and understanding the business, and that is a different piece of work.
How it is reached
Evidence, and where it came from.
Automated results are a starting point, not a finding. Anything I can confirm by hand, I confirm by hand. Anything you tell me is recorded as something you told me, and checked where checking is possible.
Nothing is tested actively without your written authorisation, the limits of what was covered are stated in the report, and no part of it claims to be an exhaustive security assessment. Twelve domains are examined:
- Business context and consequence
- Architecture and ownership
- Identity and authorisation
- Data and privacy context
- Code, dependencies, supply chain
- Infrastructure and deploy
- Reliability and failure modes
- Observability and incident readiness
- Critical business flows
- Maintainability and AI change governance
- Recovery evidence
- Legal and commercial signals, short of legal advice
What you receive
A decision, and the paperwork behind it.
The verdict
Ready, ready with conditions, or not ready — with the reasoning that produced it.
An executive summary
Written for whoever has to act on it, including someone who does not read code.
Scope and limitations
What was examined, to what depth, and what was left unexamined.
Stack and ownership map
What the system is made of, and who is responsible for each part of it.
Critical flow map
The paths your business actually depends on, traced and tested.
Evidence summary
What was verified, how, and which claims are yours rather than mine.
Risk register and blockers
What stands between you and launching, separated from what can wait.
Accepted-risk record
Anything you choose to carry anyway, written down with your name against it.
A 30-day plan
Ordered by consequence, and sized to what you can actually do.
The review call
We go through it together, and you get to argue with it.
Whether it fits
When this is worth buying.
- A real application, or a launch inside the next thirty days.
- Material users, data, payments or integrations — something is at stake.
- Someone who can make the decision the Review informs.
- Access and written authorisation from a person entitled to give it.
- A consequence of failure that costs more than the Review does.
And when it is not
If losing would cost you less than the Review costs, do not buy it.
Most apps that are still finding their first users belong one rung down. Start with the audit at €350 + VAT, and the whole of it comes off a Review bought within thirty days, so nothing is wasted if you climb later.
Price
from €1,800
plus VAT · scoped before you commit
From €2,214 including VAT. EU businesses with a valid VAT number pay €1,800 — reverse charge.
What the entry band covers
One application on one main repository, production and staging where it exists, up to three critical flows, straightforward authentication and a couple of integrations.
Larger systems
Payments, multi-tenancy, material personal data, several services or custom infrastructure take longer and are quoted after the call. You see the number before you commit to anything.
Start here
Tell me what is launching.
Thirty minutes, no deck. I will tell you whether the Review is the right thing, and say so if it is not.