Service · IT consulting and audit

Systems and architecture review

Consider a dental practice in Ankara with three branches. Its web application for appointments, patient files and treatment plans was built years ago by a freelancer who has since moved abroad and taken on other work. It still runs, but people are afraid to change anything. The server is on a PHP release that no longer receives security fixes, patient X-rays live in a shared folder, and the owner now wants online booking, SMS reminders and a mobile app. Spending on new features before anyone has examined the foundations is a gamble. We take read-only access to software we did not write and tell you whether it can bear the planned growth, whether a different team could maintain it, and what bringing it up to standard would cost. Apply works fully remotely and leaves your environment exactly as it found it.

Build test
we try to stand the system up from its own documentation
Read-only
nothing changes on the live system
Cost per finding
rough euro estimate, VAT excluded
Two-page summary
for managers who don't code

What the work covers in practice

The review is organised around the questions that matter to you as the owner. Each section closes with a risk rating and a ballpark cost to put things right.

Agree the scope with the engineer who will do the work

Ownership and access

Who is the registered owner of the repository, the domain, the server and the hosting bill? Does the contract mention usage rights? We settle this before any technical work, since it shapes your leverage in every future negotiation.

Where the knowledge lives

Are set-up steps, environment variables and secrets documented? Could a new developer run the system on their own machine? We don't just ask; we try it ourselves, and every point where we get stuck goes into the report.

Security at first glance

How passwords are stored, whether permission checks happen on the server, whether the admin panel is reachable from the internet, and which packages carry known flaws. This is not a penetration test, but it tells you where a penetration test should focus.

Components going stale

PHP, Laravel, Node.js, database and operating system versions that are out of support or close to it, each with a date and a rough difficulty rating for the upgrade.

External connections

Links to iyzico, PayTR or a bank virtual POS, the SMS provider, the e-Fatura integrator and the accounting package. We pay special attention to timeouts, retries and transactions left half-finished when the other side fails to respond.

Readiness to grow

Do the planned features fit the current data model? Is there a usable API for a mobile app, or is everything buried inside the screens? Will backups, monitoring and logging cope with more users?

Patient and customer data

Where personal data and special category data such as health information are stored, whether it is encrypted, whether access is logged, and whether deletion and access requests under KVKK can be fulfilled technically.

How we approach the job, from first call to handover

The effort depends on the application's size and number of integrations, and we estimate it before work begins.

01

Scoping call

We agree the trigger for the review (a growth plan, a supplier change, an acquisition or plain unease), the priority questions and the list of access needed.

02

Build test

We pull the code from the repository and try to run it in a separate environment using only the existing documentation. This single step reveals more about handover risk than pages of commentary.

03

Examination and short interviews

Code, database schema, server configuration and logs are examined, and we hold brief video calls with the people who use or look after the system.

04

Findings meeting

Issues ranked by severity, a cost estimate for each and a recommended order of work. We go through the document with you on Teams or Google Meet and answer your questions.

A full rewrite is almost always the first thing a new team proposes. Wading through inherited code is tiresome; a greenfield project is exciting. Yet replacing a working system wholesale means rediscovering every business rule that accumulated over the years without ever being written down. We cost both options, and in most cases the smart choice is to replace the critical parts and harden what remains.

Frequently asked questions

That is the first thing to fix. If the code sits only in the previous developer's personal account, talk to your lawyer about the contract and formally request access. In the meantime we can do a narrower review based on the server, the database structure and the running application.

No. We look at security through architecture and code and do not attempt to attack the system. The report shows where a penetration test should concentrate, and that test is scheduled separately.

No. We change nothing in production and run heavy analysis against a copy of the code and database schema. If a load test is needed, it is planned on its own and only with your go-ahead.

That is your call: your current developer, a new team or Apply. The report is written so that it works as a task list whoever picks it up.

After the first video call and scoping, you get a quote built on €55 an hour plus VAT, showing the estimated effort.

Have your application independently assessed

Tell us about the software and what prompted the review. You get a report that ranks the risks from the most serious down to the harmless.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.