Acme
Robotics.
Evidence-based review of codebase health, architectural risk, and engineering capability — 14 repositories, 42 contributors, 180k lines scanned over six weeks.
The codebase is ship-worthy.
The org is not.
Acme's platform is architecturally sound, well-tested at the boundary, and serves production traffic without incident. Four of five pillars score at or above the stage benchmark.
Concentration risk in the engineering org is severe. 56% of commits over the last 24 months originate from two engineers (`m.tanaka`, `k.weil`). Both are non-founder employees with no equity vesting beyond Q4 2026. Departure of either is a P0 event.
Two architectural defects (FDG-0031, FDG-0044) require pre-close remediation. Cost: 2–3 engineer-weeks. With the wider register, total remediation runs ≈5 engineer-weeks; we recommend a −4% adjustment to the round and gating close on the personnel-risk plan.
SUBSYSTEMS INC.
Fitness is a trajectory, not a snapshot.
EVOFIT scores Acme as an evolving system — five dimensions derived from Wong et al.'s three modes of selection. Not a checklist: a read on whether the producing mechanism is strengthening or decaying. Acme scores 74 / 100, trajectory accelerating.
23 findings.
2 critical.
Two people hold the keys.
56% of commits across all 14 repositories originate from two engineers over the last 24 months. Both ship across billing, auth, payments, and the worker plane — the critical surface area of the business.
Bus factor measures at 1.7. Industry P50 is 3.4. Founders are aware; no retention package or knowledge-transfer plan currently exists.
- Resolve billing ↔ auth circular dependency.Extract a shared `tokens` module; remove auth's import of billing. 3 engineer-weeks.FDG-0031 · OWNER · m.tanaka
- Add idempotency keys to ledger writes.Single-trip `ledger.post-and-confirm` endpoint; retry-safe. 2 engineer-weeks.FDG-0044 · OWNER · k.weil
- Retention plan for top-2 engineers.Founder LOI: refresh grants vesting through 2028; knowledge-transfer plan filed.ORG-0002 · OWNER · founders
- Rotate & purge committed secrets.History rewrite, key rotation, secret-scanning hook in pre-commit.FDG-0033 · OWNER · security
- Index foreign keys on `ledger.transactions`.Online schema migration; expect 60% p99 reduction.FDG-0019 · 3 days
- Replace GPL-3 transitives in `core-api`.Swap `markdown-it-plus`; license audit added to CI.FDG-0027 · 1 engineer-week
- Extend trace coverage to workers and CLI.OpenTelemetry SDK across all entry points; target 95% paths.FDG-0051 · 1 engineer-week
- Pin production dependencies; add an SBOM gate to CI.Lockfile enforcement on every build and a generated SBOM checked against the license policy.FDG-0066 · 3 days
- Adopt ADR practice and backfill the top 14 decisions.Onboarding cost halves; institutional memory survives departure.FDG-0061 · ongoing
- Lift frontend coverage from 41% to 70%.Component tests on every PR; e2e past happy-path checkout.FDG-0072 · 2 engineer-weeks
- Formalize an on-call rotation and a retro / OKR cadence.No written rotation or retro cadence exists today; incident and planning load falls on the top-2 engineers.ORG-0005 · ongoing
Codebase: ship.
Org: price the risk.
We recommend proceeding to close, conditional on the four pre-close items and an executed retention plan for `m.tanaka` and `k.weil`. Material defects total ≈ 5 engineer-weeks of work. Personnel exposure is the dominant risk to the thesis, not the platform.