forumNew topic

The agency handed over the code, now they're suggesting a "code audit" — why should we pay for this again?

KKadir A***MemberCommunity member
Joined
Aug 2024
Message
99
#1

We had a custom B2B hotel booking portal developed for our Saint Petersburg-based travel agency. We agreed on an 800,000 RUB fee with a local software agency, and the development process took around 4 months. Last week they deployed the software to our server; basic functions work fine and there are no obvious issues in the UI.

However, during the project wrap-up meeting, the agency manager suggested we get an external "code audit." They told us we could hand this off to an independent expert if we wanted, or their senior architects could prepare a detailed audit report for 120,000 RUB.

This offer makes no sense to me. Why am I being forced to pay extra to audit code that I already paid for and accepted delivery of? What exactly is a code audit, and is it normal for an agency to pitch a service like this for their own work, or is it a sign they don't trust what they wrote?

GGürkan V***Member
Job title
Customer service representative
Sector
Printing
Organization type
workshop
Joined
Aug 2023
Message
118
Most Helpful#2

Short answer: A code audit is a technical review that evaluates architectural quality, security vulnerabilities, and future maintenance costs rather than outward-facing functionality. It's not a matter of the agency doubting their own delivered code, but trying to sell you an audit on code they wrote themselves is definitely neither ethical nor logical.

Just because software runs doesn't mean the code was written properly. A code audit brings static code analysis tools and senior eyes into play: it looks at whether there are hidden memory leaks, whether database queries will lock up the server under scale, or whether third-party libraries are up to date and licensed. It's like testing the concrete strength of load-bearing columns instead of just admiring the exterior paint of a newly bought building.

An agency auditing its own code holds zero value; they can't write an objective report on their own mistakes. If you plan to scale the project with another team down the road or if large sums of money will flow through the system, getting an independent code audit is a very sound decision.

My advice is to reject the agency's 120,000 RUB offer. Before signing off on the project, check the acceptance criteria in your contract; compliance with clean code standards should already be part of the main agreement. If you have doubts, you can hire an independent freelance software architect for 40,000 - 60,000 RUB to run a 2-day architectural review.

BBeyzaMember
Job title
Small agency
Joined
May 2024
Message
104
#3

You got a custom suit tailored, and while handing it over the tailor goes, "Want me to check if the seams will rip for 5 grand in rubles?" An agency model that doesn't trust its own code is quite a creative side hustle, honestly.

OOkyanusMember
Job title
Embedded software
Organization type
regional distributor
Joined
Apr 2024
Message
96
#4

A code audit looks at the level of technical debt. Developers sometimes write spaghetti code or skip writing tests to meet deadlines. The system runs for now, but it'll crash on the very first update. An audit is valuable for uncovering these exact risks.

CCeren E***MemberCommunity member
Joined
May 2024
Message
1
#5

Don't pay the agency. Hook open-source static analysis tools up to your GitHub or GitLab repo. Even automated tools will list duplicate code and basic security vulnerabilities in 10 minutes for free.

ÖÖmerMember
Job title
Financial Analyst
Joined
Dec 2023
Message
126
#6

We skipped the audit on a project we paid 650,000 RUB for; 6 months later, when we wanted to add new features, another agency said "this code is garbage, we have to rebuild from scratch" and we burned another 500,000 RUB. An independent check is a must.

EEmre P***Member
Job title
Field sales representative
Sector
Cosmetics
Organization type
medium-sized business
Joined
Nov 2022
Message
55
#7

If you're going to get a code audit, have them check 3 things: 1) Database query optimization, 2) Input parameter sanitation, 3) Code documentation. If these are solid, another developer can easily take over tomorrow.

YYasemin T***New memberCommunity member
Joined
Aug 2026
Message
68
#8

selling an audit for stuff they wrote themselves is such a hustle lol but anyway just pay an indepenednt third party for a couple hours of consulting to give it a quick once-over that's plenty.

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#9

Are acceptance criteria and a warranty period included in your initial contract? If there's a clause for "compliance with clean code and architectural standards," they are legally obligated to deliver on that for free as an acceptance condition anyway.

ZZehra T***Member
Job title
Operations manager
Sector
Freight
Organization type
early-stage startup
Joined
Apr 2026
Message
68

Doki · Penetration test · 2025

#10

If I understood correctly, you're saying: Everyone rushing into code audit gets stuck at the same point.

People defend habits, not processes. Resistance comes from there. Hope this helps.

İİsmail Ş***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
boutique agency
Joined
Apr 2024
Message
32
#11

I went through the same thing two years ago. Weekly written progress reports are much more useful than asking for dates.

Start with a small trial; don't commit to everything at once.

OOnur S***Member
Job title
System support specialist
Sector
Packaging
Organization type
300-person organization
Joined
Jul 2025
Message
14
#12

The discussion got scattered, let me summarize. Payment schedules should be tied to project phases, not calendar dates.

Proven by experience.

HHasan K***MemberCommunity member
Joined
Apr 2023
Message
221
#13

Let's separate the concepts they're getting mixed up. Everyone rushing into code audit gets stuck at the same point.

If acceptance criteria arent written when the work is done is open to debate.

VVahide A***Member
Job title
QA Tester
Sector
Education
Organization type
a company within a holding
Joined
Dec 2023
Message
3
#14

There are three things to check when doing this. Implementing a change request process doesn't slow things down, it speeds them up.

People defend habits, not processes. Resistance comes from there. Of course, it varies if your situation is different.

HHavva O***Expert
Job title
Marketing manager
Sector
Construction
Organization type
sole proprietorship
Joined
Nov 2023
Message
230
#15

Let me summarize the topic, since several different answers were given. If you get three different answers on a topic, the question was asked wrong.

Hope this helps.

ZZafer K***Member
Job title
Clinic manager
Sector
Law
Organization type
regional distributor
Joined
Nov 2023
Message
344
#16

Correct. Most time waste accumulates in tasks waiting for approval.

Just because everyone does it doesn't mean it's right. Hope this helps.

OOnur A***ExpertCommunity member
Joined
Nov 2025
Message
64
#17

I've been dealing with this for a long time. Payment schedules should be tied to project phases, not calendar dates.

The cheapest quote is usually the least thought-out one. Hope this helps.

RRamazan T***MemberCommunity member
Joined
Sep 2023
Message
262
#18

Thanks for writing this, that's the right way. Access credentials should be opened in the company's name, not personal accounts.

Weekly written progress reports are much more useful than asking for dates. If you post the result here, it will help others too.

FFatihExpert
Job title
Chief Technology Officer
Joined
Jun 2023
Message
204
#19

Let me speak from the other side; I'm on the supplier side. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Hasty decisions become decisions you have to fix six months later.

VVeli Y***Member
Job title
Field sales representative
Sector
Sports and fitness
Organization type
chain store
Joined
Jun 2024
Message
45
#20

Thanks that was the answer I was looking for.

Reply