Skip to content
← All posts
7 min read

What is a software audit? A buyer's guide before acceptance or renewal

A useful audit answers a business decision with evidence. It does not hand you a longer checklist.

What a professional software audit checks, what evidence it needs, and when to use one before buying, accepting, or renewing software.

A software audit is an independent review of what a product does, who controls it, how it handles data, whether it can recover, and how the evidence compares with what the vendor promised. The report should help you make one decision: accept the build, renew the contract, buy the product, fund the fix, or walk away.

The word audit is used for many different jobs. A financial audit, penetration test, accessibility review, source-code review, and privacy-readiness check can all inspect software. Start by naming the decision you need to make. Scope follows from that decision.

Start with the decision, not the checklist

DecisionQuestion the audit must answerUseful evidence
Accept a delivered productCan we own, run, recover, and change this without the vendor?Domain and cloud ownership, source access, deployment instructions, restore test
Renew a SaaS vendorAre the security, data, recovery, and service claims supported?Configuration, data-flow map, incident process, restore records, vendor terms
Buy or investWhat technical risk and hidden operating cost come with the product?Architecture, dependency inventory, cloud spend, access model, issue history
Put an AI agent into productionWhat can the agent read, write, approve, or trigger when a prompt goes wrong?Tool permissions, approval rules, eval results, logs, kill switch, data boundaries

A checklist can support the work, but it is not the outcome. A hundred green boxes do not answer whether the buyer can recover the product after the vendor disappears. One missing domain account can matter more than ninety passed style checks.

Evidence comes before the verdict

Each finding should name the claim, status, severity, evidence, and next test or fix. Missing evidence stays missing evidence. It does not become a confirmed failure because the reviewer could not find a document.

ID: GW-REC-02
Claim: Daily backups are recoverable
Status: Needs evidence
Severity: High
Seen: Backup job screenshot
Missing: Dated restore result
Next test: Restore into an isolated environment

This format makes the report challengeable. The vendor can supply the missing restore result. The buyer can ask why the severity is high. A second reviewer can repeat the test without guessing what the first reviewer meant.

What a professional software audit usually covers

  • Ownership: domain, cloud, repositories, billing, recovery contacts, and administrator access
  • Security: authentication, secrets, encryption claims, permissions, logging, and incident paths
  • Recovery: backups, restore tests, recovery time, deployment instructions, and single-person dependence
  • Data: collection, storage, vendors, regions, retention, deletion, exports, and access
  • Architecture: major services, dependencies, failure paths, maintainability, and operating cost
  • Product behavior: the customer journey, important claims, performance, and obvious delivery gaps
  • Fix order: what to change first, what can wait, and what still needs evidence

The written scope should also say what is excluded. A reviewer cannot inspect a cloud account, repository, contract, or restore process that the owner did not authorize or supply.

Three useful depths

DepthTypical useGattyWorks starting point
SurfaceA fast outside-in check before accepting delivery or deciding whether deeper work is justified$399, first findings in 48 hours
DeepEvidence behind security, recovery, data-flow, and dependency claims$999, four days
FullArchitecture, AI, governance, privacy readiness, vendor continuity, and technology spend together$2,499, one week
Starting prices exclude applicable taxes. The signed scope fixes the exact coverage, access, exclusions, price, and delivery date.

The right depth is the lightest one that can answer the decision. A public marketing site may need a Surface Audit. A SaaS product holding customer records usually needs evidence that is not visible from the outside.

What this kind of audit does not replace

Use a specialist firm when you need a formal certification, regulated attestation, dedicated penetration test, financial audit, or legal opinion. A software audit can identify that one of those services is needed. It should not borrow the language of a credential it did not issue.

An audit is also point-in-time. A passing restore test today does not prove every future backup will restore. The report should record the test date, environment, evidence, and owner so the team can repeat it.

What to prepare before hiring an auditor

  1. Write the decision you need to make in one sentence.
  2. List the vendor's important claims and where each claim appears.
  3. Confirm who can authorize access to the product, repository, and cloud accounts.
  4. Collect architecture notes, vendor contracts, runbooks, and recent cost exports.
  5. Remove secrets and personal data from anything sent before secure access is arranged.

You can inspect the format before sharing anything. Read the synthetic sample audit report, then compare the three software audit scopes and fixed starting prices. Send only the product URL and your main concern first. Do not email passwords, API keys, or production data.

Software auditsVendor riskSecurityFoundersSoftwareAuditVendorRiskSaaSTechDueDiligenceGattyWorks

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.