Technology · Under the hood

What we measure, and how.

Maintainability Cloud is the code-measurement layer of Claroview’s Software Insights Platform. It reads every repository, scores it on a calibrated model benchmarked against 2,700 open-source systems, and tracks the result week after week. This page is the specification; the services are where it becomes a decision.

Maintainability Cloud / benchmark distribution
The Maintainability Cloud: every repository plotted by maintainability score against volume in person-years, with the benchmark in grey
What is measured

One benchmarked scale, every repository

Every measure is produced for every repository in scope, on the same scale, so systems compare like for like whoever wrote them.

Maintainability
A score from 1 to 5 for the characteristic as ISO/IEC 25010:2023 defines it (one of nine product-quality characteristics), aggregated from the properties below with calibrated weights and benchmarked against real-world systems.
Volume and growth
The size of each codebase in person-years of engineering effort, research-backed and comparable across more than fifty languages, and its growth over time. Growth reported next to quality is what makes a fast-growing, flat-quality codebase visible.
Properties
Duplication, unit size, unit complexity, file size and test ratio: the code-level properties that determine how easy a system is to analyse, change and test.
Risk exposure
Dependency vulnerabilities, secrets in git history, open-source licence obligations and an SBOM per repository, read alongside quality rather than in a separate tool.
Architecture
The dependencies, boundaries and layering as implemented in the code, set against the intended architecture and tracked as the gap moves. Typically needs expert configuration; not every technology is supported.
History and people
File age and change frequency, and contributor patterns that show where critical systems depend on a single individual.

Feature availability depends, among other things, on the technologies used and the client’s data-sharing policy.

The benchmark

A score is a position among recognised peers

[ 01 / SYSTEMS ]

2,700 open-source systems

The calibrated benchmark includes systems from Google, Apache, Amazon, Spotify, Mozilla and Netflix, measured on the same instrument as your code.

[ 02 / EFFORT ]

8,400 person-years

The engineering effort in the reference set, maintained and re-calibrated over time so the scale stays honest as the industry moves.

[ 03 / LANGUAGES ]

50+ languages

One measurement model, comparable across languages and technology stacks, so a polyglot portfolio still reads on one scale.

[ 04 / DIRECTION ]

Weekly, for years

Every repository is measured every week, and the history is kept, so a score becomes a direction of travel and improvement can be proven against the baseline.

The engine

Open standards, proprietary calibration

Analysis
Built on the open-source Sokrates analysis engine, with further engines plugged in for security, licences and SBOM. The scoring models on top are Claroview’s own, calibrated against the benchmark.
Standards
Maintainability is measured as ISO/IEC 25010:2023 defines it, the current edition of the standard (it replaced ISO/IEC 25010:2011). The standard defines what quality is; the benchmark is how we measure it.
Languages
Java, C#, JavaScript, TypeScript, Python, Go and many more. Where a technology is not supported, we say so in scoping.
Delivery models
Cloud analysis: Claroview reads the repositories and runs everything. Local analysis: the analysis runs in your environment and only the results reach the platform. Report upload: the source never leaves. Each step away from cloud analysis narrows what the platform can see, and we say so up front.
Access
Read-only repository access, single sign-on for your people, nothing to install or operate.
Services

Where the measurement becomes a decision

Software Portfolio Assurance
Weekly measurement of every repository in a portfolio, with the review rhythm that turns it into decisions. Also for a single application as Application Monitoring.
Software Risk Assessment
A one-off, benchmarked deep analysis for due diligence, vendor assessment, AI readiness or strategic planning.
Enterprise Architecture Measurement
Model quality and the drift between intended and implemented architecture, for the readiness question.
SharePoint Repository Analysis
The structure of your digital workspace, made visible and measurable.