Legacy Modernization
We work on the code everyone else has forgotten how to read.
Delphi 5 and 7. Classic ASP. ColdFusion. VB6, Access, FoxPro. These systems still run dispatch, billing, inventory and payroll for real companies, and the pool of engineers who genuinely understand them shrinks every year. We've been in that pool since 1997, and we're still hiring into it.
Why companies call us
The system works fine. Everything around it is the problem.
Almost nobody calls because their legacy application stopped doing its job. They call because of what has happened around it.
- The person who wrote it has retired, or left in 2006, and took the only mental model of the system with them.
- It won't run on supported infrastructure. Windows Server 2003 is long gone; your insurer or auditor has noticed.
- A dependency died. A component vendor folded, a COM library stopped working, a database driver isn't shipped anymore.
- You need one new feature and three firms have quoted a full rewrite to deliver it.
- Security review flagged it. Unparameterised queries, plaintext credentials, TLS versions that no longer negotiate.
- You're being acquired and diligence wants documentation that has never existed.
Supported stacks
Deep, specific experience, not a generalist reading documentation for the first time.
These are the environments we work in regularly, with the quirks that come with each.
Delphi 5 & Delphi 7
Delphi 5 (1999) and Delphi 7 (2002) remain by a wide margin the versions we're most often asked to work on. We handle VCL forms applications, BDE and Paradox data access, InterBase and Firebird, third-party component suites that went out of support two decades ago, and the tangle of DLL and COM boundaries these applications tend to accumulate.
We can maintain them where they are, move them to a current RAD Studio, or port the whole thing to .NET.
- VCL
- BDE
- Paradox
- InterBase / Firebird
- dbExpress
- QuickReport
- COM / ActiveX
Classic ASP & VBScript
Classic ASP with VBScript, ADO recordsets, COM+ components and a back end on Access or SQL Server. The usual work: getting a site running again on current IIS and Windows Server, closing SQL-injection holes that predate parameterised queries being standard practice, replacing dead COM dependencies, and untangling include files that have grown for twenty years.
When it's the right moment, we migrate to ASP.NET Core, page by page, not all at once.
- VBScript
- ADO
- COM+ / MTS
- IIS 6 → 10
- Access / Jet
- SQL Server
ColdFusion
CFML from the Allaire and Macromedia eras through modern Adobe ColdFusion and Lucee. We work with CFCs, query-heavy templates, custom tags, and the administrator settings nobody wrote down, plus the question that usually prompts the call in the first place: renew the Adobe licence, or move to Lucee?
We'll cost out both honestly, including the option of leaving it exactly as it is.
- CFML
- CFCs
- Custom tags
- Adobe CF
- Lucee
- CF Admin
Also regularly supported:
- Visual Basic 6
- Microsoft Access / VBA
- Visual FoxPro
- PowerBuilder
- ASP.NET WebForms
- Crystal Reports
- VB.NET (1.1 / 2.0)
- Legacy SQL Server
- Perl / CGI
Don't see yours? Ask anyway. Two decades of this work means the honest answer is usually "yes, we've seen that", and when it isn't, we'll tell you plainly.
Your options
There are four honest paths. Only one of them is a rewrite.
Most firms sell you the fourth because it's the biggest invoice. We'll tell you which one your situation actually calls for.
1 · Keep it running
Bug fixes, security patching, OS and database upgrades, and a maintainer who answers the phone. If the system does its job and the only real risk is operational, this is the cheapest correct answer, and often the right one for years.
2 · Extend it
New features, new reports, and modern REST APIs or web front-ends attached cleanly to the system you already have. Your Delphi application can serve a React dashboard without being rewritten to do it.
3 · Port it
Delphi 7 to current RAD Studio or to .NET. Classic ASP to ASP.NET Core. ColdFusion to Lucee. Behaviour preserved and verified against the original. The point of a port is that nothing changes for the people using it.
4 · Replace it, one piece at a time
Strangler-fig migration: new and old run side by side while functionality moves across module by module. No big-bang cutover weekend, no eighteen months with nothing shipped, and you can stop at any point and still be better off.
How an engagement works
It starts with a code audit, and you own the result either way.
Our discovery deliverable is written to be useful to you even if you never hire us for the build.
-
Discovery & code audit
We take the source, get it building reproducibly, and map what's actually in there: architecture, data model, dependencies, dead code, and the business rules buried in it. You receive a written assessment with options and costs, yours to keep and to take to another firm if you'd rather.
-
Stabilise
Source control if it isn't already. A repeatable build. Supported infrastructure. Automated tests around the paths that would hurt most if they broke. This is the safety net that makes everything afterwards safe to attempt.
-
Agree the path
Keep, extend, port or incrementally replace, chosen against your actual constraints: budget, risk tolerance, regulatory pressure, and how long the business expects to run this process at all.
-
Execute in increments
Working software at every step, deployed where you can use it. Nothing is held back for a grand reveal at the end, and you can change direction between increments without writing off the work.
-
Hand over, or stay on
Documentation, runbooks and knowledge transfer to your team, an ongoing maintenance retainer with us, or both. We're equally happy being the firm you no longer need.
{ Found in: PricingUtils.pas, line 4127 }
{ Undocumented. Still in force. }
if (Cust.Region = 'NE') and
(OrderTotal > 15000) and
(DayOfWeek(Now) <> 6) then
Discount := 0.075
else
Discount := 0.05;
==================
// 1 of 340 rules recovered and
// confirmed with the client during
// a two-week audit.
Where AI genuinely helps
Codebase archaeology used to be unaffordable. That's the part that changed.
Reading two hundred thousand lines of undocumented Object Pascal to find every place a discount is calculated used to be a month of billable hours that no client wanted to pay for. Now it's the first afternoon of the engagement.
We use AI to map call graphs, surface business rules, flag dead code and draft the specification nobody ever wrote, then we verify the findings against the running system and against you. The acceleration is real. The accountability doesn't move.
Common questions
The things people ask before they call.
Nobody here understands the system anymore. Can you still help?
Yes, and that's the normal starting point, not an unusual one. Most of the systems we're handed come with no documentation and no original author. Reconstructing how something works from the source is the core skill we sell.
Do we have to rewrite it?
Usually not, and we'll say so even though a rewrite would be a bigger engagement for us. Rewrites are the most expensive and highest-risk option available, and they throw away decades of accumulated edge cases that took real incidents to discover. We recommend one when the platform is genuinely unsupportable or the business needs have moved somewhere the old design can't follow.
We've lost the source code. Is that fatal?
Not necessarily. We've recovered source from old build servers, backup tapes, retired developer workstations and version-control systems everyone had forgotten were still running. Talk to us before you assume it's gone, and if it truly is, we'll scope a rebuild against the running system's observed behaviour.
Our developer is retiring in six months. Can you take over?
Yes, and the overlap matters enormously: bring us in while they're still there. A structured knowledge-transfer engagement with the original author available is worth several times the same work done after they've left.
How do you price this work?
Discovery is a fixed-price, fixed-duration engagement so you know the cost of finding out. After that, phases are quoted individually: fixed price where scope is clear, time and materials where it genuinely isn't. We'd rather tell you which of those applies than pretend a legacy port is more predictable than it is.
Can you sign an NDA and work under our security requirements?
Yes. We routinely work under NDA, and we'll work within your constraints on source handling, network access and where code is allowed to live, including engagements where nothing leaves your environment.
Tell us what it does and what it's written in.
That's genuinely enough to start. We'll tell you what your realistic options are, including the ones that don't involve hiring us.