We outsourced the initial build of a patient scheduling and telehealth platform for our San Francisco-based healthtech startup to an external software agency. We paid around $55,000 for a four-month build, and the project was completed per contract specifications with the repository transferred over to us.
We are now looking to maintain and scale the product in-house with one senior software engineer and two interns. However, we have no real way of gauging how clean this codebase (a Node.js and React architecture) actually is, or whether it hides vulnerabilities and severe architectural technical debt that will haunt us later.
We know there are automated static code review tools out there, but do they deliver reliable findings? What is the best strategy to thoroughly audit code quality and security—is relying on automated tooling alone sufficient?