Code Review
Your application runs. The question is what happens when the first paying customer puts real data into it, when the tenth feature arrives, or when somebody else has to work on it.
With AI, what used to take months now takes weeks. What does not come with it is the outside view: whether the architecture still holds as the application grows, whether sensitive data sits where it belongs, whether anyone will still understand the code in six months. We look at your application as a whole and tell you what is solid, what needs attention, and what should be fixed first.
The result is not an assessment for the drawer, but a list you can work through. Either on your own or with us.
Who it is for
Founders who want their prototype checked before the first paying customer arrives
Established companies that need an independent second opinion on a new platform or application
Teams that started without proper version control and want to put that right
Anyone taking over an existing application who wants to know what they are getting into
What we review
Five perspectives on the same codebase. Each one surfaces things the others do not see.
-
01.
Repository and version control
The basis for everything else. Without a clean history, nothing can be traced or rolled back.
- Setting up a Git repository or reviewing your existing setup
- Branching model and commit history
- Credentials and keys that ended up in the code by accident
- Dependencies, lockfiles and reproducible installation
- The documentation a new developer needs to get started
-
02.
Architecture
Whether the structure holds as the application grows, or falls apart with the next feature.
- Layering and separation of concerns
- Data model and relationships
- Dependencies between modules and external services
- Bottlenecks to expect under more load or more data
- Decisions that become expensive to correct later
-
03.
Security
The questions rarely asked while building, and the ones that count in production.
- Authentication, sessions and access rights
- Input validation and protection against injection
- Handling of personal data under the revised Swiss FADP
- Libraries with known vulnerabilities
- Configuration of environments, secrets and interfaces
-
04.
Code quality and maintainability
Whether a human other than the original author and the AI can carry on with it.
- Readability, structure and recurring duplication
- Error handling and logging
- Existing tests and the places where they are missing
- Code that never runs or was left over from experiments
- Consistency of the patterns in use
-
05.
Operations and deployment
The path from a development state to a server someone can actually operate.
- Separation of development, staging and production
- Deployment process and traceability
- Backups and restore
- Monitoring and error notification
- What is still missing for production use
How we review
We run several specialised AI analyses across the codebase, each with its own focus: security, architecture, code quality. That covers in hours what manual reading would take days to do, and it finds patterns across the entire project rather than only in the files someone happened to open.
The judgement is then ours. Automated analysis reports plenty that is technically correct but practically irrelevant, and it misses connections you only see with knowledge of the business case. What you receive is sorted by urgency and reasoned, not a raw dump of 400 warnings.
Fixed price
Basic check
CHF 1’500
Per repository, plus VAT.
A clearly defined entry package. You know the cost beforehand, and where you stand afterwards.
- Setting up a Git repository or cleaning up your existing one
- Baseline architecture check across the whole application
- AI-assisted analysis of security, architecture and code quality
- Assessment and prioritisation of the findings by our team
- Report as a PDF you can pass on
- Findings as issues in the repository, ready to work through
- Walkthrough of the report with you or your team
The fixed price covers one repository and one application. For multiple repositories, monorepos or very large codebases we look at the scope first and quote accordingly. Fixing the findings is not included and is agreed separately.
Request a basic checkHow it works
From the first enquiry to a list you have talked through.
-
01.
First conversation
You tell us what you have built, with what, and where it is meant to go.
- A quick look at technology and scope
- Clarifying whether the fixed price fits or a quote is needed
- Agreeing on confidentiality, with an NDA if you prefer
-
02.
Access and repository
We bring your code into a shape that can be worked with professionally.
- Taking over your existing repository or setting up a new one
- Establishing structure, branches and documentation
- Getting the environment running in a reproducible way
-
03.
Analysis
Several passes across the codebase, followed by our own assessment.
- Automated analysis passes with different focuses
- Manual review of the critical areas
- Prioritisation by urgency and effort
-
04.
Report and walkthrough
You receive the findings and we go through them together.
- Report as a PDF with findings and recommendations
- Findings as issues in the repository
- A conversation about how to proceed, with the decision staying yours
Frequently asked questions
What does a code review cost?
The basic check costs CHF 1’500 per repository, plus VAT. That covers setting up or cleaning the repository, the architecture check, the analysis and assessment, the report as a PDF and the walkthrough with you.
The price applies to one application in one repository. If you come with several repositories, a monorepo or a very large codebase, we look at the scope beforehand and send you a quote. Fixing the findings is not part of the fixed price.
Who owns the repository?
If you already have a repository, it is yours and it stays with you. We work inside it and file the findings as issues in your own repository. The question does not arise.
If you do not have a repository yet, we set one up on our side. You are welcome to keep working in it, provided we continue together. If you would rather not, we provide a full export on request so you can set the repository up yourself. Your code remains your code either way.
Is this a penetration test?
No. We review the code, the architecture and the configuration, we do not attack your running system. A code review finds different things than a penetration test and does not replace one.
Nor is it a certification. What we deliver is a professional assessment of the state of your application as reviewed. If you need a formal security attestation, we will say so and point you to the right route.
How long does it take?
That depends on the scope and the state of the codebase. After the first conversation and an initial look at the code, we give you a concrete date.
In practice, the time between getting access to the code and walking through the report is a manageable number of working days, not weeks.
What happens after the review?
You decide. The findings sit as issues in the repository, written so that a developer can work through them, whether that is us, your own team or somebody else.
In most cases we take on the most important fixes straight away, because by then we know the code. That is agreed separately on a time and materials basis, as is any further development or hosting.
Which technologies do you review?
The ones we develop in ourselves: PHP and Laravel, JavaScript and TypeScript, Node, the common frontend frameworks, WordPress, Shopware, Contao and Statamic, along with the usual database and interface landscape around them.
If you come with a stack where we cannot give you a reliable assessment, we say so before the engagement, not after.
Do we have to disclose our code?
We need access to the code, otherwise there is nothing to review. That access is confidential, used solely for the review, and revoked afterwards on request.
We are happy to sign a non-disclosure agreement, including before the first conversation. Discretion is part of the service here, not a surcharge.
Get in touch.
Tell us what's stuck or what you want to build. You'll reach someone who knows the answer, not a switchboard.