Then the acquirer’s introduction email arrived on a Tuesday. The technical review was 6 weeks out. Felix had 6 weeks to produce something he could walk an external CTO through. He didn’t have a single ADR. He didn’t have a system diagram. He had a Notion page from 2022 with eight bullet points and the words “TBD: revisit”.
Software architecture services that survive. Series A diligence.
For UK founders facing a Series A diligence call, an acquirer’s technical review, or a senior hire inheriting the codebase. 5-day audit, thirty-page brief, six ADRs — in your inbox by Friday.
Your codebase grew because the product worked. Now it has to defend itself when someone senior reads it.
Forty-seven independent software architecture audits since 2019. Three Series A and acquirer reviews passed in 2025 on the back of one written brief. Same cadence every time: NDA Monday morning, brief Friday afternoon.
0
0
5days
Felix runs a B2B SaaS. Eight engineers. Three good years. No documented architecture, because nobody had needed it yet.
We ran the 5-day audit. Read the codebase on day one. Drew the system diagram on day two. Mapped fourteen historic architectural decisions, six of which we’d quietly revise. Drafted seven ADRs by Thursday. Wrote the thirty-page brief on Friday.
Felix presented it in week two of the diligence call. The acquirer’s CTO read it once and stopped asking process questions. This page is for the founder who recognises Felix’s Tuesday.
NDA Monday. Brief Friday.
One senior architect, 5 working days, the same rhythm every time. Read the codebase first, draw the system, dig up the decisions nobody wrote down, then write the brief your acquirer or seed lead actually opens.
Read the codebase
Day one is read-only repo access and a 45-minute kick-off. We read the code before we say a word about it, no write access, ever.
Draw the system diagram
Day two we draw the one-page system diagram, printable, with Excalidraw source. The artefact a senior engineer reads first.
Decision archaeology + ADRs
Day three we surface the decisions nobody wrote down, why this DB, why this queue, why this auth, then draft six ADRs minimum in markdown.
Threat model + scale model
Day four runs STRIDE on the top eight abuse patterns and models what breaks first at 10× current load, then prices the costed fix list.
The 30-page brief, Friday
Day five we write the 30-page brief and record the walkthrough. In your inbox by Friday afternoon, the document your seed lead asked for.
The question on the left. What the audit tells you on the right.
Each one is the difference between an architecture you can defend on a diligence call and a Notion page from 2022.
- 01
“An acquirer’s CTO is reading the codebase next month. We have no architecture document.”
The written brief is the document they ask for. 30-page brief Friday. One-page diagram. Six ADRs. Threat model. Three Series A and acquirer reviews passed in 2025 on exactly this output.
- 02
“The seed lead wants technical due diligence. We don’t know what they actually want to see.”
The brief doubles as the diligence pack. Architecture diagram, ADRs, DPA, threat model. Most seed and Series A leads ask for exactly these four. The audit ships all four in the format they prefer.
- 03
“We hired eight engineers. None of them feel senior enough to make architectural calls.”
External senior architect for 5 days, then optional retainer. The audit gives you a written architecture you can defend. The optional retainer gives you a senior voice on weekly engineering calls while your first principal hire ramps up.
- 04
“Three years of growth. No documented decisions. We don’t know what’s reversible and what’s load-bearing.”
Day 2 is decision archaeology. We surface the decisions nobody wrote down. Why this DB. Why this queue. Why this auth. Ranked by impact. The next engineer knows where to step carefully.
- 05
“We have a CTO. We want an external senior voice to validate the architecture before we commit to a rebuild.”
Independent written brief, no rebuild agenda. Roughly a third of our audits end with “the architecture is fine, here are six small improvements”. Your CTO gets the second voice. You get the written validation.
- 06
“Our new CTO starts in a month. We want them to walk into something documented, not a Notion page from 2022.”
The brief is the onboarding document. 30-page brief, diagram, ADRs. Your CTO reads it on day one, asks targeted questions in week one, and makes their first architectural call by week three.
- 07
“SOC-2 (or ISO 27001) audit starts in eight weeks. We need an architecture story that matches our security controls.”
SOC-2 / ISO 27001 readiness pack in the brief. Architecture brief mapped to controls. RBAC matrix. Audit log policy. Data residency. Read alongside Vanta or Drata evidence, SOC-2 becomes paperwork, not a six-month panic.
- 08
“We’re considering a six-month re-architecture. We want to know if it’s worth it before we commit.”
Cost-of-rebuild model + alternative path. Day 4 prices the rebuild against the alternatives. Surgical fixes that achieve 80% of the benefit. The full rebuild’s real cost in engineering months. The risk of doing nothing.
Six artefacts a senior engineer recognises
Not a sixty-slide deck. The documents your acquirer’s CTO actually opens,
written in the format they’d have asked you to produce.
One-page system diagram
Printable, with Excalidraw source. It lives in your repo, not a slide on a drive. The artefact a senior engineer reads first and respects.
Six ADRs minimum, drafted
Architecture decision records written in markdown, ready to commit. Context, decision, consequences, status. Your team reviews, you own the words.
Threat model on eight patterns
STRIDE on the top eight abuse patterns your product faces. The vulnerabilities ranked by impact, documented in the brief, with the same-hour call if we find one mid-week.
10× scale model
What breaks first at ten times current load. The capacity number that goes straight into your runbook, not a hand-wave about scaling later.
Prioritised fix list, costed
Critical, High, Medium, Low. Effort in GBP and engineering days. You commit on data, not optimism, and your CFO sees one number.
SOC-2 / ISO 27001 readiness pack
Architecture mapped to controls. RBAC matrix, audit log policy, data residency, UK GDPR + DPA pack. Read alongside Vanta or Drata, compliance becomes paperwork.
The tools we audit with. The patterns we look for.
GitHub and Sourcegraph for reading. Excalidraw and Mermaid for diagrams. STRIDE for threat modelling. ADRs committed to your repo, not a deck on a drive.
What we audit with on every project
read + documentStacks we audit fluently
read on sightThe cloud + infra we audit against
AWS-defaultThe decisions we pressure-test
5 days, read-only access, one written brief. These are the load-bearing calls we surface, document, and rank by impact before your acquirer’s CTO ever asks.
47
Independent audits since 2019
3
Series A and acquirer reviews passed in 2025
“The acquirer’s CTO read it once, asked seven targeted questions, and approved the technical pillar on the same call.”
Why this database
The data store nobody re-evaluated since year one. We surface why it was chosen, whether it still fits, and what it costs to change. Reversible or load-bearing, ranked by impact.
Why this queue
The messaging and async layer that grew organically. We document the call, what it guarantees, and where it leaks under load, so the next engineer knows where to step carefully.
Why this auth
Identity, sessions, and permissions, written into an RBAC matrix. The decision your seed lead checks first and the one most teams cannot explain in a diligence call.
The threat model
STRIDE on the top eight abuse patterns. The vulnerabilities ranked by impact, with the same-hour call if we find a critical one mid-week, not a surprise on Friday.
The scale model
What breaks first at 10× current load and the cost of the surgical fix against a full rebuild. The capacity number goes straight into your runbook.
Felix’s architecture audit,
in real numbers, before the diligence call
Brief: produce the architecture brief, ADRs, and diagram for an acquirer’s technical review 6 weeks out. Audit ran Monday to Friday. Felix presented in week two. The acquirer’s CTO read it once, asked seven targeted questions, approved the technical pillar on the same call.
The audit
The diligence
Track record
What CTOs and founders actually ask before booking the audit
Pain-first, soft-second.
Roughly a third of our audits end with “the architecture is fine, here are six small improvements”. We don’t sell rebuilds we don’t recommend. The architecture review service is independent. If a rebuild is the right answer, we price it honestly against the surgical alternative. If it isn’t, we say so in writing.
5 days of senior architectural attention on your codebase. One-page system diagram. Six ADRs drafted. Threat model on the top eight abuse patterns. Scale model at 10× current load. SOC-2 / ISO 27001 readiness checklist. UK GDPR + DPA pack. A 30-page written brief. Live walkthrough recorded for your acquirer or seed lead. You can walk away after the audit, and about a third of our clients do exactly that.
In three Series A and acquirer reviews in 2025, yes. The brief is written in the format the external CTO opens: architecture diagram, ADRs, threat model, sub-processor list, SOC-2 readiness checklist. The same artefacts they’d have asked you to produce, written by senior engineers who’ve sat through diligence calls. Felix’s acquirer read it once, asked seven targeted questions, approved the technical pillar on the same call.
Two hours of your team’s time across the week, total. Day 1 kick-off (45 minutes). Day 2 quick chat on undocumented decisions (30 minutes). Day 5 walkthrough (45 minutes). The rest is us reading your codebase. We work from read-only repo access, never write access. Your customers don’t notice a thing.
Yes. After the audit you can run a senior-architect retainer at £5K-10K a month: a principal-level voice on your weekly engineering calls, ADRs maintained, architecture reviewed. Cancellable any month with 30 days’ notice both ways. Most clients run it 6-12 months while their first principal-level hire ramps up.
That’s the best time to book it. Founders who run the audit before the diligence call walk into the meeting with the brief in hand. Timelines shorten. Seed leads ask for the architecture document and you already have it. We’d rather you have it before the question gets asked.
You hear about it the day we find it, not on Friday in the report. If there’s a critical security vulnerability, an active data leak, or a payment flow that’s losing money, we call you the same hour. The written brief documents it. The on-the-day call lets you start fixing it.
Yes, before anything else. NDA signed inside 30 minutes via DocuSign. Mutual NDA template ready. We only need read-only repo access for the audit. We never request write access, and we won’t open a PR against your code during the audit week. We’ve never published or shared a client brief, ever.

See it in context.
A look at the kind of software architecture services surface we hand over — real screens, real data, documented and yours from day one.
One paragraph. That’s it.
Tell us when the diligence call is, what your acquirer or seed lead has asked for, and where the codebase lives. Mohit replies inside 24 hours: a clear yes, a clear no, or the one question that decides it.
- < 24h
A personal reply.
Yes, no, or the deciding question. Straight to your inbox.
- Mon
NDA signed, audit starts.
DocuSign inside 30 minutes. Read-only repo access. We read the codebase day one.
- Fri
Brief in your inbox.
30-page brief, one-page diagram, six ADRs, prioritised fix list. Walkthrough recorded.