An independent assessment of a target company's software — quality, security, architecture and key-person risk — delivered as a clear, evidence-backed report. Every finding traces to the actual code, because we analyse it as a knowledge graph, not by reading a pitch deck.
Team & bus-factor analysis — knowledge concentration from commit history.
Remediation plan & effort estimate — prioritized, with rough cost and timeline bands.
Live Q&A session — a working call where your team can interrogate any finding.
How It Works
Repository in. Decision-ready report out.
A fixed-scope, fixed-fee engagement — typically delivered within days of access.
Step 01
Connect
Read-only access to the target repository (or an offline copy) under NDA. Nothing leaves the agreed environment.
Step 02
Map & analyse
We build the code knowledge graph, run the analysis, and validate findings against the target's own team.
Step 03
Report & brief
You receive the report and a live Q&A session — in time for your investment decision.
Why It's Different
Evidence, not impressions.
A senior engineer skimming a repo for a week gives you opinions. We analyse the whole codebase as a graph, so the report is complete, repeatable and traceable.
Whole-codebase coverage
The graph sees every file and dependency — not a sampled skim under deadline.
Every finding cited
Each claim links to the exact code it came from, so your team can verify it.
Independent & confidential
Read-only, under NDA, in an environment you control. No conflict, no code exfiltration.
Diligence on the clock?
Send us the repository access and your deadline — we'll tell you what we'll deliver and when.