Who can reach production, and could we prove it after an incident?
Secrets handling, dependency vulnerabilities, access control and offboarding discipline, deploy permissions, audit trail, and POPIA exposure on the data you hold.
Eight questions you would ask if you knew to ask them. Scored at the start, re-scored every quarter, and each carries a rand figure rather than an adjective.
Who can reach production, and could we prove it after an incident?
Secrets handling, dependency vulnerabilities, access control and offboarding discipline, deploy permissions, audit trail, and POPIA exposure on the data you hold.
If we lost the database tonight, how much would we lose and how long until we trade again?
Backup coverage, restores that have actually been tested rather than assumed, recovery time and data-loss tolerance measured against what the business can survive, and failover that has been rehearsed.
At three times the volume, what breaks first and what does it cost?
Load headroom, database growth curves, query hotspots, and cloud spend measured against actual utilisation, so growth does not arrive as a surprise invoice.
Can we ship a fix on a Friday and undo it by Saturday?
Deployment frequency, rollback capability, manual steps still in the path, environment parity, pipeline coverage, and how much of release day depends on one person being awake.
When one thing changes, how many others break?
Service boundaries, integration fragility, upgrade paths that have been deferred, and vendor lock-in that would make leaving a platform expensive later.
Are we paying to build, or paying to redo?
Rework rate, test coverage where failure would actually hurt, dependency currency, and technical debt reported with a rand figure attached rather than an adjective.
Who could resign tomorrow and take something we cannot replace?
Where knowledge is concentrated, what is documented against what lives in one head, review participation across the team, and how long a competent replacement would take to become useful.
Do we actually own what we have paid for?
Repository and IP ownership, open-source licence exposure in what has been shipped, source escrow, and which credentials, domains and accounts sit in a supplier's name rather than yours.
Not an adjective. Each domain gets one of four ratings, the movement since last quarter, and a rand exposure so it can be weighed against everything else on the risk register.
Your team is not hiding things from you. They are describing them in a language you do not speak. Every finding is written so that the person paying can act on it without asking the person building to translate.
Who can reach production is read from the access system, not from a spreadsheet. Backups count when a restore has been watched. A quiet month is a finding too, and you get it in writing.
A quiet month is a finding, and you get it in writing.
What you receive
Three reviews owners ask for by name. Each is scoped from the Assessment and quoted on its own.
Backups proven by restore rather than assumed. Recovery time and data-loss tolerance measured against what the business can survive, and failover rehearsed instead of documented.
Where the gaps are between what you assume is tested and what has been. Access, secrets, dependencies, deploy permissions and POPIA exposure, with penetration testing scoped to an independent specialist where depth is needed.
Every domain scored, movement tracked against the previous quarter, and the whole register costed in rands so it can be taken to a board or an insurer.
Each is quoted after a scoping call, as a fixed fee for a fixed scope. Not an assurance engagement under ISAE 3000.
Forty-five minutes, no preparation needed. If this is not what you need, we will say so on the call.
hello@gooddevs.co