FlowState IT

Free buyer’s checklist

The Production-Grade SaaS Buyer’s Checklist

Score your current or planned build against the 30 points we use in a Stage-0 audit. If you can’t tick most of these, you’re carrying risk you can’t see yet.

Architecture & ownership

  • The codebase is modular and domain-separated — modules are independently testable and updatable.
  • Multi-tenant isolation (if applicable) has a documented, tested strategy.
  • Infrastructure is defined as code; every environment is reproducible from the repository.
  • Full IP — code, IaC, docs — assigns to you on payment, in writing.

Security baseline

  • Verified to OWASP ASVS Level 2, not just “best practices”.
  • Least-privilege access throughout, with audit logging on every privileged action.
  • An immutable audit trail suitable for compliance evidence.
  • Automated SAST, DAST, and dependency scanning run in CI.
  • Continuous CVE / threat-intelligence monitoring against every component.

Resilience & observability

  • Defined and tested RPO and RTO — backups restored in a rehearsal, not assumed.
  • Structured logging, metrics, error tracking, and alerting from day one.
  • Green pipelines and coverage thresholds gate every release.

The governance pack (8 documents)

  • Architecture Decision Record — every material choice and its reasoning.
  • Threat Model — attack surface and the control against each threat.
  • Security Posture Document — mapped to recognised standards, questionnaire-ready.
  • Operational Runbook — deploy, incident response, escalation, recovery.
  • Forensic Handover — a decision trail any competent team can pick up cold.

Compliance & contract

  • SOC 2 / ISO 27001 readiness is a configuration of what exists, not a retrofit.
  • AI systems designed against the EU AI Act for the relevant risk tier from day one.
  • Fixed-fee discovery produces the estimate before the build is priced.
  • Per-phase acceptance criteria agreed in writing before each phase starts.
  • A 90-day post-launch warranty with severity-based response commitments.

Want us to run the full 30-point audit on your system?

Stage 0 is a fixed-fee Discovery & Technical Audit — credited against the build if you proceed.

Book a scoping call