Skip to content
Jakub Zając

05 / Quality & assurance

A straight answer about the real state of your system

I examine code, websites, processes and infrastructure, then hand back a prioritized report — written in the language of business decisions, with a technical appendix for the team.

Companies often depend on systems they know surprisingly little about. The vendor insists everything is fine, users complain the site is slow, the cloud bill keeps climbing, and decisions about further development are made in the dark. A technical audit replaces guesswork with evidence: what works, what's a risk, and what to deal with first.

Every audit ends in a written report with findings ordered by risk and business impact. The main part reads clearly for management; the details — exact problem locations, configurations, recommended changes — go into a technical appendix for the team. The report is not a sales pitch for my services: you can implement the recommendations with any vendor you choose.

I audit as a practitioner, not a reviewer with a checklist. Day to day I design, build, test and deploy systems myself — including projects connected with organizations such as PwC, Roche and E.ON — so every recommendation in the report is something I could carry out with my own hands, with a realistic sense of the effort involved.

What the service covers

01

Application and code audits

A review of the application's code, architecture and technical quality: where the technical debt sits, what blocks development, what the test coverage looks like and whether the system can carry the company's plans for the coming years.

  • Code quality and architecture review
  • Technical-debt analysis with a paydown plan
  • Pre-takeover audit of another vendor's project
  • Readiness assessment for growth and scale
02

Website audits

A thorough examination of a website or online store: loading speed and Core Web Vitals, technical SEO, accessibility, mobile behaviour and the errors that cost you conversions.

  • Performance and Core Web Vitals audit
  • Technical SEO audit
  • Accessibility audit (WCAG)
  • Mobile behaviour verification
03

QA process and test automation audits

An assessment of how quality is actually handled in a project: what gets tested versus what merely “should be”, the state of the automated tests, whether CI genuinely stops bad releases and where the process leaks.

04

Infrastructure, database and deployment reviews

I examine the foundation the application stands on: server and cloud configuration, costs, the deployment process and database health — from query performance to whether the data can actually be restored from backup.

  • Server and cloud configuration review
  • Cloud cost analysis with savings recommendations
  • Deployment process and CI/CD review
  • Database review: performance, backups, recovery
05

Security configuration reviews

A best-practice review of your security posture: permissions and access, updates, backups, HTTPS and security headers, exposed services. To be clear and honest: this is not a certified penetration test — if your situation calls for one, I'll say so plainly and help you scope it for a specialized firm.

Typical situations

  • 01

    You pay for system maintenance every month, but no one independent has ever checked what state it's in.

  • 02

    The site loads slowly or keeps losing ground in Google, and everyone you ask names a different cause.

  • 03

    You're taking over a project from a previous vendor, or buying a company along with its system, and want to know what you're actually getting.

  • 04

    The cloud bills grow month after month and no one can explain what exactly you're paying for.

What you can count on

  • A written report with findings ordered by risk and business impact, not an alphabetical list of a hundred remarks.

  • A summary management can act on, plus a technical appendix with specifics for the team or vendor.

  • Recommendations with an indicative effort estimate, ready to implement with any vendor and with no lock-in to my services.

  • A walkthrough meeting: we go through the findings together and I answer questions, instead of leaving you alone with a PDF.

Questions about this service

A written report: an executive summary, findings prioritized by risk, recommendations with an indicative effort estimate, and a technical appendix with details for the team. Plus a meeting where we walk through the results together and agree on an action plan.

No — and I say that openly. I perform a configuration and best-practice review: access and permissions, updates, backups, exposed services, basic security hygiene. That catches a large share of typical problems, but it does not replace a certified penetration test. If your industry or situation requires one, I'll help you scope it and choose a specialized firm.

We agree the scope of access before the audit starts and keep it to a minimum — wherever possible I work with read-only access. I make no changes to production systems during an audit, and I can sign a non-disclosure agreement before work begins.

It depends on scope: a single-website audit is a different scale from a full application and infrastructure review. After a short conversation and an initial look, you get a fixed scope, timeline and price — no open-ended billing. I run audits remotely for companies across Poland, with on-site meetings available in and around Bydgoszcz.

Related services

Find out where you really stand

Tell me what you want examined — a website, an application, infrastructure or a process — and I'll propose the audit scope, a timeline and a fixed price. The report is yours, whoever ends up implementing the recommendations.