- Anti-Corruption LayerRead Anti-Corruption Layer
A translation boundary that keeps a new component from adopting a legacy system's data model, terminology, or interface. It allows both systems to communicate during an incremental migration.
- API IntegrationRead API Integration
A connection that lets a SaaS product and another system exchange data or trigger actions through defined interfaces.
- Attack SurfaceRead Attack Surface
Attack surface is the complete set of entry points, interfaces, identities, and dependencies through which a system can be reached or affected.
- AuthenticationRead Authentication
Authentication is the process a system uses to verify that a user, service, or device is who it claims to be before creating a trusted session.
- AuthorizationRead Authorization
Authorization is the set of rules that decides which data and actions an authenticated user or service may access.
- Bounded ContextRead Bounded Context
A boundary within which a domain model and its terminology have a specific meaning. Mapping bounded contexts helps a legacy team separate business capabilities without assuming the current code structure is correct.
- Branch by AbstractionRead Branch by Abstraction
A technique for replacing a component behind a shared abstraction while old and new implementations coexist. It allows a large legacy change to be delivered through small steps on the main development line.
- Build vs BuyRead Build vs Buy
A structured comparison between keeping or buying a software product and building a system the business owns.
- Characterization TestRead Characterization Test
An automated test that records what existing software currently does. It gives legacy refactoring a behavioural baseline without assuming that every observed result is correct or desirable.
- Code CouplingRead Code Coupling
The degree to which parts of a software system depend on each other's implementation or behaviour. Strong coupling can make a local change spread across a legacy codebase.
- Code HotspotRead Code Hotspot
A part of a codebase that changes frequently and carries significant complexity or defect risk. Hotspot analysis helps an audit focus attention where maintenance pressure and difficult code overlap.
- Cross-Site Request ForgeryRead Cross-Site Request Forgery
Cross-site request forgery is an attack that causes a user's browser to submit an unintended authenticated request to another site.
- Cross-Site ScriptingRead Cross-Site Scripting
Cross-site scripting is a browser vulnerability in which untrusted content is rendered as executable page code within a trusted website.
- Cutover PlanRead Cutover Plan
The timed sequence of decisions and actions used to move users, data, and integrations from a SaaS product to its replacement.
- Cyclomatic ComplexityRead Cyclomatic Complexity
A metric based on the independent paths through a unit of code. In a legacy audit, it helps locate logic that may be difficult to understand, test, and change safely.
- Data MappingRead Data Mapping
A specification that connects data fields, values, relationships, and rules in a SaaS product with their destination in a replacement system.
- Data MigrationRead Data Migration
The controlled transfer of business data from a SaaS product into a new system, including selection, transformation, validation, and cutover.
- Data ValidationRead Data Validation
The checks that confirm migrated data is complete, accurate, connected, accessible, and usable in a SaaS replacement.
- Dependency GraphRead Dependency Graph
A map of the relationships between modules, services, libraries, and data stores in a software system. It helps a legacy codebase audit reveal what a proposed change can affect.
- Dependency RiskRead Dependency Risk
The exposure a product carries through the third-party packages it depends on. AI-generated code tends to add dependencies quickly, so the surface is usually wider than the team expects.
- Input ValidationRead Input Validation
Input validation checks that data entering a system has the expected type, shape, range, and meaning before the system uses it.
- Integration TestingRead Integration Testing
Testing that confirms the replacement and its connected systems exchange data and complete required workflows correctly.
- Modular MonolithRead Modular Monolith
A single deployable application divided into modules with explicit responsibilities and interfaces. It can restore change boundaries inside legacy code without introducing distributed services.
- MonolithRead Monolith
A software application deployed as one unit, with features that share the same release lifecycle. A legacy audit maps its internal boundaries before deciding whether to refactor modules or extract services.
- Parallel RunRead Parallel Run
A transition period in which a SaaS product and its replacement operate together so outputs and working procedures can be compared.
- Path TraversalRead Path Traversal
Path traversal is a vulnerability in which untrusted path input reaches files or directories outside the location an application intended.
- RefactoringRead Refactoring
A disciplined change to the internal structure of existing code without changing its observable behaviour. In a legacy codebase, refactoring makes selected areas easier to understand, test, and modify.
- Rollback PlanRead Rollback Plan
A predefined procedure for restoring safe operation in the former SaaS product when a replacement cutover cannot continue.
- Secrets ManagementRead Secrets Management
Secrets management controls how credentials, keys, tokens, and certificates are stored, delivered, rotated, and revoked.
- Service ExtractionRead Service Extraction
The staged movement of a capability from an existing application into a separately deployed service. It requires a defined boundary, redirected callers, and clear data ownership.
- Shared DatabaseRead Shared Database
A database that multiple modules or applications access directly. In a legacy migration, shared reads and writes can hide ownership and constrain the order in which capabilities move.
- Single Sign-OnRead Single Sign-On
An authentication arrangement that lets users access connected applications through one identity provider session.
- Single Source of TruthRead Single Source of Truth
The designated authoritative source that other systems and users rely on for a defined set of business information.
- SQL InjectionRead SQL Injection
SQL injection is a vulnerability in which untrusted input changes the structure or meaning of a database command.
- Strangler Fig PatternRead Strangler Fig Pattern
An incremental migration pattern that routes selected capabilities from a legacy system to new components until the old implementation can be retired. It avoids replacing the whole system in one release.
- Switching CostRead Switching Cost
The one-time and transitional effort required to move from a SaaS product to another product or to software the business owns.
- Technical DebtRead Technical Debt
The accumulated cost of past shortcuts in software. It is the first thing a legacy audit has to measure, and it sits on both sides of a build-versus-buy decision.
- Test CoverageRead Test Coverage
Evidence about which parts of a codebase execute during automated tests. It shows where behaviour is protected, but a high number can still verify very little, especially in code generated with AI.
- Test EnvironmentRead Test Environment
A separate setup where a SaaS replacement and its connections can be checked without changing live business data or workflows.
- Threat ModelingRead Threat Modeling
Threat modeling maps what a system must protect, where trust changes, how misuse could occur, and which controls should prevent or limit it.
- Total Cost of OwnershipRead Total Cost of Ownership
The complete cost of acquiring, operating, changing, and eventually leaving a software system over a defined period.
- Workflow MappingRead Workflow Mapping
A documented view of the people, steps, decisions, data, and systems that make up a business process before a SaaS product is replaced.