How we do it in 2 to 6 weeks
This is how Codebridge finishes the job in 15 to 30 working days.
Access and Permission
Set up
Dig in
Report
If you want more
How both sides are protected
This work only happens if the person who owns the code agrees to it. So the terms have to work for them too, not just for you. Four things make that possible.
A three-year confidentiality agreement
The industry standard is one year. Ours is three as standard, and five on request, at no extra cost. That matters more than it sounds. A deal that falls over in month eight leaves the seller exposed under a one-year agreement well before the commercial risk has passed. Three years covers the period in which the information could still be used against them. It is also the single most common reason a nervous seller says yes to us after saying no to someone else.
Read-only access
We can look. We cannot change anything. This is set at the source, not promised in an email.
The owner decides where the code sits
Some companies will not let code leave their building, because their own security rules or their industry regulator do not allow it. In that case we work inside their systems. Others would rather we took a controlled copy into a sealed environment of ours, so their production systems are never touched at all. Both are normal. The agreement says which one applies, and where any copy is destroyed at the end.
Written permission before any break testing
The tools that attack a running system are only pointed at software when the owner and the host have both signed off in writing. This protects them, and it protects us.
If you are the seller reading this
You are allowed to set the terms. A buyer’s adviser who will not accept read-only access, a long confidentiality agreement, and a written limit on what they may run is telling you something about how they intend to work. Ask for all three before you grant anyone access.
What a good report contains
The report is what you are paying for. Your investment committee will read it. Your insurance broker will read it. If the deal goes wrong, lawyers will read it. Almost none of those people are engineers, so the report is built in two halves.
The front – written for the person signing
The back – written for your engineers
The order is the point. A partner or an underwriter should be able to read the first three pages and make a decision. Their technical people should be able to read the rest and start work on Monday. A report that mixes the two gets skimmed by both.
One question to ask before you hire anyone
Ask to see a sample report structure. It must show, for every finding, what they looked at, how they looked at it, and what they concluded. If they cannot show you that, the report will not hold up in an argument after the deal closes. Ask before you sign them up, not after.
Keep checking after the deal closes
The biggest lesson of the last three years is simple. Checking the software once, before you buy, is not enough. That first check is your starting point. After that you keep watching, every three months.
Once the deal is done, the same tools stay switched on inside the company you bought. Every quarter you get a short update: what changed, what new risks appeared, whether the cloud bill is tracking the forecast, and which new rules now apply.
If you own 20 to 40 companies, this replaces the yearly audit from a big consultancy at about 15 percent of the cost. It also gives you the running record that cyber insurers now ask for before they will renew your policy.

Three real examples
Three jobs, three different reasons for the call. Details are kept general where the parties are identifiable or matters are still on foot.
A handover nobody wanted to make
An Australian point-of-sale software business was changing hands in the middle of a legal dispute. The lawyers involved asked us to check the software for anything left behind deliberately, before the new owners switched it into their own name. We were brought in specifically because neither side trusted a check run by the other.
We found three things.
None of these were accidents, and none would have shown up in a standard security scan. The handover went ahead with all three closed first.
A hosting bill nobody could explain
An established Australian software business had watched its monthly cloud bill climb for two years. Their team had already tried the obvious answer, moving to cheaper machines, which had not worked because the problem was not the machines.
We went through the software and the setup together. The bill was high because the code was making the rented computers do a great deal of unnecessary work: repeating the same database questions, retrying failed jobs indefinitely, and making customers wait for things that should have run quietly in the background.
We took between $5,000 and $6,000 a month off the bill, with no noticeable change in speed for their customers. Nothing was bought. Nothing was migrated. The savings came from fixing what the software was doing.
A committee voting in 21 days
An Australian investment fund had agreed to buy a finance software company. The seller would not let anyone copy the code off site. The first firm the buyer asked quoted 10 weeks. The buyer’s committee was voting in 21 days.
We worked inside the seller’s own systems from day one. By the end of week two we had found three problems big enough to change the price. The seller’s own security scanner had missed all three.
The signed report landed in 15 working days. The buyer used it to knock the cost of the two engineering fixes off the purchase price, and to rebuild their financial model with the real cloud bill. The deal closed on time.
Australian rules you must follow
Every check has to say whether the company follows the rules that apply to it. Four sets of rules matter most.
Rule | Who has to follow it | What we check |
|---|---|---|
APRA CPS 234 | Banks, insurers and super funds, plus the companies that supply them | Installs and runs open-weight models on site with safety controls. Can they keep data safe? Do they report break-ins on time? Do they check their suppliers? |
APRA CPS 230 (from 2025) | The same companies, wider rules | Do they know which systems are critical? How long can each one be down? Do they have a list of who they depend on? |
Australian Privacy Principles | Most Australian businesses earning over $3 million a year | How they handle personal data, whether they send it overseas, and whether they can report a leak quickly |
DORA (European rule) | Any company with European finance customers | How they manage technology risk, supplier risk, and whether they test that the system keeps running under stress |
If the company sells to Australian banks, or to anyone in Europe, the report must name these rules directly. If you buy a company that does not follow them, the cost of fixing that becomes yours on day one.
Common questions
Get the PDF version.
The whole guide as a PDF you can print and hand around: to your deal team, your investment committee, your underwriters, your lawyers, or the board. We will send our checklist template with it.
