Service Software architecture services · 5-day audit + ADR pack · UK

Software architecture services that survive. Series A diligence.

For UK founders facing a Series A diligence call, an acquirer’s technical review, or a senior hire inheriting the codebase. Five-day audit, thirty-page brief, six ADRs — in your inbox by Friday.

47architecture audits since 2019
3Series A + acquirer reviews passed 2025
5day audit window
(Why founders book)

Your codebase grew because the product worked. Now it has to defend itself when someone senior reads it.

Forty-seven independent software architecture audits since 2019. Three Series A and acquirer reviews passed in 2025 on the back of one written brief. Same cadence every time: NDA Monday morning, brief Friday afternoon.

0

0

5days

The founder this page is for6 weeks to diligence · 0 ADRs · approved first call

Felix runs a B2B SaaS. Eight engineers. Three good years. No documented architecture, because nobody had needed it yet.

01

Then the acquirer’s introduction email arrived on a Tuesday. The technical review was six weeks out. Felix had six weeks to produce something he could walk an external CTO through. He didn’t have a single ADR. He didn’t have a system diagram. He had a Notion page from 2022 with eight bullet points and the words “TBD: revisit”.

02

We ran the five-day audit. Read the codebase on day one. Drew the system diagram on day two. Mapped fourteen historic architectural decisions, six of which we’d quietly revise. Drafted seven ADRs by Thursday. Wrote the thirty-page brief on Friday.

03

Felix presented it in week two of the diligence call. The acquirer’s CTO read it once and stopped asking process questions. This page is for the founder who recognises Felix’s Tuesday.

ADR-first since 2019
The five-day audit cadence

NDA Monday. Brief Friday.

One senior architect, five working days, the same rhythm every time. Read the codebase first, draw the system, dig up the decisions nobody wrote down, then write the brief your acquirer or seed lead actually opens.

Step-01

Read the codebase

Day one is read-only repo access and a 45-minute kick-off. We read the code before we say a word about it, no write access, ever.

Step-02

Draw the system diagram

Day two we draw the one-page system diagram, printable, with Excalidraw source. The artefact a senior engineer reads first.

Step-03

Decision archaeology + ADRs

Day three we surface the decisions nobody wrote down, why this DB, why this queue, why this auth, then draft six ADRs minimum in markdown.

Step-04

Threat model + scale model

Day four runs STRIDE on the top eight abuse patterns and models what breaks first at 10× current load, then prices the costed fix list.

Step-05

The 30-page brief, Friday

Day five we write the 30-page brief and record the walkthrough. In your inbox by Friday afternoon, the document your seed lead asked for.

The eight questions a software architecture consultant answers

The question on the left. What the audit tells you on the right.

Each one is the difference between an architecture you can defend on a diligence call and a Notion page from 2022.

  1. 01
    Acquirer interestAudit answer

    “An acquirer’s CTO is reading the codebase next month. We have no architecture document.”

    The written brief is the document they ask for. 30-page brief Friday. One-page diagram. Six ADRs. Threat model. Three Series A and acquirer reviews passed in 2025 on exactly this output.

  2. 02
    Seed lead diligenceAudit answer

    “The seed lead wants technical due diligence. We don’t know what they actually want to see.”

    The brief doubles as the diligence pack. Architecture diagram, ADRs, DPA, threat model. Most seed and Series A leads ask for exactly these four. The audit ships all four in the format they prefer.

  3. 03
    No internal architectAudit answer

    “We hired eight engineers. None of them feel senior enough to make architectural calls.”

    External senior architect for 5 days, then optional retainer. The audit gives you a written architecture you can defend. The optional retainer gives you a senior voice on weekly engineering calls while your first principal hire ramps up.

  4. 04
    Organic codebaseAudit answer

    “Three years of growth. No documented decisions. We don’t know what’s reversible and what’s load-bearing.”

    Day 2 is decision archaeology. We surface the decisions nobody wrote down. Why this DB. Why this queue. Why this auth. Ranked by impact. The next engineer knows where to step carefully.

  5. 05
    Second senior voiceAudit answer

    “We have a CTO. We want an external senior voice to validate the architecture before we commit to a rebuild.”

    Independent written brief, no rebuild agenda. Roughly a third of our audits end with “the architecture is fine, here are six small improvements”. Your CTO gets the second voice. You get the written validation.

  6. 06
    New CTO inheritingAudit answer

    “Our new CTO starts in a month. We want them to walk into something documented, not a Notion page from 2022.”

    The brief is the onboarding document. 30-page brief, diagram, ADRs. Your CTO reads it on day one, asks targeted questions in week one, and makes their first architectural call by week three.

  7. 07
    Compliance auditAudit answer

    “SOC-2 (or ISO 27001) audit starts in eight weeks. We need an architecture story that matches our security controls.”

    SOC-2 / ISO 27001 readiness pack in the brief. Architecture brief mapped to controls. RBAC matrix. Audit log policy. Data residency. Read alongside Vanta or Drata evidence, SOC-2 becomes paperwork, not a six-month panic.

  8. 08
    Pre-rebuild validationAudit answer

    “We’re considering a six-month re-architecture. We want to know if it’s worth it before we commit.”

    Cost-of-rebuild model + alternative path. Day 4 prices the rebuild against the alternatives. Surgical fixes that achieve 80% of the benefit. The full rebuild’s real cost in engineering months. The risk of doing nothing.

What the 5-day architecture audit ships

Six artefacts a senior engineer recognises

Not a sixty-slide deck. The documents your acquirer’s CTO actually opens,
written in the format they’d have asked you to produce.

01

One-page system diagram

Printable, with Excalidraw source. It lives in your repo, not a slide on a drive. The artefact a senior engineer reads first and respects.

02

Six ADRs minimum, drafted

Architecture decision records written in markdown, ready to commit. Context, decision, consequences, status. Your team reviews, you own the words.

03

Threat model on eight patterns

STRIDE on the top eight abuse patterns your product faces. The vulnerabilities ranked by impact, documented in the brief, with the same-hour call if we find one mid-week.

04

10× scale model

What breaks first at ten times current load. The capacity number that goes straight into your runbook, not a hand-wave about scaling later.

05

Prioritised fix list, costed

Critical, High, Medium, Low. Effort in GBP and engineering days. You commit on data, not optimism, and your CFO sees one number.

06

SOC-2 / ISO 27001 readiness pack

Architecture mapped to controls. RBAC matrix, audit log policy, data residency, UK GDPR + DPA pack. Read alongside Vanta or Drata, compliance becomes paperwork.

Architecture review service · what we read your codebase with

The tools we audit with. The patterns we look for.

GitHub and Sourcegraph for reading. Excalidraw and Mermaid for diagrams. STRIDE for threat modelling. ADRs committed to your repo, not a deck on a drive.

T1

What we audit with on every project

read + document
GitHub + SourcegraphExcalidrawMermaid + ADR markdownSTRIDE + MITRE ATT&CKOWASP ZAPk6Snyk + npm auditDatadog + SentryVanta / DrataLucidchartNotion + MarkdownLoom
T2

Stacks we audit fluently

read on sight
Node + Express (MERN)Next.js + PostgresPython + DjangoJava + SpringRuby + RailsReact + TypeScript
T3

The cloud + infra we audit against

AWS-default
AWSKubernetes (EKS)DockerTerraformApache KafkaRedisElasticSearchPostgres + MongoDBStripeCloudflareGraphQLAWS Lambda
What a software architecture consultant reads for

The decisions we pressure-test

Five days, read-only access, one written brief. These are the load-bearing calls we surface, document, and rank by impact before your acquirer’s CTO ever asks.

47

Independent audits since 2019

3

Series A and acquirer reviews passed in 2025

“The acquirer’s CTO read it once, asked seven targeted questions, and approved the technical pillar on the same call.”

Felix’s audit

UK B2B SaaS, 2025

001

Why this database

The data store nobody re-evaluated since year one. We surface why it was chosen, whether it still fits, and what it costs to change. Reversible or load-bearing, ranked by impact.

002

Why this queue

The messaging and async layer that grew organically. We document the call, what it guarantees, and where it leaks under load, so the next engineer knows where to step carefully.

003

Why this auth

Identity, sessions, and permissions, written into an RBAC matrix. The decision your seed lead checks first and the one most teams cannot explain in a diligence call.

004

The threat model

STRIDE on the top eight abuse patterns. The vulnerabilities ranked by impact, with the same-hour call if we find a critical one mid-week, not a surprise on Friday.

005

The scale model

What breaks first at 10× current load and the cost of the surgical fix against a full rebuild. The capacity number goes straight into your runbook.

Recent client · UK B2B SaaS · 2025

Felix’s architecture audit,
in real numbers, before the diligence call

Brief: produce the architecture brief, ADRs, and diagram for an acquirer’s technical review six weeks out. Audit ran Monday to Friday. Felix presented in week two. The acquirer’s CTO read it once, asked seven targeted questions, approved the technical pillar on the same call.

The audit

5
Day audit, NDA to brief
30
Page written brief

The diligence

7
ADRs drafted
+12%
Deal closed above indicative offer

Track record

47
Audits since 2019
0
Briefs leaked, ever
Software architecture services · honest answers

What CTOs and founders actually ask before booking the audit

Pain-first, soft-second.

Roughly a third of our audits end with “the architecture is fine, here are six small improvements”. We don’t sell rebuilds we don’t recommend. The architecture review service is independent. If a rebuild is the right answer, we price it honestly against the surgical alternative. If it isn’t, we say so in writing.

Five days of senior architectural attention on your codebase. One-page system diagram. Six ADRs drafted. Threat model on the top eight abuse patterns. Scale model at 10× current load. SOC-2 / ISO 27001 readiness checklist. UK GDPR + DPA pack. A 30-page written brief. Live walkthrough recorded for your acquirer or seed lead. You can walk away after the audit, and about a third of our clients do exactly that.

In three Series A and acquirer reviews in 2025, yes. The brief is written in the format the external CTO opens: architecture diagram, ADRs, threat model, sub-processor list, SOC-2 readiness checklist. The same artefacts they’d have asked you to produce, written by senior engineers who’ve sat through diligence calls. Felix’s acquirer read it once, asked seven targeted questions, approved the technical pillar on the same call.

Two hours of your team’s time across the week, total. Day 1 kick-off (45 minutes). Day 2 quick chat on undocumented decisions (30 minutes). Day 5 walkthrough (45 minutes). The rest is us reading your codebase. We work from read-only repo access, never write access. Your customers don’t notice a thing.

Yes. After the audit you can run a senior-architect retainer at £5K-10K a month: a principal-level voice on your weekly engineering calls, ADRs maintained, architecture reviewed. Cancellable any month with 30 days’ notice both ways. Most clients run it 6-12 months while their first principal-level hire ramps up.

That’s the best time to book it. Founders who run the audit before the diligence call walk into the meeting with the brief in hand. Timelines shorten. Seed leads ask for the architecture document and you already have it. We’d rather you have it before the question gets asked.

You hear about it the day we find it, not on Friday in the report. If there’s a critical security vulnerability, an active data leak, or a payment flow that’s losing money, we call you the same hour. The written brief documents it. The on-the-day call lets you start fixing it.

Yes, before anything else. NDA signed inside 30 minutes via DocuSign. Mutual NDA template ready. We only need read-only repo access for the audit. We never request write access, and we won’t open a PR against your code during the audit week. We’ve never published or shared a client brief, ever.

Software architecture services — product screenshot / UI
In context

See it in context.

A look at the kind of software architecture services surface we hand over — real screens, real data, documented and yours from day one.

Walk into Tuesday’s diligence call with the brief in your inbox

One paragraph. That’s it.

Tell us when the diligence call is, what your acquirer or seed lead has asked for, and where the codebase lives. Mohit replies inside 24 hours: a clear yes, a clear no, or the one question that decides it.

Write to mohit@empyrealinfotech.com Replies in 24hNDA inside 30 minutesBrief on Friday
What happens after the email lands
  1. < 24h

    A personal reply.

    Yes, no, or the deciding question. Straight to your inbox.

  2. Mon

    NDA signed, audit starts.

    DocuSign inside 30 minutes. Read-only repo access. We read the codebase day one.

  3. Fri

    Brief in your inbox.

    30-page brief, one-page diagram, six ADRs, prioritised fix list. Walkthrough recorded.