Skip to main content
Home/Services/Technical Due Diligence
Technical Due Diligence

Know the codebase before you buy it.

An independent assessment of a target company's software — quality, security, architecture and key-person risk — delivered as a clear, evidence-backed report. Every finding traces to the actual code, because we analyse it as a knowledge graph, not by reading a pitch deck.

Investors PE & VC firms Acquirers Boards & CTOs
What We Assess

The eight questions every technical DD must answer.

Not a checklist read off a README — each is measured against the codebase itself.

Code quality & maintainability

Complexity, duplication, test coverage and how hard the code is to change safely.

Security exposure

Known-pattern vulnerabilities, secret handling, dependency and supply-chain risk.

Technical debt

Where the debt sits, what it will cost to service, and whether it blocks the roadmap.

Bus factor & key-person risk

From Git history — how much knowledge sits with how few people, and where.

Architecture risk

Coupling, cyclic dependencies, service boundaries and single points of failure.

Scalability & performance

Whether the architecture supports the growth the deal thesis assumes.

Remediation effort estimate

A grounded estimate of the engineering effort to fix, harden and scale what's there.

Licensing & open-source risk

Third-party and OSS licenses that could constrain the business post-acquisition.

The Deliverable

A report your investment committee can act on.

Written for decision-makers, backed by evidence engineers can verify.

Sample scorecard Report format only — the figures below are illustrative, not the result of an actual assessment.
Sample figure

Your report carries your codebase's real scores, each traceable to the file, module or dependency behind it.

How It Works

Repository in. Decision-ready report out.

A fixed-scope, fixed-fee engagement — typically delivered within days of access.

Step 01

Connect

Read-only access to the target repository (or an offline copy) under NDA. Nothing leaves the agreed environment.

Step 02

Map & analyse

We build the code knowledge graph, run the analysis, and validate findings against the target's own team.

Step 03

Report & brief

You receive the report and a live Q&A session — in time for your investment decision.

Why It's Different

Evidence, not impressions.

A senior engineer skimming a repo for a week gives you opinions. We analyse the whole codebase as a graph, so the report is complete, repeatable and traceable.

Whole-codebase coverage

The graph sees every file and dependency — not a sampled skim under deadline.

Every finding cited

Each claim links to the exact code it came from, so your team can verify it.

Independent & confidential

Read-only, under NDA, in an environment you control. No conflict, no code exfiltration.

Diligence on the clock?

Send us the repository access and your deadline — we'll tell you what we'll deliver and when.

Request an assessment