Service

Code Insights

Legacy code intelligence

We analyse legacy, inherited and undocumented codebases and explain what they actually do. Start with a free analysis of up to 500 lines of your code.

The problem

You cannot safely change what you do not understand.

The systems businesses depend on most are often the least understood: undocumented, written in languages few people still use, and maintained by people who have moved on. Changes become risky, migration plans become guesswork, and critical knowledge sits with a handful of people.

What it does

Clarity about a codebase, backed by evidence.

Free initial analysis

Up to 500 lines analysed at no cost and under NDA, so you can judge the value on your own code before committing.

Architecture recovery

How the system is structured, where its components sit and how they interact.

Business logic extraction

The business rules embedded in the code, surfaced and explained, along with what depends on them.

Dependency and data-flow mapping

Modules, jobs, services, databases and external systems, and where a change will ripple.

Risk and quality insight

Fragility, complexity, duplication, dead code and hardcoded assumptions, flagged before they cause trouble.

Plain-English documentation

Findings written for developers, architects and business stakeholders alike.

How it works

  1. Choose the route: we deploy a guardrailed analysis engine, trained for the language in question, into a pre-production or test environment, or you share a copy of the codebase under NDA, by secure transfer or on encrypted media by courier.
  2. The engine maps the codebase: its languages, structure, patterns and dependencies.
  3. It traces business rules, data flows and risks, and our engineers review and verify every finding.
  4. You receive a detailed report: how the system works, where the risks are, and what should happen next.
Route AIn your environmentWe deploy a guardrailed analysis engine, trained for the language in question, into a pre-production or test environment. Your code stays where it is.
Route BSecure copyWhere security policy prevents that, you share a copy of the codebase under NDA through secure transfer, and we analyse it in our own controlled environment.
Route CBy courierFor the most sensitive systems, the codebase arrives on encrypted media by secure courier and is analysed offline, on equipment with no network connection.

What the report covers

Every report is scoped to what you need. A full analysis includes:

Understand
  • Function descriptions
  • Business rules, traced to source
  • Data lineage and usage
  • Interfaces and integrations
  • Batch schedule and job dependencies
Quality
  • Coding standards and compile-readiness
  • Dead code and dead ends
  • Loops and control flow
  • Complexity and duplication
  • Error-handling gaps
  • Hardcoded values
  • Performance hotspots
Risk and compliance
  • Security vulnerabilities
  • Personal data map
  • Concurrency and locking
  • Date, rounding and precision
  • End-of-life platforms and components
  • Third-party licences
  • Logging and audit trail
Plan
  • Impact analysis
  • Migration readiness by module
  • Effort estimate
  • Test gaps and suggested test cases
  • Documentation drift
aevris · Code InsightsReport CI-0142 · Confidential
Claims Settlement Platform
Legacy code analysis, full codebase. Fictional example.
412programs
1.84Mlines of code
3languages
27batch jobs
9data stores

01Executive summary

The platform is stable and its settlement logic is sound, but knowledge of it is concentrated in very few places. It can be modernised safely, provided three issues are dealt with first.

  • Two programs hold 61% of the business rules and change most often. Any migration should start with a full specification of these two.
  • 147 business rules extracted. 23 of them exist only in the code, with no matching documentation.
  • 11% of the code is unreachable and can be retired before migration, reducing the effort.
  • Two nightly batch jobs write to the same file without locking. This is the most likely cause of the month-end reconciliation errors reported by Finance.
Maintainability42 / 100
below average for its size
Documented modules4%
17 of 412 programs
Unreachable code11%
safe to retire
Complexity hotspots17
4 are business-critical

02Dependency map (excerpt)

Intake12 programsValidation31 programsRating engine58 programs!Settlement64 programs!Document storeexternalReserves22 programsPayments40 programsBank gatewayexternalBatch N07nightly!Batch N12nightly!SETTLE.DAT (shared)Ledger interface9 programshotspot: change carries high riskexternal systemunsafe dependency

03Business rules (excerpt of 147)

BR-014Claims over £25,000 need a second approver before payment is released.SETTLE-VAL · line 1182documented
BR-031A claim reopened within 30 days reuses its original reserve instead of creating a new one.RESERVE-CALC · line 407code only
BR-052Payments to accounts outside the UK are held for two working days before release.PAY-OUT · line 96code only
BR-077A fixed tax rate of 17.5% is still applied to policies issued before 2011.RATE-CALC · line 2210outdated value

04Risk register (top three)

CriticalBatch N07 and N12 write to SETTLE.DAT without locking.Serialise the jobs or add locking. Fix before any migration.
High318 hardcoded values: rates, thresholds and account codes.Move to managed configuration, starting with the 41 used in settlement.
Medium44 programs with no known owner or recent change history.Assign ownership and add them to the knowledge base.

05Security and data handling

Personal data found in 14 fields across 5 data stores. Two of those fields leave the platform in a nightly extract.

SEC-03Database credentials are stored in plain text in three programs.DB-CONN · line 58credentials
SEC-07Claim search builds database queries from user input without validation.CLM-SEARCH · line 311injection risk
PD-02Bank details and dates of birth go to the document store in an unencrypted extract.EXTRACT-N09 · line 140personal data
CAL-04Premium totals are rounded at every step instead of once, causing penny differences on large batches.PREM-TOT · line 882rounding

06Migration readiness

Intakemove as is
Validationrefactor
Rating enginerewrite
Settlementrefactor
Reportingreplace
Unreachable coderetire

07Recommended next steps

  • Fix the batch file conflict (critical, low effort).
  • Remove credentials from the code, add query validation and encrypt the nightly extract.
  • Specify the rating engine and settlement rules in full, with the business owners.
  • Plan a staged migration with Code Revive, starting with intake and validation.
Produced by the aevris analysis engine and verified by our engineers.Page 1 of 38

Scroll the report. Simulated example with fictional data.

Where it delivers value

Code Insights fits wherever a codebase matters more than it is understood:

  • Legacy and mainframe systems, in any language
  • Undocumented, inherited or proprietary codebases
  • Pre-migration assessment and planning
  • Technical due diligence before acquisition or replacement
  • Audit, compliance and resilience reviews
  • Business-critical systems where the expertise is ageing

The aevris approach

Every codebase is quoted individually. A small sample might produce a concise explanation and risk summary; a larger system can become a knowledge base, an architecture map, a migration plan or an onboarding pack.

Code Insights is usually the first step before Code Revive: it establishes what can move, what should be rewritten and where the real effort sits.

Talk to us about Code Insights

Send us up to 500 lines you are unsure about. We will show you what the first analysis reveals.