Contact

Code support

Review, debugging, testing, takeover Service 06 / 08 ← 0507 →

I read the code the team wrote and list findings by severity; we reproduce the bug in production and find its root cause; we deliver the fix together with a test that breaks when the fix is reverted.

With code inherited from someone else, I start with the path that touches the most money and data.

P0now
Security, money, data loss. Must not stay live; this comes first.
P1before release
Wrong result. Shows the user a wrong figure or a wrong status.
P2planned
Fragile spot. Works today, fails at the first unexpected case.
P3improvement
Readability and repetition. The code works, but makes the next change harder.

06.1The work in three parts

A green test alone is not proof. A test that does not break when the fix is reverted is not catching the bug.

aWhat we do

  • Code reviewI read the changes and write findings in P0-P3 order, with line numbers.
  • DebuggingWe reproduce the production bug first, then find its root cause.
  • TestingTests for critical flows that really catch the bug.
  • TakeoverA map of undocumented code: what is where, which part touches what.

bWhat we deliver

  • List of findingsEach finding: location, problem, suggested fix, test.
  • Fix branchOn a separate branch, with small, explained commits; the merge decision is yours.
  • TestsShown to break when the fix is reverted.
  • Code mapA one-page structure note for an inherited project.

cHow we measure

  • Escaped bugsNumber of bugs found after reaching production, month by month.
  • Time to fixTime from a bug being reported to the fix going live.
  • RepeatsHow often the same kind of bug shows up again.
  • CoverageShare of paths in critical flows (payment, login, data writes) that have a test.

06.2What a review looks like

Four findings in a made-up order function. Click the number on a line or a finding on the right.

Code review

A made-up example, 19 lines

Sample code
order.js4 findings
  1. export async function orderTotal(cart, coupon) {
  2. let total = 0;
  3. for (const item of cart.items) {
  4. total += item.price * item.quantity;
  5. }
  6. if (coupon) {
  7. total = total - total * coupon.rate;
  8. }
  9. const shipping = await shippingFee(cart.address);
  10. return Math.round(total + shipping);
  11. }
  12. app.post('/api/order', async (req, res) => {
  13. const { id, coupon } = req.body;
  14. const cart = await db.query(
  15. `SELECT * FROM cart WHERE id = ${id}`);
  16. const total = await orderTotal(cart, coupon);
  17. res.json({ total });
  18. });

06.3Related packages

The three packages that most often go with code support.

Start

Starting audit and score

A scan of the codebase in P0-P3 order and a score for critical flows.

  • Payment, login, data write paths
  • Critical paths without tests

Security

Compliance and risk review

A review of secrets, personal data and third-party dependencies.

  • Secret scan in code and logs
  • Old dependencies with known vulnerabilities

Speed

AI agents built for the project

Code agents: a setup that writes on its own branch, is reviewed by a separate agent, and leaves the decision to the team.

Write where the code lives and what is broken.

Repository access can be discussed later; a short description of the bug and how long it has been happening is enough to start.