- Job title
- Store associate
- Sector
- Electrical-electronics
- Organization type
- 120-person company
- Joined
- May 2025
- Message
- 263
We run a London-based marketplace startup. We had an independent audit firm review the backend architecture of our mobile app, which was built by an external agency over eight months, and we paid 4,000 GBP for the audit. Two days ago, a 65-page code review report was delivered.
The report lists hundreds of items, ranging from SQL injection vulnerabilities to circular dependencies, memory leaks to code smells. There are pages of colorful charts and severity levels like critical, high, medium, but as a non-technical founder, I can't tell what is a genuinely urgent fire and what is just a quest for theoretical perfection.
If I go to the dev agency and say "fix everything," an argument will break out and the project will stall for weeks. How should I rationally read this code review report, which items should I insist the agency fix unconditionally, and which ones can I ignore for now?