Skip to content

it consulting

An architecture audit that ends in a document, not a meeting

Consulting here means an independent read of a system and a written assessment you can act on without us. This page states what we look at, who we talk to, what you receive and what the engagement explicitly does not include.

method

Four stages, each with its own output

Durations are indicative for a mid-sized system and are agreed in the statement of work before the engagement starts. A larger estate lengthens each stage rather than adding new ones.

01Typically days 1–4

Read what exists

Source repositories, infrastructure definitions, deployment history, monitoring, incident and change records, and the documents the organisation already believes are true. We read before we ask.

Output. An inventory and a list of contradictions between what is documented and what is running.

02Typically days 3–7

Interview the people who operate it

Structured conversations with engineers, operators and the business owners of the affected processes. The constraint that matters is rarely in the code; it is usually in what someone is not allowed to change.

Output. A constraint register, separating technical limits from organisational ones.

03Typically days 6–12

Write the findings down

Each finding gets a severity, an estimated effort, a business impact and the evidence behind it. A finding without evidence is an opinion and is marked as one.

Output. A findings register you can circulate internally without us in the room.

04Typically days 10–15

Options, trade-offs, roadmap

Two or three viable target states, each with what it costs in effort and what it forecloses. Then a phased roadmap, ordered so that the earliest phases reduce risk rather than add features.

Output. A roadmap in phases with a decision record for every recommendation.

questions procurement asks

Answered before you ask

Is a build proposal attached to the audit?

Not automatically. An audit whose only possible conclusion is “hire us to build it” is worth less than one that can end in “keep what you have and fix these four things”. If implementation follows, it is contracted separately.

What access do you need?

Read access to repositories, infrastructure definitions and monitoring, plus time with the people who operate the system. Production data access is not required; where a data profile is needed we work from schema, statistics and anonymised samples under a written agreement.

Who owns the output?

You do. The findings register, the options paper and the roadmap are yours, in an editable format, and you may share them with anyone including other suppliers.

Do you certify compliance?

No. 2GO Systems OÜ holds no certification and issues none. We can produce the engineering evidence that a certification body, an auditor or a data-protection officer will ask for, and we can advise on technical measures — but assessment and certification belong to accredited bodies, and legal conclusions belong to your counsel.

Outside the scope of any engagement

Published so there is no ambiguity about the kind of company you are contacting.

  • We do not provide consumer or home-user technical support of any kind.
  • We do not perform account recovery, password resets, unlocking or credential support for any product or service.
  • We do not offer remote access, device clean-up, virus removal or PC repair services.
  • We are not a helpdesk for, an agent of, or affiliated with Microsoft, Google, Apple, Amazon or any other software vendor, and we do not act on their behalf.
  • We do not sell software licences, subscriptions or hardware, and we do not take payment for support incidents.
  • We contract with legal entities only. Engagements begin with a written statement of work; nothing on this site is an offer capable of acceptance.
Request an audit scope