Blue Top ConsultingCOMPASS
Menu

INDEPENDENT SOFTWARE ASSESSMENT

See your software clearly.

Blue Top Compass examines software at three levels: what can be observed from the outside, what the repository reveals, and what requires specialist examination.

Independent. Evidence-led. Decision-focused.

THE COMPASS MODEL

Assessment at the depth you need.

Not every technical question requires the same access or effort. Start with external observations, move into the repository when needed, and add specialist examination for material decisions.

01
OUTSIDE-IN

Compass Scan

Automated external assessment

Compass Scan examines what can be observed from a deployed application, including security basics, privacy signals, runtime behaviour, performance, production readiness and public search visibility.

  • Security basics
  • Privacy signals
  • Runtime behaviour
  • Performance
  • Production readiness
  • Search Visibility
02
INSIDE THE CODE

Compass Code

Customer-controlled repository assessment

Analyse repository and engineering evidence inside your controlled environment without requiring source code to be transferred to Blue Top.

  • Architecture
  • Dependencies
  • Framework lifecycle
  • Testing
  • CI/CD
  • Maintainability
03
SPECIALIST REVIEW

Compass Assessment

Specialist independent assessment

Examine the software alongside its architecture, delivery history, vendor model, operating environment and business constraints.

  • Stakeholder interviews
  • Architecture review
  • Source analysis
  • Vendor delivery
  • Technical debt
  • Executive reporting

Observations first. Conclusions second.

Compass separates what was directly observed from what the evidence only indicates, so stronger conclusions are not drawn from weaker signals.

01

Observed

Directly established from the available evidence.

02

Indicated

Evidence suggests a condition, but further context may be required.

03

Not assessed

The available evidence is insufficient for a reliable conclusion.

Assessment activity

The activity used depends on what can be tested safely and what authority has been provided.

  1. Passive observationRecords signals visible during ordinary public application access.
  2. Safe probeUses a tightly bounded request or interaction to verify a specific observable condition.
  3. Authorised assessmentReserved for work that requires explicit authority, additional access or specialist examination.

TECHNOLOGY LIABILITY

When technical debt becomes technology liability.

Small technical compromises can remain manageable for years. But as complexity, dependencies and operational risk accumulate, remediation becomes harder, more expensive and more disruptive.

See how Compass identifies these signals →
Technology liability curve showing manageable debt progressing through accelerating cost and risk to material business exposure.
  1. 01
    Manageable DebtLow risk / high flexibility
  2. 02
    Accelerating Cost & RiskDiminishing options
  3. 03
    Technology LiabilityMaterial business exposure

The same evidence can answer very different questions.

Product owners, auditors, risk teams, developers and investors each need a different interpretation of technical condition.

Software Owners & Product Leaders

Understand where technical risk is building, what is becoming harder to support, and what deserves attention next.

Explore for Software owners

Security & Risk Partners

Connect vulnerabilities and control weaknesses to the architecture, dependencies and engineering practices that created or sustain them.

Explore for Security & risk

Developers & AI Builders

Inspect public configuration, runtime failures, dependency signals and production exposure, then move into the repository when the outside view is not enough.

Explore for Developers & AI builders

ANONYMISED CASE STUDY

What an independent technical assessment uncovered.

A business-critical healthcare platform delivered through a large outsourced software programme.

20production components400k+lines of code~300database tables
Read the case study
01

Obsolete technology

Unsupported and end-of-life components

02

Dependency exposure

Vulnerable and unmanaged packages

03

Insecure implementation

Weak or bypassed controls

04

Engineering weakness

Testing, duplication and data-integrity concerns

THE COMBINED EFFECTCompounding technology risk

Individual weaknesses reinforce one another across the software estate.

COMPARE PRODUCTS

Choose the right level of examination.

CapabilityCompass ScanCompass CodeCompass Assessment
Access
Public application reviewYesOptionalYes
Source-code assessmentNoIn your environmentAs agreed
Source code transferred to Blue TopNoNoOnly if explicitly agreed
Technical depth
Architecture reviewExternal indicatorsYesYes
Dependency analysisLimitedYesYes
Testing maturityNoYesYes
Security observationsPublic controlsRepository findingsSpecialist examination
Operational reviewPublic signalsRepository findingsStakeholder + delivery context
Context and decision support
Stakeholder interviewsNoNoYes
Vendor assessmentNoNoYes
Executive recommendationsAutomated findingsRepository findingsSpecialist recommendations
Availability
AvailabilityAvailable nowComing soonBespoke engagement
Available now

Compass Scan

Automated external assessment

Access

  • Public application reviewYes
  • Source-code assessmentNo
  • Source code transferred to Blue TopNo

Technical depth

  • Architecture reviewExternal indicators
  • Dependency analysisLimited
  • Testing maturityNo
  • Security observationsPublic controls
  • Operational reviewPublic signals

Context and decision support

  • Stakeholder interviewsNo
  • Vendor assessmentNo
  • Executive recommendationsAutomated findings
Run Compass Scan

NEXT STEP

Choose the assessment that fits the question.

Run Compass Scan Explore Compass CodeDiscuss an Assessment →