We start cold, before asking anyone anything: clone it, build it, run the tests, try to make a
small change. That first hour is the only chance to see the system the way a new engineer would,
and how long it takes to make a safe change is one of the clearest signals there is.
Then the evidence. Commit and review history, whether the tests actually catch anything,
dependency and security posture, where change concentrates, and whether it can be deployed and
rolled back. Every finding cites something your own team can go and check — you’re trusting
our reading, so the reading has to be verifiable.
You get a report that leads with what’s working, states each risk with its cost of inaction in
business terms, and closes with the questions worth asking next. Then a live session to talk it
through. If you want the findings fixed, that’s a separate quote from the same list, and your
team is welcome to do it instead.