MOCKUP cleanrewrite.com · Home Free scan QuoteTests Job Audit pack Policy
Clean-room reimplementation

Lost the source?
We rebuild it, clean-room.

You have software that still runs your business (a desktop app, a tool, a file format) and no source. One team specifies what it does. A second, firewalled team writes new code from that spec. Then we prove the new program behaves like the old one, as closely as you need: from "does the same job" to byte-identical.

Fixed price before we startYou sign off the testsAudit pack with every jobYour code is yours
The firewalljob #CR-0001 · bspatch
Spec team

Studies the original

  • bspatch (arm64, 34 KB)
  • black-box test runs
  • decompile: formats only
  • → SPEC.md, no code
Build team

Writes new code

  • SPEC.md (281 lines)
  • 44 test fixtures
  • binary
  • decompile
SHA-256Only the spec and fixtures cross the wall, hashed and logged. 4 questions crossed, all recorded.
Unseen inputs, output identical to the original258/258
Who it's for

The program still works. Nobody can change it.

🏚️

The vendor is gone

Software from a company that shut down or stopped answering. It runs on one old machine and everyone is afraid to touch it.

🗝️

Your own program, source lost

Written in-house years ago. The repo, the contractor or the laptop is gone. You own it; you just can't build it.

🖥️

An old desktop app

A Delphi, Borland C++, VB or MFC program your staff use every day, stuck on old Windows. Same screens and workflows, rebuilt for today.

🔌

A format or protocol to talk to

You need to read, write or speak something a closed program uses, so your new system can work with it.

Built with
Borland C++ OWLC++BuilderDelphi 1–7 VCL Embarcadero Delphi / C++BuilderTurbo PascalVisual Basic 3–6 Visual C++ MFCPowerBuilderClipperFoxProClarionAccess apps
Stored its data in
Paradox .dbdBase .dbfFoxPro .dbf .cdxClipper .ntx BtrieveAccess .mdbInterBaseClarion .tpsBDE aliases Lotus 1-2-3 .wk1Excel 95 .xlsCrystal Reports .rptQuickReport.inicustom binary files

Not on the list? The free scan identifies the compiler, the runtime and the data formats for you.

How it works

Six steps, one firewall, one fixed price.

Agents do the work, which keeps the price down. What makes the result defensible is the separation, the records that prove it, and the tests that prove it works.

Scan and quote

Upload the program. We measure its size, screens, files and risks, and price each fidelity level. Free. Then you send a VM or Docker image we can run.

~5 minutes

Observe

The spec team uses the original as a black box: every screen, workflow and output is recorded. Decompilation is limited to file formats and interfaces.

spec team

Specify

They write a functional spec: screens, workflows, business rules, messages and file formats. Prose, tables and redrawn wireframes. No code.

spec team

Sign off the tests

We generate a test suite in plain language, with expected results recorded from the original. You review it, add to it and sign it off. Then the spec is checked, hashed and passed across the wall.

you sign off

Build

A separate team that never sees the binary writes new code from the spec: a web app, a modern desktop app or a native tool.

build team

Prove and deliver

Every test you signed off must pass on the new version, plus unseen inputs at the level you chose. You get the code, the tests and the audit pack.

differential tests
What you'll give us

Something we can run, and a little of your staff's time.

The agents learn the original by using it, and test the new version against it, thousands of times. So they need their own copy that runs, away from your live systems.

💿

A VM image

.ova, .vmdk, .vhdx or .qcow2 with the program installed. Best for old Windows apps: XP, 7, even 98.

🐳

Or a Docker image

For servers, Linux and command-line programs, with the data volume and compose file.

🗄️

Sample data

A copy or anonymised extract: the Paradox folder, the .mdb, the files it opens and saves.

👥

Two hours of staff

For desktop apps: two recorded sessions of normal work, and a week of testing at the end.

Only have the installer, or a single old PC? We'll build the VM for you, or talk your IT through imaging the machine.

Agents do the work

A fraction of the cost of a consultancy.

Reverse engineering by hand takes engineers weeks. Our agents drive the same tools experts use, around the clock, and people step in only where judgement matters.

  • 🔬Ghidra and friends, driven by agents. Headless decompilation of the data formats, UI automation that clicks through every screen, and capture of every file and printed report.
  • ⚡A tight feedback loop. Each change is rebuilt and replayed against the original's recorded behaviour in under a minute, so the build agents iterate thousands of times.
  • 🧑‍⚖️People where it counts. You sign off the test suite, an engineer reviews the code, a lawyer can sign off the spec, and your staff try it before you pay the balance.
The build loop · ~40 seconds
changeagent edits the code
buildcompile and start
replayrun every workflow
diffdata, files, PDFs
↺ repeat until every diff is empty
build side
"What does the original do with this input?"
spec side
Runs it on the original and returns only the expected result.

These oracle requests are checked and logged like any other question, so the loop stays fast and the firewall holds.

How close do you need it?

You choose the fidelity. It sets the price and the time.

Matching every pixel, every message and every odd edge case takes far longer than matching what the software is for. Most people need the middle level.

Functional

Does the same job

Same features, a modern interface.
Same
Features, business rules and results. Opens your existing data and files
May differ
Screen layout, workflow steps, messages and report layout. Old bugs are fixed, not copied
Tested by
Running your key tasks on both and comparing the results
Fastest · lowest price
Compatible most chosen

A drop-in replacement

Swap it in; nobody needs retraining.
Same
Screens, fields, workflows and shortcuts. Files, data and reports identical on normal use
May differ
Fonts and look, exact message wording, behaviour on bad data
Tested by
Replaying recorded workflows on both and diffing data, files and reports
About 1.5× Functional
Exact

Byte-identical

Indistinguishable from the original.
Same
Every screen, message, output byte and edge case, including bad input. Bugs are reproduced
May differ
Only speed and memory use
Tested by
Every path through every screen, plus fuzzed and corrupt inputs
2–3× Functional · much longer

You can mix levels: Exact for the data files and reports, Functional for the screens. The scan tells you what each would cost.

A real run · Exact level

bspatch, rebuilt from a stripped binary.

A widely used binary-patch tool. We picked a permissively licensed program (BSD-2) so the trial is clearly legal. Both teams logged that its source may be in the model's training data.

Original
34 KB
14 functions, names stripped
Rebuild
391
lines of Rust, 14 unit tests
Identical
258/258
bytes, stderr and exit code
50 MB file
0.07s
original: 0.08s
StepWhat happenedTime
0 · QuarantineSource built into a read-only folder nobody on either team reads.–
1 · BinaryStripped arm64 build. Headless decompile: 388 lines of pseudo-C.1m
2 · Spec281-line SPEC.md, 44 fixtures, audit log. No code.5m
3 · FirewallSpec linted for code and decompiler names: clean. Hashed manifest.<1m
4 · BuildRust from the spec only. 50/50 fixtures on the first run.2.5m
5 · Prove43 unseen file pairs × (round trip + 5 corrupt patches).1m
What you get

New code, plus the paperwork that makes it defensible.

A clean room only holds up if you can show how it was kept. Every job ships an audit pack your lawyer can read.

📦
src/

The new program, building from scratch, in the language you chose.

📄
SPEC.md

The functional spec the build team worked from, exactly as it crossed the wall.

🧪
tests/

The test suite you signed off, plus the harness. Rerun it after any future change.

🔐
manifest.sha256

Hashes of everything each team could see, so access can be checked later.

💬
questions.log

Every question that crossed the wall and its answer, time-stamped.

🔍
similarity.html

Similarity of the new code against the decompile. Low means independent.

Pricing

A fixed price, from the scan.

The scan reads the binary and prices the job at each fidelity level: tokens, review time and test-harness time, times a risk factor. You see the numbers before anything starts.

Small tool or utility
€300–1k
under 50 functions
  • Spec, build, tests
  • Audit pack
  • Days, not weeks
Library or file format
€2k–10k
50–500 functions
  • Everything in Small
  • Fuzzed format tests
  • Similarity report
Desktop or business app
€10k+
screens, databases, reports
  • Quoted per job
  • A human engineer on the run
  • Your staff test it before delivery
  • Data migration included
Add-on
+ fixed fee
lawyer sign-off
  • A lawyer reviews the spec before it crosses the wall
  • Signed opinion in the pack

Prices shown at the Compatible level. Functional costs less; Exact costs more and takes longer. If the new version fails a test you signed off, we fix it or refund you.

Policy

What we take on, and what we turn down.

This is a way to recover software you're entitled to use, not a way around someone else's rights. We check every job against this list before quoting.

We accept

✓
  • Your own program, with the source lost
  • Abandoned tools whose owner consented, is defunct, or didn't reply to a documented request
  • File-format and protocol interoperability
  • Black-box-only rebuilds

We refuse

✕
  • DRM or licence-check bypass
  • Game cheats, malware, offensive tools
  • Relicensing open-source code ("licence laundering")
  • Brand or look-and-feel clones
  • US targets under a no-reverse-engineering licence, without counsel

A clean room doesn't cover patents, trademarks or contract terms. Read the full policy →

Who we are

Engineers who match binaries byte for byte, for fun.

There's a community of engineers who spend their evenings rebuilding old programs until the new build is identical to the original, down to the last byte. They read compiler output the way other people read prose, and they know why Delphi 7 and Borland C++ lay out code the way they do.

That's who we are. We've built agents that work the way we do, with the patience to try thousands of variations, and we put the same obsession into your software. The difference is how we work: in a documented clean room, from a spec and never from the original code.

"Byte-identical is the hard level. It's the one we're best at, so the other levels are easy."
🎯
Matching is our hobbyYears of byte-exact rebuilds of old games and tools, where "close enough" doesn't count.
🧰
We know the old toolchainsBorland, Embarcadero, Microsoft, Watcom: their compilers, runtimes and quirks, and the data formats of the 90s.
🤖
We built the agentsThey drive Ghidra, VMs and test harnesses the way we would, around the clock.
⚖️
We keep it cleanBlack-box first, a firewall between the teams, and a lawyer when it matters.
FAQ

Questions people ask first.

Is this legal?

In the EU and UK, a lawful user may observe, study and test a program, and functionality and file formats aren't protected by copyright. We build the spec mainly from black-box observation and limit decompilation to formats and interfaces. In the US, a licence can forbid reverse engineering, so those jobs need counsel's sign-off first. This isn't legal advice; the lawyer sign-off add-on is there for jobs where it matters.

Does the new version have to be identical?

Only if you need it to be. Exact means copying every screen, message and edge case, including the bugs, and it can take two to three times as long. Most people choose Compatible: the same screens, workflows and files, so staff and other systems carry on as before. If you only need the job done, Functional is quickest and gives you a modern interface.

Why two AI teams, and how are they kept apart?

They run in separate sandboxes with separate inputs. The build team's sandbox never contains the binary or the decompile; we hash what each side could see and log every question that crosses. That record is the audit pack.

What if the original is open source?

Then we'll usually say no. Its source may be in the model's training data, so a "clean" rewrite is hard to defend, and relicensing open-source code isn't something we do.

Who owns the new code?

You do. We assign all rights we have in it. AI-written code may carry thin copyright, so human review and edits are recorded as part of every job.

How do we know it works?

Before anything is built, we generate a test suite from your staff sessions and from agents exploring the original. Each test is written in plain language ("when a user books in 38 of 40, the order shows 2 outstanding"), and its expected result is recorded from the original. You review it, add the cases your business relies on, and sign it off. The job is done when every test passes, and the suite is yours to keep.

Why do you need a VM or Docker image?

Because the agents work by using the original: clicking through screens, feeding it data and recording what it does, then checking the new version against it after every change. That takes thousands of runs on copies we can reset, so we need an image that boots on its own. It never touches your network or live data. If you can't make one, we'll build it from your installer or help your IT image the PC it runs on.

Do my staff need to be involved?

For desktop apps, a little. We record two short sessions of people doing their normal work, which shows the spec team the workflows that matter. They test the new version before delivery.

What happens to my binary?

It's kept in an isolated job sandbox, never used for training, and deleted 30 days after delivery unless you ask us to keep it.

Which kinds of software?

Desktop business apps from the 90s and 2000s: Borland C++ and C++Builder, Delphi (Borland, CodeGear or Embarcadero), Visual Basic, MFC, PowerBuilder, Clipper, FoxPro, Clarion, WinForms and Java Swing. Also utilities, libraries and file formats, on Windows, macOS and Linux. Your data comes with you: Paradox, dBase, FoxPro, Btrieve, Access and InterBase databases are migrated to Postgres or SQLite, and Crystal Reports or QuickReport layouts are rebuilt. The new version can be a web app, a modern desktop app or a native program. So far the pipeline is proven end to end on small tools; desktop apps are quoted per job with a human engineer on the run. The scan tells you if your software is in range.

Start with a free scan.

Upload the binary. In about five minutes you get its size, surface and risk flags, whether we'll take it on, and a fixed price.

Scan a binary →
⬆Drop a binary here.exe, ELF, Mach-O, .dll, .so · up to 200 MB

Still have the source? Move it to a new language at migratecode.com.