Consider a dental practice in Ankara with three branches. Its web application for appointments, patient files and treatment plans was built years ago by a freelancer who has since moved abroad and taken on other work. It still runs, but people are afraid to change anything. The server is on a PHP release that no longer receives security fixes, patient X-rays live in a shared folder, and the owner now wants online booking, SMS reminders and a mobile app. Spending on new features before anyone has examined the foundations is a gamble. We take read-only access to software we did not write and tell you whether it can bear the planned growth, whether a different team could maintain it, and what bringing it up to standard would cost. Apply works fully remotely and leaves your environment exactly as it found it.
we try to stand the system up from its own documentation
Read-only
nothing changes on the live system
Cost per finding
rough euro estimate, VAT excluded
Two-page summary
for managers who don't code
What the work covers in practice
The review is organised around the questions that matter to you as the owner. Each section closes with a risk rating and a ballpark cost to put things right.
Who is the registered owner of the repository, the domain, the server and the hosting bill? Does the contract mention usage rights? We settle this before any technical work, since it shapes your leverage in every future negotiation.
Where the knowledge lives
Are set-up steps, environment variables and secrets documented? Could a new developer run the system on their own machine? We don't just ask; we try it ourselves, and every point where we get stuck goes into the report.
Security at first glance
How passwords are stored, whether permission checks happen on the server, whether the admin panel is reachable from the internet, and which packages carry known flaws. This is not a penetration test, but it tells you where a penetration test should focus.
Components going stale
PHP, Laravel, Node.js, database and operating system versions that are out of support or close to it, each with a date and a rough difficulty rating for the upgrade.
External connections
Links to iyzico, PayTR or a bank virtual POS, the SMS provider, the e-Fatura integrator and the accounting package. We pay special attention to timeouts, retries and transactions left half-finished when the other side fails to respond.
Readiness to grow
Do the planned features fit the current data model? Is there a usable API for a mobile app, or is everything buried inside the screens? Will backups, monitoring and logging cope with more users?
Patient and customer data
Where personal data and special category data such as health information are stored, whether it is encrypted, whether access is logged, and whether deletion and access requests under KVKK can be fulfilled technically.
How we approach the job, from first call to handover
The effort depends on the application's size and number of integrations, and we estimate it before work begins.
01
Scoping call
We agree the trigger for the review (a growth plan, a supplier change, an acquisition or plain unease), the priority questions and the list of access needed.
02
Build test
We pull the code from the repository and try to run it in a separate environment using only the existing documentation. This single step reveals more about handover risk than pages of commentary.
03
Examination and short interviews
Code, database schema, server configuration and logs are examined, and we hold brief video calls with the people who use or look after the system.
04
Findings meeting
Issues ranked by severity, a cost estimate for each and a recommended order of work. We go through the document with you on Teams or Google Meet and answer your questions.
A full rewrite is almost always the first thing a new team proposes. Wading through inherited code is tiresome; a greenfield project is exciting. Yet replacing a working system wholesale means rediscovering every business rule that accumulated over the years without ever being written down. We cost both options, and in most cases the smart choice is to replace the critical parts and harden what remains.
Frequently asked questions
That is the first thing to fix. If the code sits only in the previous developer's personal account, talk to your lawyer about the contract and formally request access. In the meantime we can do a narrower review based on the server, the database structure and the running application.
No. We look at security through architecture and code and do not attempt to attack the system. The report shows where a penetration test should concentrate, and that test is scheduled separately.
No. We change nothing in production and run heavy analysis against a copy of the code and database schema. If a load test is needed, it is planned on its own and only with your go-ahead.
That is your call: your current developer, a new team or Apply. The report is written so that it works as a task list whoever picks it up.
After the first video call and scoping, you get a quote built on €55 an hour plus VAT, showing the estimated effort.
Availability Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls By video, over Microsoft Teams or Google Meet
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
Filling the gaps. If we need more information to judge the job, we send questions by email or propose a quick Teams or Google Meet call.
A written quote. It lists the scope, a euro price excluding VAT and a realistic start date. No hidden clauses, no items that appear later.
Your decision. The quote arrives by email. Take whatever time you need, raise questions on any line, and decide when you are ready.
Where are you based?
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.