Free buyer’s checklist
The Production-Grade SaaS Buyer’s Checklist
Score your current or planned build against the 30 points we use in a Stage-0 audit. If you can’t tick most of these, you’re carrying risk you can’t see yet.
Architecture & ownership
- The codebase is modular and domain-separated — modules are independently testable and updatable.
- Multi-tenant isolation (if applicable) has a documented, tested strategy.
- Infrastructure is defined as code; every environment is reproducible from the repository.
- Full IP — code, IaC, docs — assigns to you on payment, in writing.
Security baseline
- Verified to OWASP ASVS Level 2, not just “best practices”.
- Least-privilege access throughout, with audit logging on every privileged action.
- An immutable audit trail suitable for compliance evidence.
- Automated SAST, DAST, and dependency scanning run in CI.
- Continuous CVE / threat-intelligence monitoring against every component.
Resilience & observability
- Defined and tested RPO and RTO — backups restored in a rehearsal, not assumed.
- Structured logging, metrics, error tracking, and alerting from day one.
- Green pipelines and coverage thresholds gate every release.
The governance pack (8 documents)
- Architecture Decision Record — every material choice and its reasoning.
- Threat Model — attack surface and the control against each threat.
- Security Posture Document — mapped to recognised standards, questionnaire-ready.
- Operational Runbook — deploy, incident response, escalation, recovery.
- Forensic Handover — a decision trail any competent team can pick up cold.
Compliance & contract
- SOC 2 / ISO 27001 readiness is a configuration of what exists, not a retrofit.
- AI systems designed against the EU AI Act for the relevant risk tier from day one.
- Fixed-fee discovery produces the estimate before the build is priced.
- Per-phase acceptance criteria agreed in writing before each phase starts.
- A 90-day post-launch warranty with severity-based response commitments.
Want us to run the full 30-point audit on your system?
Stage 0 is a fixed-fee Discovery & Technical Audit — credited against the build if you proceed.
Book a scoping call