You have software that still runs your business (a desktop app, a tool, a file format) and no source. One team specifies what it does. A second, firewalled team writes new code from that spec. Then we prove the new program behaves like the old one, as closely as you need: from "does the same job" to byte-identical.
Software from a company that shut down or stopped answering. It runs on one old machine and everyone is afraid to touch it.
Written in-house years ago. The repo, the contractor or the laptop is gone. You own it; you just can't build it.
A Delphi, Borland C++, VB or MFC program your staff use every day, stuck on old Windows. Same screens and workflows, rebuilt for today.
You need to read, write or speak something a closed program uses, so your new system can work with it.
Not on the list? The free scan identifies the compiler, the runtime and the data formats for you.
Agents do the work, which keeps the price down. What makes the result defensible is the separation, the records that prove it, and the tests that prove it works.
Upload the program. We measure its size, screens, files and risks, and price each fidelity level. Free. Then you send a VM or Docker image we can run.
~5 minutesThe spec team uses the original as a black box: every screen, workflow and output is recorded. Decompilation is limited to file formats and interfaces.
spec teamThey write a functional spec: screens, workflows, business rules, messages and file formats. Prose, tables and redrawn wireframes. No code.
spec teamWe generate a test suite in plain language, with expected results recorded from the original. You review it, add to it and sign it off. Then the spec is checked, hashed and passed across the wall.
you sign offA separate team that never sees the binary writes new code from the spec: a web app, a modern desktop app or a native tool.
build teamEvery test you signed off must pass on the new version, plus unseen inputs at the level you chose. You get the code, the tests and the audit pack.
differential testsThe agents learn the original by using it, and test the new version against it, thousands of times. So they need their own copy that runs, away from your live systems.
.ova, .vmdk, .vhdx or .qcow2 with the program installed. Best for old Windows apps: XP, 7, even 98.
For servers, Linux and command-line programs, with the data volume and compose file.
A copy or anonymised extract: the Paradox folder, the .mdb, the files it opens and saves.
For desktop apps: two recorded sessions of normal work, and a week of testing at the end.
Only have the installer, or a single old PC? We'll build the VM for you, or talk your IT through imaging the machine.
Reverse engineering by hand takes engineers weeks. Our agents drive the same tools experts use, around the clock, and people step in only where judgement matters.
These oracle requests are checked and logged like any other question, so the loop stays fast and the firewall holds.
Matching every pixel, every message and every odd edge case takes far longer than matching what the software is for. Most people need the middle level.
You can mix levels: Exact for the data files and reports, Functional for the screens. The scan tells you what each would cost.
A widely used binary-patch tool. We picked a permissively licensed program (BSD-2) so the trial is clearly legal. Both teams logged that its source may be in the model's training data.
| Step | What happened | Time |
|---|---|---|
| 0 · Quarantine | Source built into a read-only folder nobody on either team reads. | – |
| 1 · Binary | Stripped arm64 build. Headless decompile: 388 lines of pseudo-C. | 1m |
| 2 · Spec | 281-line SPEC.md, 44 fixtures, audit log. No code. | 5m |
| 3 · Firewall | Spec linted for code and decompiler names: clean. Hashed manifest. | <1m |
| 4 · Build | Rust from the spec only. 50/50 fixtures on the first run. | 2.5m |
| 5 · Prove | 43 unseen file pairs × (round trip + 5 corrupt patches). | 1m |
A clean room only holds up if you can show how it was kept. Every job ships an audit pack your lawyer can read.
The new program, building from scratch, in the language you chose.
The functional spec the build team worked from, exactly as it crossed the wall.
The test suite you signed off, plus the harness. Rerun it after any future change.
Hashes of everything each team could see, so access can be checked later.
Every question that crossed the wall and its answer, time-stamped.
Similarity of the new code against the decompile. Low means independent.
The scan reads the binary and prices the job at each fidelity level: tokens, review time and test-harness time, times a risk factor. You see the numbers before anything starts.
Prices shown at the Compatible level. Functional costs less; Exact costs more and takes longer. If the new version fails a test you signed off, we fix it or refund you.
This is a way to recover software you're entitled to use, not a way around someone else's rights. We check every job against this list before quoting.
A clean room doesn't cover patents, trademarks or contract terms. Read the full policy →
There's a community of engineers who spend their evenings rebuilding old programs until the new build is identical to the original, down to the last byte. They read compiler output the way other people read prose, and they know why Delphi 7 and Borland C++ lay out code the way they do.
That's who we are. We've built agents that work the way we do, with the patience to try thousands of variations, and we put the same obsession into your software. The difference is how we work: in a documented clean room, from a spec and never from the original code.
In the EU and UK, a lawful user may observe, study and test a program, and functionality and file formats aren't protected by copyright. We build the spec mainly from black-box observation and limit decompilation to formats and interfaces. In the US, a licence can forbid reverse engineering, so those jobs need counsel's sign-off first. This isn't legal advice; the lawyer sign-off add-on is there for jobs where it matters.
Only if you need it to be. Exact means copying every screen, message and edge case, including the bugs, and it can take two to three times as long. Most people choose Compatible: the same screens, workflows and files, so staff and other systems carry on as before. If you only need the job done, Functional is quickest and gives you a modern interface.
They run in separate sandboxes with separate inputs. The build team's sandbox never contains the binary or the decompile; we hash what each side could see and log every question that crosses. That record is the audit pack.
Then we'll usually say no. Its source may be in the model's training data, so a "clean" rewrite is hard to defend, and relicensing open-source code isn't something we do.
You do. We assign all rights we have in it. AI-written code may carry thin copyright, so human review and edits are recorded as part of every job.
Before anything is built, we generate a test suite from your staff sessions and from agents exploring the original. Each test is written in plain language ("when a user books in 38 of 40, the order shows 2 outstanding"), and its expected result is recorded from the original. You review it, add the cases your business relies on, and sign it off. The job is done when every test passes, and the suite is yours to keep.
Because the agents work by using the original: clicking through screens, feeding it data and recording what it does, then checking the new version against it after every change. That takes thousands of runs on copies we can reset, so we need an image that boots on its own. It never touches your network or live data. If you can't make one, we'll build it from your installer or help your IT image the PC it runs on.
For desktop apps, a little. We record two short sessions of people doing their normal work, which shows the spec team the workflows that matter. They test the new version before delivery.
It's kept in an isolated job sandbox, never used for training, and deleted 30 days after delivery unless you ask us to keep it.
Desktop business apps from the 90s and 2000s: Borland C++ and C++Builder, Delphi (Borland, CodeGear or Embarcadero), Visual Basic, MFC, PowerBuilder, Clipper, FoxPro, Clarion, WinForms and Java Swing. Also utilities, libraries and file formats, on Windows, macOS and Linux. Your data comes with you: Paradox, dBase, FoxPro, Btrieve, Access and InterBase databases are migrated to Postgres or SQLite, and Crystal Reports or QuickReport layouts are rebuilt. The new version can be a web app, a modern desktop app or a native program. So far the pipeline is proven end to end on small tools; desktop apps are quoted per job with a human engineer on the run. The scan tells you if your software is in range.
Upload the binary. In about five minutes you get its size, surface and risk flags, whether we'll take it on, and a fixed price.
Scan a binary →Still have the source? Move it to a new language at migratecode.com.