Taddesse · Jabari Ennis

The Engineering Health Audit

You paid for the code. Do you know what you own?

A fixed-price review of the software you own, whether an agency built it, your developer moved on, or you built it yourself with AI. What's solid, what could hurt you, what to fix first, and whether it's safe to ship. Delivered in days, written so an owner can act on it.

Book the 30-minute call hi@jabariennis.com The call is free. I only need permission to read your code, never to change it.
A sample engineering health audit: an estate review for an example company, opening with a plain-English summary and a scorecard of every project ranked by risk, with a note of how many people understand each one.

The real deliverable, the summary and scorecard your engineers and your accountant can both read, shown here with sample data.

Why I offer this

I ran it on my own company first.

I'm the founder and CTO of a fintech that moves real money, and I've done exactly what I'm offering you: a full read of the nine core codebases my own company runs, covering how current they are, where they're exposed, what's written down, what's actually tested, and what only one person understands. It's the kind of review most companies never do, because done by hand it takes a consultancy weeks and costs five figures.

It surfaced real things worth fixing, gaps in the safety checks around money, tests that passed without ever running, systems only one person understood, and foundations built on retired tools, none of it dramatic, and all of it fixable, most within a day.

The AI does the reading: every project, every part it's built on, every pattern in how it's been looked after. I do the thinking: what actually matters, in what order, and what it means for your business. You get the coverage of a machine with the judgment of someone who ships.

What you receive

One document. Everything ranked.

Executive summary

Two pages in plain English, covering what you own, what it's worth operationally, and the three decisions worth making about it next.

Project-by-project scorecard

Every piece of software scored: is it maintained? Written down? Tested? How old are the parts it's built on? And who actually understands it?

Ranked risk list

What could actually hurt you, in order, known security holes left unfixed, things only one person can repair, passwords saved where they shouldn't be. Ranked by consequence, not by count.

Quick wins

The list of things fixable in a day each, separated from the structural work, so momentum starts immediately.

AI-readiness roadmap

Where AI could start doing real work on your software first, and what groundwork it needs to be safe, the part no traditional audit includes.

The walkthrough

A live session where we go through the findings together and your team can push back. The report is yours to keep either way.

Your code stays yours

Read-only, confidential, and deleted when we're done.

The audit needs nothing more than permission to read, never to change, and you can switch that access off the moment we're done. I'll sign your NDA or bring mine. My working copies are deleted after delivery; what remains is your report, in your hands.

And a line you should hear from anyone who reads your code: this is an engineering health audit with security screening, not a formal penetration test. Where your risk profile warrants one, the report says so and I'll point you to specialists who do that work well.

How it works

Access to answers in about a week

The call

Thirty minutes, free. What you have, what worries you, and what you want to be true in six months. If an audit isn't the right move, I'll say so.

The access

You grant read-only permission, I'll walk you through it, it takes minutes. NDA signed before anything is read.

The audit

The sweep runs, then I read what matters and rank everything by consequence, a matter of days rather than weeks.

Solo / small: from US$1,500 · Organizations: from US$5,000

The walkthrough

We go through it together. You leave with the report, the ranked list, and the quick wins in plain English. If you want the urgent items closed, I do it as a fixed-price sprint, and can stay on to keep watch, so the next audit finds less.

Who this fits

  • Founders who paid an agency, and want to know what they got
  • Anyone who built an app with AI and needs to know it's safe to ship
  • Owners whose developer or CTO moved on
  • Buyers and investors sizing up a small acquisition
  • Teams inheriting software they didn’t write
  • Organizations that want AI leverage but don't know where to start

What this is not

  • Not a formal penetration test, where you need one, the report says so and names the kind of specialist to hire.
  • Not a rewrite pitch, most findings are fixes, not projects, and the report says which is which.
  • Not a scare document, healthy things are called healthy. The ranking is the value.

Start

Find out what you own.

Tell me roughly what you have, what the software does, who built it (agency, developer, or AI), what's keeping you up at night. I'll tell you what the audit would cover and quote it flat.

Need software built, not audited? Bespoke builds are the other thing I do.