Software Project Rescue

Find Out What Is Wrong Before You Spend More Money Fixing It.

When important software is late or unstable, “add developers” and “start over” are common answers. Both can be expensive mistakes.

The assessment is led personally by Codepoet’s founder and CEO. It starts with the existing system, identifies the parts worth keeping, and lays out the most defensible path forward for the current team and budget.

Standard assessment

$6,500 7–10 business days after access is complete
  • One bounded business application
  • Up to three related repositories
  • Plain-English owner’s verdict
  • 30/60/90-day recovery plan

You may need a rescue assessment if…

Deadlines have slipped more than once and nobody can give you a dependable new date.

The team is busy, but finished work is hard to see.

Estimates and invoices are growing faster than the product.

A vendor or one key developer holds most of the system knowledge.

Releases are risky, manual, or regularly rolled back.

You inherited the software through an acquisition, departure, or failed handoff.

An application built quickly with AI now needs to handle real customers, data, and operational risk.

Architecture diagrams and delivery materials arranged for technical review

Evidence, not assumptions

One artifact never tells the whole story.

A clean repository can still hide a broken release process. A busy issue tracker can still hide a team that is not shipping.

The assessment compares code, history, environments, and interviews before it reaches a conclusion.

Four evidence areas

What the assessment reviews

Code

Software & Architecture.

Repository history, dependencies, database design, integrations, tests, maintainability, and places where change is unusually dangerous.

Operations

Deployment & Reliability.

Environments, infrastructure, release paths, error visibility, backups, and the operational evidence needed to understand risk.

Security

Access & Data Handling.

Authentication, authorization, secrets, sensitive data, and obvious security risk. This is not a penetration test or compliance certification.

Delivery

People & Process.

Issue history, estimates, pull requests, meetings, roles, decision rights, delivery cadence, and team or vendor accountability.

The deliverable

A report the owner can understand and use.

This is not a code-quality score or a stack of scanner output. It is a decision document that connects evidence to risk, options, cost, and sequence.

Software Rescue Assessment

Owner’s Decision Report.

Independent reviewPrepared for action
01

Executive verdict

The condition of the project, stated directly.

A plain-English account of what is working, what is not, and what the evidence supports.
02

Prioritized risk register

  • Act nowBusiness-critical risk
  • Plan nextMaterial constraint
  • MonitorKnown exposure
03

Decision matrix

FixRefactorRebuildPause
The recommendation includes the evidence and tradeoffs behind each practical option.
04

30/60/90-day plan

30 Stabilize60 Correct90 Prove
Immediate action, ordered technical work, team or process changes, and decisions that can wait.
05

Cost & Sequencing Bands.

Enough information to plan and compare options without pretending certainty that does not exist yet.

06

Findings Meeting.

The decision-makers walk through the report, challenge the findings, and get the answers needed to act.

From evidence to action

How the report reaches a decision.

Each stage narrows uncertainty. The work moves from establishing facts to giving the owner a sequence that can be funded and defended.

  1. 01

    Inventory.

    Establish the system, access, people, history, and business constraints actually in scope.

  2. 02

    Cross-check.

    Compare code, issue history, environments, and interviews instead of accepting one account as complete.

  3. 03

    Prioritize.

    Separate urgent business risk from ordinary technical debt and rank findings by effect, not drama.

  4. 04

    Decide.

    Give the owner a defensible sequence: act now, plan next, monitor, or deliberately leave alone.

The engagement boundary

Standard assessment scope.

The review window begins when the agreed access is complete. Missing credentials, unavailable repositories, or absent stakeholders pause the clock rather than consuming the review.

7–10business days after access is complete

Included in the standard assessment

  • One application or closely related product
  • Up to three related repositories
  • One primary production, cloud, and database path
  • Roughly five material integrations
  • Executive kickoff, selected interviews, and findings meeting
  • Approximately five included hours of live meetings
  • Fourteen days after delivery for factual corrections, clarification, and one follow-up call

Access boundary

Read-only wherever practical.

Codepoet normally needs the repository, issue tracker, pull or merge request history, documentation, database schema, development environment, and relevant cloud or deployment information.

  • Production access: only when necessary
  • Credentials: named and time-limited
  • Project material: return or deletion agreed in writing

Codepoet will sign a reasonable NDA. Production credentials are not a standard requirement.

Your report. Your decision.

The findings do not depend on Codepoet receiving the follow-up work.

Implementation is proposed separately only after the findings are understood.

01Keep the current team.

Give the plan to the people already doing the work.

02Use another provider.

The report is written so another qualified team can act on it.

03Ask Codepoet to help.

Scope stabilization or ongoing technical leadership separately.

04Pause deliberately.

Stopping can be the right decision when the evidence supports it.

Prototype meets production

AI-built applications still need a production reality check.

Software built with Claude, ChatGPT, Cursor, Lovable, Replit, or another AI-assisted tool can move from idea to working product remarkably quickly. The harder questions arrive with real users, sensitive data, integrations, billing, and multiple people changing the code.

The point is not to criticize how the software started. It is to determine what it needs next.

Production gates

  1. 01AccessWho can see and change what?
  2. 02DataWhere does sensitive information go?
  3. 03DeliveryCan changes be tested and deployed safely?
  4. 04OwnershipCan another developer maintain it?
Standard$6,500

One bounded application and up to three related repositories.

Complex assessmentFrom $9,500

Several applications, broader infrastructure, regulated data, additional teams, active incident response, or unusually difficult access.

Scope and price are agreed before work begins. A standard assessment will not quietly become open-ended.

Common questions

Frequently asked questions.

How do you keep the assessment independent if Codepoet also offers implementation?

The assessment and any implementation proposal are separate decisions. The report explains the evidence behind each practical option and is written so your current team or another qualified provider can act on it. Codepoet only scopes follow-up work if you ask.

Can our existing developers stay?

Yes. A rescue does not automatically mean replacing the team. Good developers can struggle inside a project with unclear priorities, weak ownership, or a delivery process that works against them.

What if our documentation is poor or missing?

That is common. Repository history, issue records, infrastructure, interviews, and the running system can still provide substantial evidence. Missing documentation is identified as a risk rather than guessed around.

Do you need production credentials?

Usually not. Codepoet prefers repositories, documentation, schema information, a development environment, and read-only operational evidence. If production access becomes necessary, Codepoet will explain why before requesting it.

Will you change the system during the assessment?

Not as part of the standard assessment. Separating diagnosis from implementation protects the system and keeps the findings independent. Emergency work can be authorized separately.

What technology stacks do you review?

The founder’s current hands-on work is primarily PHP, Laravel, React, Tailwind, and Linux, with decades of earlier C# and .NET experience. Many assessment questions cross language boundaries. If specialist review is needed, Codepoet will say so before accepting the work.

Find out if the assessment fits your project.

The first call is 30 minutes. We will discuss what is happening, how urgent it is, and what access a useful review would require.

Send a Message