Home › Use cases › Enterprise

Millions of lines
of legacy code.
Zero big-bang.

Your IT department manages an ageing application estate that no one can replace overnight — while business teams have been waiting for features for 18 months. WakaStart modernises progressively, without interrupting production, with CISO sign-off at every stage.

0Big-bang required
CISOHuman Dual-Control
NIS2Native Zero Trust
from €90kFixed price
Free Free audit audit See the migration solution →
Startup — Launch your SaaS Scale-up — Rebuild your SaaS Software vendor — Move to SaaS cloud Enterprise — Modernise your legacy

The situation every IT department knows

Modernise without breaking everything.
It's the only acceptable scenario.

In an enterprise, no one can afford to switch off production to make room for a complete rewrite. But doing nothing is also a choice — and its consequences pile up every quarter.

What your legacy system is costing you today

Senior developers spending 60–70% of their time maintaining code that no one fully understands — instead of delivering value to the business.
Tenders where your suppliers and technology partners ask for NIS2 compliance that your legacy architecture cannot prove.
A patchwork of disparate SaaS tools (CRM, ERP, business applications) stitched together — with no centralised traceability, no unified IAM, no consistent audit logs.
Delivery times of 12 to 18 months for features your business teams have been waiting for since the last management committee — and which will be outdated by the time they're delivered.
A CISO security audit that grows longer with every renewal — because the architecture wasn't designed to answer an ISO 27001 auditor's questions.

The WakaStart approach for enterprises

No immediate replacement of the core system — WakaStart starts with the peripheral developments (portals, APIs, microservices) that orbit the legacy system.
Every new development is Secure-by-Design: NIS2, ISO 27001-ready, native Zero Trust. The existing legacy system is consumed in a sealed manner via the WakaStart Gateway.
The core system rewrite happens progressively, module by module, on a multi-year timeline driven by value — not by an arbitrary technical constraint.
Human Dual-Control at every stage: no code goes into production without the explicit, signed approval of your CISO and Release Manager. Zero blind deployments.
Total reversibility guaranteed contractually: standardised TypeScript/Nest.js source code, exportable Docker runtime, zero vendor lock-in at any stage of the project.
60–70%of dev time on average spent on curative maintenance in legacy IT departments
×5the cost of fixing a flaw discovered in production vs during the design phase
2027NIS2 deadline — every critical supplier must prove its compliance to its clients
18 monthsaverage delivery time for a feature in an IT department in curative maintenance mode

The method

We don't replace your legacy system.
We make it harmless.

Target architecture — peaceful coexistence

New WakaStart developments

Portals · APIs · Business microservices

Secure-by-Design · Native NIS2 · ISO 27001-ready · Delivered in weeks

↕ Secure interfacing via WakaStart Gateway
Gateway & Integration layer

Unified IAM · Centralised audit logs · Zero Trust

Single control point · NIS2 traceability · Strict isolation

↕ Sealed consumption of the core system
Existing core system — untouched initially

Legacy Java · COBOL · .NET · PHP

Maintained as-is · Progressive module-by-module rewrite · Zero big-bang

The legacy system isn't the problem. The absence of a control layer is.

A Java core system from 2008 that runs is an asset — not a problem. The problem is that nothing controls what goes in and out, access rights are scattered across 12 different applications, and your NIS2 auditor can't get a consistent audit log of the whole estate. WakaStart puts in place the missing Zero Trust control layer — then progressively rewrites the core system onto a modern architecture, module by module, without ever interrupting production.

1

Free audit — Estate mapping

Analysis of your existing IT system, identification of dependencies, modular modernisation plan with business priorities.

2

Unified Gateway & IAM layer

Zero Trust control point between the legacy system and new developments. Centralised audit logs, immediate NIS2 compliance.

3

Peripheral developments in Cybercoding

Portals, APIs and microservices delivered in a matter of weeks — while the legacy system keeps running unchanged.

4

Progressive core system rewrite

Module by module, validated 1-to-1 through automated tests before each switchover. Multi-year, value-driven.

The operational process

From audit to complete modernisation.
Every stage approved by your CISO.

Phase 0 — Free audit (48 hours, free)

Complete mapping of your application estate.

Our Lead Developer and CISO analyse your IT system: applications, dependencies, data flows, access rights management, NIS2 compliance status. Within 48 hours, you receive a complete report — priority risk areas, modular modernisation plan, fixed-price budget and timeline. Nothing is signed until you have a precise figure.

Free · 48 hours · No commitment · NDA if required
Phase 1 — Zero Trust Gateway & unified IAM

Immediate NIS2 compliance without touching existing code.

WakaStart deploys the Zero Trust integration layer between your legacy system and the new applications. Centralised Keycloak IAM, unified audit logs, NIS2-compliant traceability across the whole IT system. Your auditors can obtain a consistent security report by the end of this phase — without your core system changing by a single line.

Immediate NIS2 · Centralised IAM · Legacy untouched
Phase 2 — Priority peripheral developments

The features your business teams have been waiting for since 18 months ago. Delivered in weeks.

Customer portal, employee space, partner exchange API, decision-support dashboard — every development surrounding the core system is built with Cybercoding. Secure-by-Design from the outset, ISO 27001-ready, connected to the legacy system via the Gateway. Your business teams see concrete deliverables within weeks instead of 18 months. CISO and Release Manager sign-off before every production release.

Delivered in weeks · CISO Dual-Control · ISO 27001-ready
Phase 3 — Progressive core system rewrite

Module by module. Validated 1-to-1. Without ever interrupting production.

Cognitive reverse engineering analyses each module of the core system — even without documentation, even in COBOL or Java 6. It produces the exact functional specifications, module by module. Regeneration happens on the new stack, with automated 1-to-1 tests that mathematically prove the behaviour is identical. The switchover is invisible to end users. The pace is set by your business priorities, not by a technical constraint.

1-to-1 tests · Invisible switchover · Multi-year · Value-driven

The legitimate questions

What your CISO and IT department
will ask. With the answers.

CISO questions

Security & Compliance

If the AI forge runs as SaaS, what guarantees me that no secrets leak out?

The WakaStart Control Plane operates via API gateways with contractual Zero Data Retention (ZDR) clauses. Your specifications and code never take part in any public model training. For the most sensitive cases, the on-premise Runtime runs the AI forge directly within your infrastructure — zero data leaves your walls.

An AI that generates code can introduce flaws that no one sees.

That's precisely why Dual-Control exists. No code goes into production without the explicit, signed approval of your human CISO and Release Manager. The SAST/DAST pipeline validates every build before presentation. The AI prepares the evidence — humans decide.

How is the generated code auditable for our ISO 27001 certification?

Every build automatically generates complete technical documentation: security assurance plan, quality assurance plan, business continuity plan, disaster recovery plan, architecture, RBAC matrix, SAST/DAST report. Your auditor has a complete, structured file for every release. The code is ISO 27001-ready from generation — not as an afterthought.

IT department questions

Governance & Reversibility

If we commit to WakaStart, we become dependent on your platform.

Reversibility is contractually guaranteed on two levels: firstly, the standardised TypeScript/Nest.js source code you fully receive can be maintained by any development team. Secondly, an exportable Docker runtime lets you deploy the application on any infrastructure without the WakaStart platform. Zero vendor lock-in at any level.

Our in-house teams are going to feel sidelined.

WakaStart doesn't replace your teams — it changes their working conditions. Your developers take part in the reverse engineering and validate the specifications. They upskill on Nest.js, Kubernetes and modern DevSecOps practices. They move from curative maintenance to value creation. And they no longer handle Sunday-night incidents.

The 5-year TCO — how does it compare to our current model?

The legacy TCO includes: maintenance developer salaries, obsolete software licences, incident costs, delayed feature delivery, NIS2 non-compliance. The Free audit produces a precise TCO comparison tailored to your situation — it's one of the deliverables of the free report. As a general rule, the break-even point falls between 18 and 30 months.

What we guarantee

The contractual commitments
no IT services firm makes.

Zero production interruption

Every switchover happens after 1-to-1 validation. A rollback plan is in place at every stage. Your end users never see an error page related to the migration.

Human Dual-Control at every release

Your CISO and Release Manager sign off on every production release. No code runs in production without their explicit approval. AI proposes, humans validate.

Fixed price — controlled budget

No creeping day-rate. The figure is set after the Free audit and doesn't change after signature. You know the total cost before you start.

Total reversibility

Standardised TypeScript/Nest.js code, exportable Docker runtime, IP fully transferred. You can take back your code and have it maintained by any team at any time.

Complete audit documentation

Security assurance plan, quality assurance plan, business continuity plan, disaster recovery plan, technical architecture, RBAC matrix, SAST/DAST reports — generated automatically with every release. Your ISO 27001 or NIS2 auditor has everything they need.

Your teams upskill

Nest.js, Kubernetes, Keycloak, GitOps — the market standards for 2026. Your developers come out of a WakaStart project with valuable skills, not a dependency on a proprietary framework.

What it changes

The metrics that matter
for an IT department.

8 wks Peripheral delivery time vs 12–18 months in legacy mode — for the same features
0 NIS2 non-compliance After deployment of the Zero Trust Gateway & centralised IAM
-60% Maintenance time Freed up for business value after modernising priority modules
18–30 months Return on investment Break-even point vs total legacy cost — calculated in the Free audit

The budget

A fixed price per phase.
A controlled 5-year TCO.

Component

Cost

Phase 0 — Free audit & IT system mapping

Free

Phase 1 — Zero Trust Gateway & IAM

Quoted after Free audit

Phase 2 — Peripheral developments

from €90,000 excl. VAT

Phase 3 — Core system rewrite (per module)

Multi-year · quoted on request

ISO 27001-ready preparation option

+€10,000 excl. VAT

Smoothing without a bank loan

Quoted on request

Phase 2 starting from

€90,000 excl. VAT

Why the Free audit is the essential first step.

A precise figure, not a range

The WakaStart fixed price is calculated based on the reality of your IT system, not on assumptions. The Free audit produces an exact budget tailored to your complexity.

A comparative TCO included

The Free audit report compares the total cost of your legacy system over 5 years with the cost of WakaStart modernisation. You can present this comparison to your management to secure budget approval.

Business priorities guide the phases

We don't modernise what has no value. The modernisation plan is driven by the ROI of each module — not by technical ease.

Your questions

What IT and security teams
ask us before getting started.

How long does Phase 1 — Gateway and IAM take?

On average 4 to 6 weeks to deploy the Zero Trust Gateway and centralised Keycloak IAM, depending on the complexity of your IT system and the number of applications to connect. By the end of this phase, your architectural-level NIS2 non-compliance drops to zero — without touching the code of existing applications. The Free audit specifies the timeline for your specific situation.

Our data is highly sensitive. What level of isolation is guaranteed?

Three levels available depending on your requirements. Dedicated SaaS (exclusive OVH France infrastructure, zero co-tenancy) for sensitive data. On-premise runtime (the AI forge operates within your IT system, no data leaves your walls) for highly regulated data. Air-Gap on physical media for classified environments. The Free audit determines the level suited to your regulatory constraints.

Our Java core system is 15 years old. Is it really reverse-engineerable?

Yes — it's actually the use case cognitive reverse engineering was designed for. The AI analyses the application's real behaviour (not the documentation, which is often outdated) by examining the source code, interfaces and data flows. We've worked on Java 5, VB6, COBOL and PHP 4. The age of the code isn't an obstacle — it can even be an advantage, since business rules are more stable than in newer code.

How is project governance handled on the WakaStart side?

Every enterprise project is led by a WakaStart Lead Architect and a dedicated CISO. A fortnightly steering committee brings together your IT department, your CISO and business stakeholders. Deliverables are approved in committee before every production release. Role segregation is strictly enforced: the Product Owner validates specifications, the Tech Lead orchestrates the forge, the CISO signs off on releases. No deployment decision is made without human quorum.

What happens if we want to stop the project partway through?

At any time, you get back all the code produced up to that point — clean, documented, in standard TypeScript/Nest.js. The Docker runtime lets you keep running the application without the WakaStart platform. Your in-house teams, or any development team, can take over the project without a technical transition period. No penalising exit clause — it's contractually guaranteed.

Your next NIS2 audit
could be your
best report.

Start with the Free audit — 48 hours to map your IT system, identify priority non-compliances and price out the modernisation plan. NDA signed before any access to your code. No commitment until you have the report in hand.

Start the Free audit See the migration solution →
Zero big-bang Native NIS2 ISO 27001-ready CISO Dual-Control Total reversibility FR · OVH