Architecture Audit | A senior look at your platform | Concept to Cloud

Assessment · Cloud-Native & Open Source

Where your platform actually stands.

The Tech Risk Scorecard is you scoring yourself in twenty minutes. The Architecture Audit is a senior engineer going into the real system and telling you what a self-score cannot: where the risk actually is, how bad it is, and what to fix first. A thorough look across the whole platform, handed back as a recorded walkthrough of the findings and a written report ranked by impact.

From $8,000 · 2 to 3 weeks · Recorded walkthrough + ranked report

Where it sits

Between the self-score and the full assessment.

Most teams don’t need a $50K engagement to know where they stand. The Audit is the senior look in the middle: deep enough to trust, scoped enough to move on.

Free · 20 min

Tech Risk Scorecard

Self-serve, in your browser. Where the risk might be.

From $8K · 2-3 wks

Architecture Audit

A senior engineer, deep in your system. Where the risk is, ranked, with the walkthrough and the report.

From $50K · 4-6 wks

Technical Assessment

The full deep dive, the whole team interviewed, a board-ready remediation plan.

Built on open foundations

Fluent in the stack you actually run.

Most of the platforms we audit stand on the same open foundations we do: Kubernetes and the cloud-native tooling around it, Prometheus, Argo, OpenTelemetry, and Kubeflow among them, and Apache projects like Spark, Kafka, Arrow, and Calcite. We don’t just recognise them. We build with them, and we contribute back: Tom served as VP of Apache OODT at the Apache Software Foundation and founded the open-source analytics platform Saiku.

We come in and find the holes

Where your cloud-native or open-source stack is misconfigured, mis-sized, or leaning on a component past what it was built for. The failure modes that only show up when you know a project’s internals, not just its docs.

Then we fill them at the source

Not a brittle workaround. Because we work inside these communities, we can tell whether the fix belongs in your code, in a setting you didn’t know existed, or upstream in the project itself, and work with the foundation to get it filled properly, for you and everyone downstream.

What we look at

Six dimensions, honestly.

The same six dimensions the scorecard scores, worked through by a person who has built and rescued platforms across NASA-grade and regulated systems. The method is an ATAM-style trade-off analysis, benchmarked against the CNCF cloud-native maturity model where that is the bar you are building toward.

Key-person dependency

What only lives in one person’s head, which systems have no second owner, and what happens to delivery the week they are on leave.

Architecture & headroom

Where the design still has room to grow and where it is already fighting itself. The decisions that will cost the most to unwind later.

Delivery & change safety

How safely a change reaches production: tests, review, rollout, the blast radius of a bad deploy, and how long a fix actually takes.

Resilience & operations

What breaks under load or failure, what the team sees when it does, and whether recovery is a runbook or a scramble.

Security & compliance posture

The exposed surface, the data paths that carry PII, and the audit-trail and residency questions a regulator, an auditor, or a big customer’s security team will raise.

Data & economics

Where the data model is holding you back, and where the cloud bill is quietly scaling faster than the business underneath it.

How it runs

Low lift for you. Senior time on us.

What you send

View-only access to the code and infrastructure (or a sandbox), time with the people who built and run it, and a short brief on what you want the audit to answer. Diagrams if you have them; we draw them if you don’t.

What we do

Two to three weeks of senior time: the system diagrammed as it stands and modelled against your load and your plans, the security surface, data-residency, and audit-trail impact examined alongside the technical work, all across the six dimensions.

What you leave with

A recorded walkthrough of the findings, the system diagrammed as it actually is, and a written report ranked by risk and impact, with the trade-offs and the sequencing that keeps the team shipping while you act on it. Board-ready, yours to keep.

Who it’s for

When you need the truth before you commit.

Founders and CTOs

You inherited or grew a platform fast and want an honest senior look before you scale it, or before someone else takes one for you.

New in the seat

You just took over the platform, or a new engineering lead did, and you want a fast, honest map of what you’ve actually inherited before you start changing it.

Weighing a big change

A replatform, an AI initiative, a scaling push. The Audit examines the platform as it is and models the change against it before you commit the quarter.

Questions you’ll probably ask first

How is this different from the free Tech Risk Scorecard?

The scorecard is you scoring yourself in twenty minutes across the six dimensions. The Architecture Audit is a senior engineer spending two to three weeks in the real system: reading the code, modelling the architecture against your load and your plans, and testing the claims the self-score has to take on trust. The scorecard is a good place to start, and it makes the audit sharper.

And how is it different from the $50K Technical Assessment?

The Assessment is the full four-to-six-week engagement: the whole team interviewed, a risk register aligned to your compliance framework, and a board-ready remediation plan. The Audit is the focused version when the question is narrower: go through the platform, rank the risk, and model the change you are weighing, in two to three weeks rather than six. Most teams start with the Audit and only escalate if it surfaces something worth the deeper engagement.

What if the gap is in an open-source project we depend on?

Then you are in the right hands. We build with and contribute to the cloud-native and Apache projects most platforms stand on, so instead of a brittle workaround we can often get the fix into a configuration, an extension, or the project itself, working with the foundation on your behalf. The gap closes for you, and for everyone downstream.

Do we need architecture diagrams to send you?

No. Diagrams help if you have them, but a verbal walkthrough and view-only access to the code and infrastructure are enough. Part of what you get back is the system diagrammed as it actually is, which is often the first time anyone has seen it drawn accurately.

Who runs it, and is it remote?

A senior engineer, remote, and the findings come back on a recorded walkthrough so your team can replay the reasoning rather than rely on notes. No junior hand-off, no questionnaire farmed out to a tool.

What if you find something that needs real work?

You leave with the ranked report either way; the audit is the deliverable, not a sales funnel. If the fix is bigger than a report, we will say so and scope it honestly. If we are not the right team for it, we will point you to who is.

A senior look, before you commit.

Tell us what the platform is and what you’re worried about. If the Audit is the right call, we’ll scope it; if the free scorecard or the deeper assessment fits better, we’ll say so.

Book an Architecture Audit

From $8,000 · 2 to 3 weeks · Yours to keep