IT audit

What you were actually sold

An independent check of what the business runs on: the code and the platform, the server and the backups, the CRM and the registers — and who really holds the domain, the hosting and the access. The result is a written report: what is sound, what is at risk, and what to fix first.

88
projects delivered
19
years in development
25
systems implemented

When to check

  1. The vendor is leaving — or gone

    The developer has stopped answering, or you are parting on good terms. The audit shows what you are getting into your hands and what the handover is missing.

  2. Nobody knows what was delivered

    The site works, the invoices are paid, and what is inside is known only to whoever built it. The report moves that knowledge to you.

  3. After an incident

    A break-in, lost data, a site down on the wrong day. The review answers how it became possible and what to close so it does not repeat.

  4. Before a purchase

    You are buying a ready-made site, or a business together with one. A check before the deal is cheaper than surprises after it.

  5. The estate has grown

    A site, a CRM, registers, mail — and nobody sees the whole picture. The audit gathers it into one document.

Four layers of the check

  1. Code and platform

    The state of the CMS or the framework, the discipline of updates, the quality of custom work, the speed. Not the aesthetics of the code but the risks: what breaks on the next update and what already holds on a promise.

  2. Security and backups

    Vulnerabilities, passwords and staff access, whether copies exist — and whether they have ever been restored. A backup that has never been restored does not count as a tested one.

  3. Server and ownership

    Where the site lives and what state the server is in; who the domain, the hosting and the admin access are registered to. If everything is in the vendor's name, the business runs on somebody else's property — and the report says so in plain words.

  4. Systems and services

    The CRM, the registers and fiscal devices, the mail, the integrations between them. What is connected, what is typed in by hand, and where data lives in a single copy with no backup.

Three steps to the report

  1. The access

    The list of required access arrives before the start. What exists, you hand over; what cannot be found is already the first finding of the check.

  2. The check

    Each layer is walked through a method: code, server, copies, access, systems. Nothing is changed or fixed along the way — only recorded.

  3. The report

    A written document: what is sound, what is at risk, what to fix first. Ordered by priority, in human language, with each finding weighed.

Two depths of checking

  • For the site and the access

    Express

    $500

    The core risks in a short run: the site, its server, and who all of it belongs to.

    • The site and its platform
    • Domain, hosting and admin access
    • Backups and their restorability
    • A written report with priorities
    Order the audit

The date is named before the start, after the scope is weighed, and does not drift along the way. This is a one-off piece of work, not a retainer — IT consulting in the shape of a check with a document at the end. Talking the task over costs nothing; the paid work is the check with the written report.

Before you write in

No. An SEO audit looks at positions in search; this one looks at the construction and the risks: code, server, copies, access, systems. The search review is on the SEO page.

The access, by a list that arrives before the start: the hosting or the server, the admin area, the domain. If something cannot be found, that is already a finding — the picture gets restored first.

The conversation and the first assessment cost nothing, as on every page of this site. What is paid is the methodical check with a written report — it takes days, not the minutes of a call.

That depends on the size of the estate. The date is named before the start, once the scope is weighed — and it is fixed by agreement.

The report stands on its own — you can take it to any contractor. Taking the fixes on is also possible: that is separate work with its own estimate, and the audit does not oblige you to it.

Recovery first, the review after. An audit after an incident answers how the break-in became possible and what to close; along the way it checks what you would restore from next time.

Yes — that is the systems-and-services layer: what is connected to what, where entry is manual, and where data lives without a copy. The Full plan covers the estate end to end.

With an inventory of what there is: the domain, the hosting, the admin areas. Part of the access can be recovered through the registrar and the host — the report gives the steps for each.

Fill in the brief

Naming the site and saying what worries you is enough. The conversation costs nothing; after it — which plan fits and what date is realistic.

    What to check