The Integration Audit is a standalone, fixed-price assessment of an integration you inherited or had built elsewhere, from $2,400 + GST. It tests the integration against vendor contracts, real workflows, rate limits, failure modes and security, and delivers a scored, evidenced, severity-rated report with a fix list any developer can act on.
Key takeaways
- 01The Integration Audit costs from $2,400 + GST and does not require us to have built the integration.
- 02It uses the same method as the SEO and AI readiness audit: fixed checks, recorded evidence, severity ratings and a score.
- 03Every finding names the failure it would cause, the evidence, the severity, the effort and an owner.
- 04The report and the test suites are yours to hand to any developer; the fee is not credited because the audit is a complete deliverable.
What you receive
- 01Inventory of every integration in scope with its systems, direction, authentication method and owner
- 02Contract test results against each vendor API, with every mismatch recorded
- 03End-to-end test results through each real workflow, in a sandbox or with safe records
- 04Rate-limit findings against each vendor's documented caps
- 05Failure-mode findings for token expiry, webhook retry, partial failure and duplicate delivery
- 06Security findings covering IDOR exposure, client-side tokens and credential handling
- 07Monitoring and alerting gap assessment
- 08Scored report with a severity-rated findings register and a prioritised fix list
- 09Recorded walkthrough call
- Service type
- Standalone integration audit
- Area served
- Australia
Who the integration audit is for
You have an integration that moves money, bookings or customer records, and you did not build it. The agency has moved on, the developer left, or it was set up years ago and nobody is sure how it works. It runs, mostly: an invoice is occasionally doubled, a booking goes missing, someone re-authorises a connection without knowing why. You want to know whether to trust it, from evidence rather than reassurance.
The audit assesses the integration as it is, in your systems, and reports what would fail, how badly, and what it takes to fix. It works on a connector built on Zapier, Make or n8n, a coded integration between a website and Xero, HubSpot or ServiceM8, or a multi-system sync, with the depth adjusted to what is there.
What the audit tests
The method is the one we use for the Standard SEO & AI Readiness Audit: fixed checks, recorded evidence, severity ratings and a score. Every check is the one we run on integrations we build ourselves.
- Contracts: tests written against each vendor API and run, recording where the vendor's current behaviour no longer matches what the code assumes.
- Workflows: real records pushed through each workflow end to end, in a sandbox or with safe records, comparing what arrives with what should have. Field mismatches, silently dropped records and lossy transformations are captured here.
- Limits: the integration's behaviour at each vendor's published call limits. Queue and back off, or drop records.
- Failure modes: a token that expires mid-run, a webhook delivered twice after a timeout, a batch that fails halfway, the same event arriving twice. An integration that creates two invoices from one event fails.
- Security: where credentials live and how they are used. Tokens in client-side code or a spreadsheet are findings of the highest severity. Every exposed endpoint is tested for insecure direct object references, and credential rotation is checked for whether it is possible without a code change.
- Monitoring: whether health checks exist, whether alerts reach a person, and whether a failed run can be identified and replayed. If a customer would be the first to notice an outage, that is a finding.
How findings are scored
Each finding carries the failure it would cause, the evidence that it exists, a severity, an effort estimate and an owner. Findings roll up into a score across contracts, workflows, limits, failure modes, security and monitoring, weighted so a credential in a browser bundle outweighs a missing alert. Page one is for whoever is accountable for the systems; the following pages are for whoever will do the work. Where the right fix is a rebuild rather than a patch, the report says so and names the tier, whether a standard integration build or a two-way sync and multi-system integration.
What we need from you
Access to the platform accounts on each side of the integration, granted as read access to an account we name, and a description of what the integration is supposed to do in plain terms. Code access helps but is not required: contract, workflow, limit and failure-mode tests run from the outside against the vendor APIs and the workflow itself. With code we can confirm credential handling and object-reference findings directly rather than inferring them. Where a vendor sandbox is needed and the vendor charges for it, that is named in the quote and settled before we begin.
After the audit
The audit is a complete deliverable, so its fee is not credited against later work; that is the opposite of integration discovery and scoping, which is partial work toward a build. Fixes can be quoted from the report without a separate scoping engagement, and the integration support retainer picks up from the audit if you want the integration kept healthy rather than repaired once. You own the report, the test suites written to produce it, and the accounts we were given access to. Third-party fees the audit incurs, such as a vendor sandbox that is charged for, are named in the quote.
Frequently asked questions
What does an integration audit cost?
From $2,400 + GST, fixed before we start. The figure depends on how many systems and workflows are in scope: a single connector between a website and a CRM is the starting price, a multi-system sync with several vendors sits above it. The scope and the price are confirmed in writing before work begins.
Do you need access to the code?
It helps but it is not required. Contract, end-to-end, rate-limit and failure-mode tests run against the integration from the outside, using the vendor APIs and the workflow itself. Code access lets us confirm credential handling and IDOR findings directly rather than inferring them. Access to the platform accounts is required, and we work with read access you grant.
Will you fix what the audit finds?
We can, and the fixes can be quoted from the report without a separate scoping engagement because the audit has already done that work. The report is written so any developer can act on it, including one who is not us, so you are free to have the fixes done elsewhere.
Is the audit fee credited against a rebuild?
No. The audit is a complete deliverable: a scored report, a findings register, the test results and the evidence behind them. That is the same rule as the SEO audit and the opposite of integration scoping, which is partial work toward a build and is credited when the build proceeds within 30 days.
Who owns the report and the test suites?
You do. The report, the findings register, the evidence and every test suite written to produce them are handed over, along with the accounts and credentials we were given access to. Third-party fees the audit incurs, such as a vendor sandbox that is charged for, are named in the quote and who pays is settled in writing first.
Related
Services
Standard SEO & AI Readiness AuditFixed-price SEO and AI readiness audit for sites of up to 50 pages. Crawl, rankings baseline, AI visibility testing and a 90-day roadmap for $1,950 + GST.
Services
Integration Support RetainerMonth-to-month monitoring, credential rotation and vendor change response for your integrations, from $250 a month + GST. No lock-in, you own every account.
Services
Standard Integration BuildCustom-coded integration between your website and one system, one direction, from $3,500 + GST. Tested against the vendor API and monitored after launch.
Services
Two-Way Sync and Multi-System IntegrationBidirectional and multi-system integration with conflict handling and reconciliation, custom-coded and fully tested, from $8,000 + GST.
