$2,500 · two weeks · fixed scope
Technology Health Check
Two weeks. I read your codebase, run it, talk to your engineers, and write down what I find — ranked by severity, with the repair-versus-rebuild calls costed. You keep the report, and it is written so you could hand it to anyone.
Credited against your first month if you go on to a fractional CTO retainer within 90 days.
Who books this
Three situations, mostly
You inherited a codebase and don't know what you have. An agency built it, or a founding engineer left, and every estimate you get now is a guess. You need an independent read before you spend another dollar on it.
You're raising, and diligence is coming. Investors will put someone technical on your system. Better to know what they'll find while you can still fix it or have an answer ready.
Something feels wrong and you can't name it. Velocity dropped, incidents are up, the team is defensive about a particular subsystem. That instinct is usually correct and usually specific.
Scope
What the report covers
Architecture & codebase
What the system actually is versus what the diagram says. Data model, coupling, the parts everyone avoids touching, and what breaks first under 10x load.
Security & data handling
Where sensitive data lives and who can reach it. Access control, secrets handling, audit trails. For regulated products: PHI boundaries and whether every vendor touching them is BAA-covered.
Cloud spend & infrastructure
What you are paying for, what you are paying for twice, and what is provisioned for load you do not have.
Delivery & process
How code reaches production. Deploy path, test coverage where it matters, review practice, and the bus factor on anything critical.
Team & capability
Up to two interviews with your engineers. Whether the team you have can build the product you described, and what the gap is if not.
AI systems, where present
Model selection and routing, evals, whether inference over sensitive data widens your compliance scope, and what the cost curve looks like at 10x usage.
Timeline
How the two weeks run
-
Day 0
Kickoff call and read-only access
Repos, infrastructure, docs. The two-week clock starts when access lands, not when the invoice does.
-
Days 1–5
Assessment
Codebase, infrastructure, deploy path, data handling. I run it locally. Questions arrive by email as they come up rather than saved for the end.
-
Days 6–8
Team interviews
Up to two conversations with your engineers. Usually the highest-signal part — people know where the bodies are.
-
Days 9–12
Writing
Findings ranked by severity, with cost ranges on the repair-versus-rebuild calls.
-
Day 14
Read-out call
Sixty minutes walking through the report. You keep the document either way, and it is written so any competent provider could act on it.
Boundaries
What this is not
A fixed price only means something if the scope has edges. Explicitly outside this engagement:
- Code changes or fixes — this is an assessment, not an engagement
- Penetration testing or a formal security audit
- A HIPAA or SOC 2 compliance certification (this is an engineering opinion, not an attestation)
- Legal or regulatory advice
- Financial or commercial due diligence
Any of those can be scoped separately. The report will tell you if you need them.
Get started
Book 30 minutes to scope it
The call is free and there is no obligation to book the Health Check afterward. If a 30-minute conversation is enough to answer your question, I will tell you that and we are done.
Rather see one than read about one? I published a real Health Check — run on this website, which is the one codebase I can share without a client's permission.
Questions
What do I actually receive? +
A written report: every finding ranked by severity, what is sound and should be left alone, what needs repair versus rebuild with cost ranges attached, and a prioritized 90-day plan. Plus a 60-minute read-out call. The document is yours — it is deliberately written so you could hand it to any competent engineer or agency and they could act on it without me.
Why $2,500, and why fixed price? +
Fixed price because you should know the cost before you commit, and because an hourly assessment gives me an incentive to take longer. $2,500 is roughly two weeks of part-time work at a rate below my retainer, priced so it is a low-risk way to find out whether we should work together at all.
Is it credited if we work together after? +
Yes. If you start a fractional CTO retainer within 90 days of the report, the $2,500 comes off your first month. It is effectively free if this goes anywhere.
How is this different from the free call? +
The free 30-minute call is a conversation — I give you a straight verbal read on where you stand. The Health Check is two weeks of actual work producing a document. If you want findings you can forward to a co-founder, a board, or an investor, that is this.
What access do you need? +
Read-only is enough: repository access, read access to your cloud console, and whatever documentation exists. I do not need write access, and I do not need production credentials. Access delays extend the timeline day for day, which is worth knowing before you book.
Will you sign an NDA? +
Yes. Send me yours before we start, assuming it is not unreasonable. For clients handling protected health information I will also sign a BAA.
What if the report says everything is fine? +
Then you have a written, independent assessment saying so, which is worth having before a raise or an enterprise security review. It has not happened yet, but "you are in better shape than you think, here are the three things to watch" is a legitimate outcome and I will not manufacture problems to justify the invoice.