If your technology supplier walked out tomorrow, could you carry on?
Most companies cannot answer that. Not because the answer is bad — because nobody has ever been asked to check. Ten questions, ten minutes, one number. Nothing you enter leaves this page.
It is a control problem, and it is invisible until the day it is not.
The supplier owns the work
The repository sits in their organisation. The cloud account is billed to them. The contract assigns intellectual property on final payment rather than on creation. None of this matters while everyone is friendly — and all of it matters at once when they are not.
Nobody can enumerate the access
No written register of who holds the highest-privilege credential for each production system. You cannot revoke access you cannot list, and you cannot hand over a system you cannot describe. This is the most common gap I find, in companies of every size.
The exit clause was never written
Notice period, handover deliverables, the format your data comes back in, what happens during a dispute. Written when everyone is friendly, read when nobody is. If it is not in the contract, the leverage belongs to whoever holds the credentials.
Where this came from
Why I built this
In 2020 I was brought into a company whose development team — hired outside the agency that was supposed to hold the contract — refused to continue work and threatened to publish everything built up to that point. The company had no contractual position to answer with. We resolved it and planned what came next, and their CEO and COO put that in writing afterwards.
It was not a billing dispute. It was a supplier holding a company's own product hostage, and every control that would have prevented it is on the list below. None of them are expensive. All of them have to exist before you need them.
Developers from a different country refused to work and threatened to leak the work done up to that point to the public. They were hired outside of the freelancer agency, which caused significant issues when trying to make a formidable case.
From a signed reference, January 2021
Self-assessment
The checks
Pick which one you are — the questions change, because the two fail in different ways. Answer honestly: not sure scores as no, since a control you cannot confirm today is one you cannot rely on during a dispute.
0 of 10 answered
01People
Can you name every person currently working on your product?
If you cannot list them, you cannot tell a team of six from a team of two with four names on an invoice. This is the fastest way to find out you are paying for people who do not exist.
02People
Have you been on a single call with all of them at once — not just the account manager?
An account manager is a layer between you and the work. A call with everyone takes ten minutes to arrange and is remarkably hard to fake.
03People
Have you verified your supplier is a real registered company — filings, registered address, named directors?
It is free, it takes two minutes at Companies House or the local equivalent, and almost nobody does it. If you ever have to enforce anything, this is what you enforce it against.
04People
Does each discipline — frontend, backend, mobile, design, payments — have somebody who actually specialises in it?
The same two or three people building a website, a mobile app, a payment gateway and a brand simultaneously is the clearest tell that you are being sold a team that does not exist. Payments in particular is not a general skill.
05Money
Can you break your last invoice down line by line — what each charge was for, and who did the work?
A lump sum for a month of effort is not an invoice, it is a request. You cannot dispute what you cannot itemise.
06Visibility
Is the work tracked in a ticket system your own company owns and can read without asking?
If the tickets live in your supplier's workspace, you lose the entire history of your own project on the day you part company — including every decision and every thing you already paid to have discussed.
07Money
Have the last three deliverables arrived on time, on budget and working?
One slip is a project. Three, each explained by changing requirements, is a pattern — and the explanation is doing a lot of work.
08Money
Have your payment terms stayed exactly as agreed, with no mid-project demand to change them?
Pressure to move money forward mid-build is the earliest warning sign there is. It usually means their cash problem is about to become your delivery problem.
09Visibility
If you asked tomorrow — show me everything, line by line, and explain it like I am five — could they do it, without preparation?
This is not a question, it is a test, and you can run it this week for nothing. A team that knows what it built can do it from memory. Anyone who needs a week to prepare is building the answer, not showing you one.
10Contract
If you had to enforce your contract, do you know which country's courts would hear it — and has anyone checked that is realistic?
Where a team sits matters far less than whether the agreement is enforceable where they sit. Plenty of excellent teams are overseas; the risk is a contract with no forum, not a passport.
11People
Can you list every external supplier with access to production, and what each one costs you per year?
Most organisations can produce the invoice list or the access list, but not the two joined together. The gap between them is where both the spend and the risk hide.
12People
Does one named person own that supplier register — and was it last updated within ninety days?
A register owned by everybody is owned by nobody. If the last edit predates your last three contract changes, it is a document about the past.
13Access
If a supplier's engineer left their company today, would you know within one working day whether their access to your systems had been removed?
Their HR process is not your access control. Leavers at third parties are the most reliably forgotten accounts in any estate.
14Money
Do you know which lines of your cloud, hardware and licensing spend are actually in use — and what would break if each were switched off?
The commonest finding in this work by a wide margin: reserved capacity, duplicated tooling and licences for people who left, renewing quietly because nobody can say what depends on them.
15Continuity
For every business-critical system, is there more than one person who can operate it?
One person leaving should be a resourcing problem, not an outage. Key-person risk concentrates quietly and is obvious only in hindsight.
16Visibility
Has anyone independent of the team that built it reviewed your architecture in the last two years?
A team reviewing its own decisions is not an audit, however good the team. The value is in the questions nobody inside has a reason to ask.
17Continuity
Could you bring your largest supplier's work in-house within one quarter, using documentation you already hold?
This is the number that decides your negotiating position at every renewal. A supplier who knows you cannot leave prices accordingly, and is usually right.
18Money
If the board asked for every technology cost line by line, each with a named business owner, could finance produce it this week?
Unowned cost lines never get cancelled, because cancelling them is somebody's risk and keeping them is nobody's.
19Ownership
Is your source code in a repository owned by your company's own account, rather than a supplier's?
If the repository lives in the supplier's organisation, your code is their asset in a dispute. Getting it back becomes a negotiation instead of a right.
20Access
If your main supplier's lead engineer deleted their account tonight, would someone at your company still hold owner-level access to the repository, the cloud account and the domain?
Administrator is not owner. An administrator can be removed by the owner; the owner cannot be removed by anyone. Most companies have the first and believe they have the second.
21Access
Do you have a written register of every production system, who holds the highest-privilege credential for it, and how that credential would be revoked?
You cannot revoke access you cannot enumerate, and you cannot hand over a system you cannot describe. Ten minutes of work that almost nobody has done.
22Access
Have you personally logged in with your highest-privilege credentials in the last ninety days — and did they still work?
Being handed a password is not the same as having access. The usual version: super-admin credentials are given over at handover, quietly rotated a month later, and nobody finds out until the day it matters. I have sat with a client who was certain he had full access and discovered that every credential he held, SSH included, had stopped working. An untested credential is a belief, not a control.
23Access
Do you hold root or SSH-level access to the servers your product runs on — with read and write — rather than only an administrator login to the application?
An admin account inside the application is granted by whoever controls the machine, and can be taken back the same way. Server-level access is the layer underneath that decides who can actually rebuild, move or recover the thing. Plenty of owners have the first and assume it implies the second.
24Contract
Do your contracts assign intellectual property to you on creation, rather than on final payment?
Assignment on payment means one disputed invoice leaves the supplier owning your product. It is standard wording and it is very rarely read before signing.
25Continuity
Could a new engineering team build, test and deploy to production using documentation you already hold — without asking your supplier anything?
Code you cannot deploy is not an asset. An undocumented deployment path is the most effective form of lock-in there is, and it is usually accidental.
26Contract
Do your contracts define the notice period, the handover deliverables, the format your data is returned in, and what happens during a dispute?
The exit clause is written while everyone is friendly and read when nobody is. If it is not there, the leverage belongs to whoever holds the credentials.
Your score
0/0
In control
You could change supplier without stopping. That is rare — confirm the register is current rather than historic, and run this again before your next contract renewal.
Recoverable
A walkout would cost you weeks, not the company. Each gap below is a few days of work and far cheaper to close now than to argue about later.
Exposed
A dispute would stop your roadmap and leave your supplier holding the stronger position. Close the ownership and access gaps first — those are the ones that decide who has leverage.
Hostage
Your supplier could end your company, and it would not take malice to do it. One disputed invoice or one resignation would be enough. Start with ownership: repository, cloud account, domain.
In control
You can account for what you buy, who holds access and what would break. Keep it that way by putting a date on the register and an owner's name against every cost line.
Managed
The structure exists. The gaps below are the ones that turn a supplier change from a decision into a project, and they are the cheapest things on your roadmap to fix.
Sprawling
You are paying for more than you can account for and depending on more than you can name. This is where the money is — unowned cost lines and forgotten third-party access, both renewing quietly.
Blind
You cannot currently say what you are buying, who has access to production, or what would break if you stopped paying for it. That is not a technology problem; it is a governance one, and the board owns it.
Scored in your browser. Nothing is sent anywhere unless you choose to send it below — and you can see exactly what would go.
Want the full written report?
Your score is above, free and yours. If you would like it verified properly — the evidence behind each answer, and the two gaps worth closing first — tell me where to send it.
Got it.
Your score and answers are with me. I read every one of these myself — no assistant, no CRM sequence — and I will come back to you within two working days with the two gaps worth closing first.
If it is urgent, or you would rather not wait, email hello@naushad.co.uk directly and put EXIT TEST in the subject.
The engagement
What the full audit is
The self-assessment tells you where you stand. The audit proves it — because the answer a company believes and the answer its systems give are frequently different.
Evidence-backed verification of all ten checks — I look at the accounts, not the assumptions
Contract review: IP assignment trigger, exit terms, notice, data return, dispute position
Written register of every production system and who holds the top-level credential
Named single points of failure across people, accounts and undocumented systems
A remediation order of work, cheapest and highest-leverage first
A short board-ready summary your CFO can act on without a technical translator
Duration
10 working days
Fee
Fixed, quoted up front
Delivered to
You alone, under NDA
Coverage
UK, Europe and remote
No commissions
Independence is the product
Almost everyone who tells a company what technology to buy is paid by somebody who sells it — referral fees, reseller margin, partner tiers. That is not always dishonest, but it is never neutral, and you are rarely told. So this is a contractual term of every engagement, not a value on a wall:
No commission, referral fee or reseller margin from any vendor, ever
No partner tier, certification agreement or rebate with anything I might recommend
I recommend and evidence; I never authorise a change to your production systems
If the honest answer is that you do not need me, that is the answer you get
Questions
Before you ask
Who is this for?
Any company whose product is built or run by somebody outside it — a development agency, a freelance team, an outsourced platform partner, or a single contractor who knows more about your systems than you do. It applies equally to a scale-up with one supplier and an enterprise with forty.
Is the self-assessment really private?
Your answers are scored entirely in your browser — no answer is transmitted as you click, and the score is never gated behind an email address. There is an optional form under the result if you want the written report, and it shows you the exact text it would send before you send it. Including the checks you failed is a tick box you control.
Will this make my CTO or supplier defensive?
It should not, and it is deliberately framed to avoid it. The question is not whether anyone made bad decisions; it is what happens if a supplier leaves. Most good CTOs are already worried about exactly this list and have not had the budget conversation to fix it. The audit gives them that conversation.
Do you charge a share of the savings you find?
No, and I would not. A percentage of savings creates a direct incentive to recommend cuts that are not safe, which destroys the only thing that makes the audit worth having. The fee is fixed and quoted before the work starts.
What happens if you find nothing?
You get a report saying so, and it is worth the fee — an evidenced clean bill of health is exactly what a board, an investor or an acquirer wants to see, and you cannot produce one after the fact.
Can investors commission this for a portfolio company?
Yes, and it is often the better route. The same ten checks work as pre-investment technical due diligence and as an annual health check across a portfolio. Ask about portfolio terms.
Start with the number
Take the test above. If it comes back Exposed or Hostage, send me the score and I will tell you which two gaps to close first — no charge, no meeting required. If you would rather have it verified properly, that is the audit.