Discovery audit
A fixed-scope audit, with a written findings document
This is the low-risk first step, and the one I recommend for almost everyone. I read the codebase and the infrastructure around it, map how it’s put together, and grade what’s there: architecture, maintainability, test coverage, data security, deployment, and the operational process around all of it.
You get a written document, addressed to you, that says what’s sound, what’s risky, and what I’d fix first and why. If the codebase turns out to be in good shape, the document says so. That’s a perfectly good outcome, and I’ll tell you if it’s the one you have.
The audit is fixed in scope, so you know what it costs before it starts, and it gives us both a clear picture before deciding whether there’s a larger piece of work to do.