Software reverse engineering services for the system nobody documented and everybody depends on. Legacy code with no source, an undocumented integration, a binary someone left behind when they left the company — we trace it, document it, and hand you a costed choice between maintaining, migrating and replacing it. We work on systems you own or are licensed to analyse, for interoperability, maintenance and migration.
A black box, opened up — behaviour mapped, protocols documented, and a clear, low-risk plan to maintain, migrate or replace it.
Undocumented systems traced and documented.
We map how it actually talks.
Mobile and native binaries — we built APK tooling.
Maintain, migrate or replace — with a plan, not a rewrite.
Not a rewrite quote. Application reverse engineering and code reverse engineering services give you something more useful first: an accurate picture of what the system does, what depends on it, and where the risk sits. As a reverse engineering company we do the software archaeology services nobody else wants to — reading a codebase whose authors are long gone and turning it into something a team can reason about. Security-focused reverse engineering is available where the question is what a system exposes rather than how it works.
Legacy system reverse engineering and legacy code analysis when there is source, lost source code recovery when there is not. Undocumented codebase analysis, legacy application audit and legacy system recovery for the platform that has been running unattended for a decade. The output is legacy software documentation your team can actually use, not a diagram that ages out in a month.
Binary analysis services for native and mobile artefacts — we have built our own APK-analysis tooling, so binaries do not frighten us. Protocol reverse engineering and network protocol analysis when two systems talk in a language nobody wrote down. API reverse engineering for undocumented API integration and proprietary protocol integration. File format reverse engineering and data format recovery when the only copy of your data is in a format the vendor no longer supports. Firmware analysis services and embedded system reverse engineering where the device is the documentation.
Desktop app reverse engineering, web app reverse engineering and mobile app reverse engineering analysis. Hardware protocol integration for the instrument, reader or controller that speaks a serial dialect from 1998 and will outlive us all.
Legacy database reverse engineering and schema recovery services when the schema is undocumented, the column names are abbreviations nobody can expand, and the business rules live in triggers. This is usually the step that unblocks a migration everyone had written off.
Codebase documentation services, software dependency mapping and system behavior documentation — the artefacts that make reverse engineering for maintenance possible for your own team afterwards. Technical due diligence services for investors and acquirers who need to know what is really inside a codebase before the money moves.
The point of reverse engineering for migration is to remove the guesswork. Legacy migration planning, legacy modernization consulting and legacy replacement planning based on evidence, with a legacy system risk assessment behind each recommendation. Where a clean break is not possible we build the bridge: compatibility layer development, legacy integration bridge work, legacy system integration and system interoperability consulting so old and new run side by side. Vendor lock-in escape consulting where a supplier holds your data hostage by format. Safe legacy migration services and legacy-to-modern rewrite planning mean you move in stages you can reverse.
Almost always a fixed-scope investigation first — a defined question, a defined budget, a written answer — because open-ended reverse engineering is how budgets disappear. From there you can hire reverse engineering experts for delivery, or keep us as a reverse engineering consultant alongside your team. We take on reverse engineering services USA, UK and EU clients, and we only work on systems you own or are contractually entitled to analyse.
Legacy recovery and protocol analysis on undocumented systems.
Binary and mobile-app inspection — we've built APK-analysis tooling.
Interoperability work so old and new systems talk.
Documentation that turns a black box into something maintainable.
The whole practice, in one place. If what you need is on this list, we have shipped it before — and if it is not, ask anyway, and we will tell you honestly whether it is ours to take.
We're publishing work in this area — meanwhile, tell us what you need and we'll walk you through relevant examples on a call.
For systems you own, and for interoperability, maintenance and security purposes, it is routine and lawful in most jurisdictions. We ask for confirmation that you own the system or are licensed to analyse it before starting, and we decline work aimed at circumventing licensing or copying someone else's product.
The original source, rarely. A working, documented equivalent, usually yes — through binary analysis and behavioural tracing. For most clients that is the real goal anyway: something maintainable, not the exact original file.
In stages. The first is a fixed-fee investigation that answers a specific question and tells you what the next stage is worth. You get a decision point with real information at the end of each one rather than an open meter.
Yes — that is one of our most common jobs. We observe the traffic, map the protocol, document the endpoints and build you a client with the edge cases and failure modes written down.
Often not, or at least not all at once. Rewrites overrun because the old system's undocumented behaviour is the requirement nobody captured. We map it first, then recommend maintain, bridge or replace — with the cost of each.
Always, before anything is shared. This work involves your most sensitive systems and we treat it that way.
Tell us what you're trying to ship. We'll come back with an honest, costed plan — no jargon.
Book a call