Your IT department manages an ageing application estate that no one can replace overnight — while business teams have been waiting for features for 18 months. WakaStart modernises progressively, without interrupting production, with CISO sign-off at every stage.
The situation every IT department knows
In an enterprise, no one can afford to switch off production to make room for a complete rewrite. But doing nothing is also a choice — and its consequences pile up every quarter.
What your legacy system is costing you today
The WakaStart approach for enterprises
The method
Target architecture — peaceful coexistence
Portals · APIs · Business microservices
Secure-by-Design · Native NIS2 · ISO 27001-ready · Delivered in weeks
Unified IAM · Centralised audit logs · Zero Trust
Single control point · NIS2 traceability · Strict isolation
Legacy Java · COBOL · .NET · PHP
Maintained as-is · Progressive module-by-module rewrite · Zero big-bang
The legacy system isn't the problem. The absence of a control layer is.
A Java core system from 2008 that runs is an asset — not a problem. The problem is that nothing controls what goes in and out, access rights are scattered across 12 different applications, and your NIS2 auditor can't get a consistent audit log of the whole estate. WakaStart puts in place the missing Zero Trust control layer — then progressively rewrites the core system onto a modern architecture, module by module, without ever interrupting production.
Free audit — Estate mapping
Analysis of your existing IT system, identification of dependencies, modular modernisation plan with business priorities.
Unified Gateway & IAM layer
Zero Trust control point between the legacy system and new developments. Centralised audit logs, immediate NIS2 compliance.
Peripheral developments in Cybercoding
Portals, APIs and microservices delivered in a matter of weeks — while the legacy system keeps running unchanged.
Progressive core system rewrite
Module by module, validated 1-to-1 through automated tests before each switchover. Multi-year, value-driven.
The operational process
Complete mapping of your application estate.
Our Lead Developer and CISO analyse your IT system: applications, dependencies, data flows, access rights management, NIS2 compliance status. Within 48 hours, you receive a complete report — priority risk areas, modular modernisation plan, fixed-price budget and timeline. Nothing is signed until you have a precise figure.
Free · 48 hours · No commitment · NDA if requiredImmediate NIS2 compliance without touching existing code.
WakaStart deploys the Zero Trust integration layer between your legacy system and the new applications. Centralised Keycloak IAM, unified audit logs, NIS2-compliant traceability across the whole IT system. Your auditors can obtain a consistent security report by the end of this phase — without your core system changing by a single line.
Immediate NIS2 · Centralised IAM · Legacy untouchedThe features your business teams have been waiting for since 18 months ago. Delivered in weeks.
Customer portal, employee space, partner exchange API, decision-support dashboard — every development surrounding the core system is built with Cybercoding. Secure-by-Design from the outset, ISO 27001-ready, connected to the legacy system via the Gateway. Your business teams see concrete deliverables within weeks instead of 18 months. CISO and Release Manager sign-off before every production release.
Delivered in weeks · CISO Dual-Control · ISO 27001-readyModule by module. Validated 1-to-1. Without ever interrupting production.
Cognitive reverse engineering analyses each module of the core system — even without documentation, even in COBOL or Java 6. It produces the exact functional specifications, module by module. Regeneration happens on the new stack, with automated 1-to-1 tests that mathematically prove the behaviour is identical. The switchover is invisible to end users. The pace is set by your business priorities, not by a technical constraint.
1-to-1 tests · Invisible switchover · Multi-year · Value-drivenThe legitimate questions
CISO questions
Security & Compliance
If the AI forge runs as SaaS, what guarantees me that no secrets leak out?
The WakaStart Control Plane operates via API gateways with contractual Zero Data Retention (ZDR) clauses. Your specifications and code never take part in any public model training. For the most sensitive cases, the on-premise Runtime runs the AI forge directly within your infrastructure — zero data leaves your walls.
An AI that generates code can introduce flaws that no one sees.
That's precisely why Dual-Control exists. No code goes into production without the explicit, signed approval of your human CISO and Release Manager. The SAST/DAST pipeline validates every build before presentation. The AI prepares the evidence — humans decide.
How is the generated code auditable for our ISO 27001 certification?
Every build automatically generates complete technical documentation: security assurance plan, quality assurance plan, business continuity plan, disaster recovery plan, architecture, RBAC matrix, SAST/DAST report. Your auditor has a complete, structured file for every release. The code is ISO 27001-ready from generation — not as an afterthought.
IT department questions
Governance & Reversibility
If we commit to WakaStart, we become dependent on your platform.
Reversibility is contractually guaranteed on two levels: firstly, the standardised TypeScript/Nest.js source code you fully receive can be maintained by any development team. Secondly, an exportable Docker runtime lets you deploy the application on any infrastructure without the WakaStart platform. Zero vendor lock-in at any level.
Our in-house teams are going to feel sidelined.
WakaStart doesn't replace your teams — it changes their working conditions. Your developers take part in the reverse engineering and validate the specifications. They upskill on Nest.js, Kubernetes and modern DevSecOps practices. They move from curative maintenance to value creation. And they no longer handle Sunday-night incidents.
The 5-year TCO — how does it compare to our current model?
The legacy TCO includes: maintenance developer salaries, obsolete software licences, incident costs, delayed feature delivery, NIS2 non-compliance. The Free audit produces a precise TCO comparison tailored to your situation — it's one of the deliverables of the free report. As a general rule, the break-even point falls between 18 and 30 months.
What we guarantee
Zero production interruption
Every switchover happens after 1-to-1 validation. A rollback plan is in place at every stage. Your end users never see an error page related to the migration.
Human Dual-Control at every release
Your CISO and Release Manager sign off on every production release. No code runs in production without their explicit approval. AI proposes, humans validate.
Fixed price — controlled budget
No creeping day-rate. The figure is set after the Free audit and doesn't change after signature. You know the total cost before you start.
Total reversibility
Standardised TypeScript/Nest.js code, exportable Docker runtime, IP fully transferred. You can take back your code and have it maintained by any team at any time.
Complete audit documentation
Security assurance plan, quality assurance plan, business continuity plan, disaster recovery plan, technical architecture, RBAC matrix, SAST/DAST reports — generated automatically with every release. Your ISO 27001 or NIS2 auditor has everything they need.
Your teams upskill
Nest.js, Kubernetes, Keycloak, GitOps — the market standards for 2026. Your developers come out of a WakaStart project with valuable skills, not a dependency on a proprietary framework.
What it changes
The budget
Component
Cost
Phase 0 — Free audit & IT system mapping
Free
Phase 1 — Zero Trust Gateway & IAM
Quoted after Free audit
Phase 2 — Peripheral developments
from €90,000 excl. VAT
Phase 3 — Core system rewrite (per module)
Multi-year · quoted on request
ISO 27001-ready preparation option
+€10,000 excl. VAT
Smoothing without a bank loan
Quoted on request
Phase 2 starting from
€90,000 excl. VAT
Why the Free audit is the essential first step.
A precise figure, not a range
The WakaStart fixed price is calculated based on the reality of your IT system, not on assumptions. The Free audit produces an exact budget tailored to your complexity.
A comparative TCO included
The Free audit report compares the total cost of your legacy system over 5 years with the cost of WakaStart modernisation. You can present this comparison to your management to secure budget approval.
Business priorities guide the phases
We don't modernise what has no value. The modernisation plan is driven by the ROI of each module — not by technical ease.
Your questions
How long does Phase 1 — Gateway and IAM take?
On average 4 to 6 weeks to deploy the Zero Trust Gateway and centralised Keycloak IAM, depending on the complexity of your IT system and the number of applications to connect. By the end of this phase, your architectural-level NIS2 non-compliance drops to zero — without touching the code of existing applications. The Free audit specifies the timeline for your specific situation.
Our data is highly sensitive. What level of isolation is guaranteed?
Three levels available depending on your requirements. Dedicated SaaS (exclusive OVH France infrastructure, zero co-tenancy) for sensitive data. On-premise runtime (the AI forge operates within your IT system, no data leaves your walls) for highly regulated data. Air-Gap on physical media for classified environments. The Free audit determines the level suited to your regulatory constraints.
Our Java core system is 15 years old. Is it really reverse-engineerable?
Yes — it's actually the use case cognitive reverse engineering was designed for. The AI analyses the application's real behaviour (not the documentation, which is often outdated) by examining the source code, interfaces and data flows. We've worked on Java 5, VB6, COBOL and PHP 4. The age of the code isn't an obstacle — it can even be an advantage, since business rules are more stable than in newer code.
How is project governance handled on the WakaStart side?
Every enterprise project is led by a WakaStart Lead Architect and a dedicated CISO. A fortnightly steering committee brings together your IT department, your CISO and business stakeholders. Deliverables are approved in committee before every production release. Role segregation is strictly enforced: the Product Owner validates specifications, the Tech Lead orchestrates the forge, the CISO signs off on releases. No deployment decision is made without human quorum.
What happens if we want to stop the project partway through?
At any time, you get back all the code produced up to that point — clean, documented, in standard TypeScript/Nest.js. The Docker runtime lets you keep running the application without the WakaStart platform. Your in-house teams, or any development team, can take over the project without a technical transition period. No penalising exit clause — it's contractually guaranteed.
Start with the Free audit — 48 hours to map your IT system, identify priority non-compliances and price out the modernisation plan. NDA signed before any access to your code. No commitment until you have the report in hand.