Technical Due Diligence

Technical Due Diligence Code Audits

An independent, third-party review of a startup's codebase before money or ownership changes hands. We tell investors and acquirers what they are actually buying, and help founders find and fix the issues before someone else's reviewer does.

For investors, acquirers, and founders · NDA available · written findings, not a sales pitch. Read client case studies.

What technical due diligence surfaces

Pitch decks describe the product. The repository describes the risk. These are the areas where a codebase most often changes a valuation, a deal structure, or a post-close plan.

Security liabilities

Broken access control, exposed secrets, unverified payment flows, and unpatched dependencies are inherited by the buyer along with the code, as is any data already exposed.

Architecture that will not scale

Single-tenant assumptions, synchronous work on request paths, and missing indexes can work for hundreds of users and fail at the growth the deal assumes.

Dependency licensing and provenance

Copyleft licences in shipped code, abandoned packages, and unclear origin of copied snippets can create obligations or rework that should be known before signing.

Unreviewed AI-generated code

Large volumes of AI-written code with no tests or review history are harder to maintain and reason about. We assess how much of the system the team can actually explain and change safely.

Key-person and process risk

No CI, no code review, manual deploys, and knowledge held by one founder all affect how quickly a new team can operate the product after close.

Hidden rewrite cost

Some codebases need targeted fixes; others need a partial rebuild. We separate the two so the remediation estimate is grounded in the code, not in guesswork.

What the due diligence report includes

A fixed-scope engagement that produces two layers of output: an executive summary for decision-makers and detailed findings for engineers.

Executive summary with an overall risk view and deal-relevant findings
Security review of authentication, authorization, data handling, and secrets
Architecture and scalability assessment against the stated growth plan
Dependency inventory with known vulnerabilities and licence flags
Assessment of AI-generated code, test coverage, and maintainability
Engineering process review: CI/CD, code review, environments, backups
Remediation plan separating quick fixes from structural work
Walkthrough call with investors, acquirers, or the founding team

How a due diligence engagement works

  1. 1

    Scope and access

    We agree the questions the review must answer, sign an NDA if needed, and receive read-only repository and infrastructure access.

  2. 2

    Codebase and infrastructure review

    We review the code, configuration, dependencies, and deployment setup, prioritising the flows that carry revenue and user data.

  3. 3

    Team conversation

    A short technical interview with the engineering lead clarifies intent, roadmap, and anything the code alone cannot explain.

  4. 4

    Report and walkthrough

    You receive the executive summary and detailed findings, followed by a call to discuss severity, remediation effort, and open questions.

Founder pre-diligence checklist

Start here before you book anything. If any of these fail or you are not sure how to check, that is the signal to get a second pair of eyes.

  • Every production secret is in a secrets manager or environment config, and none appear in git history.
  • You can produce a dependency list with licences, and nothing copyleft is shipped in a way you cannot explain.
  • A second engineer can set up the project locally and deploy it from documentation alone.
  • Users cannot access another user's or tenant's data when tested with two accounts.
  • Database backups exist, are automated, and have been restored at least once.

Want a scored version? Take the free vibe code security check or work through the 25-point launch checklist.

Frequently asked questions

Preparing for a raise or acquisition?

Book a free 30-minute call. Tell us about the deal timeline and the questions the review needs to answer, and we will send a fixed-scope quote.