Products
What do you need to know about this codebase?
One audit, twelve answers — for pre-deal diligence, the hold period, and preparing an exit. Pick the question, or read the estate end to end.
Codebase
Is it worth what you are paying?
How maintainable the code is, what it costs to fix, and how much growth the architecture carries.
- Code qualityIs this code maintainable — or expensive to own?63 / 100health score, above peers on 5 of 7
- Technical debtWhat it costs to fix this codebase$106kto bring the code up to standard
- ArchitectureHow much growth can this architecture carry?Tier 2 of 5one repository holds the estate back
- Estate mapWhich system can the business not run without?4 systemsstop when ledger-core fails
Security
What risk comes with it?
Verified vulnerabilities in the code, in the open-source packages it ships, and in their licences.
- Application securityWhich security risks are real — and what it takes to close them7Critical or High findings, about 41h to close
- SBOM & dependenciesWhich open-source packages put this product at risk1 Criticalknown CVE, about 5 days to patch all 15
- LicencesCan this product be shipped — and sold — as it is?1 licencenot identified, still unpriced risk
Team & delivery
Can this team carry the plan?
Where engineering effort goes, how safely the team ships, and who holds the knowledge.
- Development activityIs engineering building the future — or keeping the past alive?38%of engineering effort on new product
- Delivery (DORA)Can this team ship the plan?4.2 / weekproduction deploys, High on DORA bands
- Team & key-person riskWho holds the knowledge — and what if they leave?94%of the code written by one person
AI due diligence
Is the AI story real?
How much AI is in the product, and how much of the code AI wrote without a review.
One platform
One audit, not twelve tools.
Every view reads the same audit of the same estate — every repository in scope — so the numbers agree with each other. The Advisor answers across them: which Critical findings sit in code one engineer owns, or whether the debt went down since the last audit.
Across the investment cycle
Where to start
Pre-deal tech DD
Application security, Technical debt, and Team & key-person risk — the exposure, the cost to fix, and the people the code depends on.
Hold period
Delivery (DORA), Development activity, and Technical debt over time — whether the plan is landing, audit after audit.
Pre-sale preparation
SBOM, Licences, and Code quality — close what a buyer's diligence would find before the data room opens.
FAQ
Questions
Do I buy these products separately?
No. They are views of one CodeDD audit, not separate licences. Pay Per Audit, Portfolio Monitoring, and Enterprise are described on Pricing.
How long does an audit take?
An estate is analysed in hours, not weeks. Delivery metrics then stay current from a daily Git sync.
Does CodeDD keep our source code?
No. In a cloud audit, scoped source is analysed and then overwritten; CodeDD keeps structured results. The audit can also run in your own environment.
See all twelve views on a codebase you are evaluating
Run it on a repository yourself, or book a walkthrough of the estate end to end.