Technical Due Diligence Code Audits
An independent, third-party review of a startup's codebase before money or ownership changes hands. We tell investors and acquirers what they are actually buying, and help founders find and fix the issues before someone else's reviewer does.
For investors, acquirers, and founders · NDA available · written findings, not a sales pitch. Read client case studies.
What technical due diligence surfaces
Pitch decks describe the product. The repository describes the risk. These are the areas where a codebase most often changes a valuation, a deal structure, or a post-close plan.
Security liabilities
Broken access control, exposed secrets, unverified payment flows, and unpatched dependencies are inherited by the buyer along with the code, as is any data already exposed.
Architecture that will not scale
Single-tenant assumptions, synchronous work on request paths, and missing indexes can work for hundreds of users and fail at the growth the deal assumes.
Dependency licensing and provenance
Copyleft licences in shipped code, abandoned packages, and unclear origin of copied snippets can create obligations or rework that should be known before signing.
Unreviewed AI-generated code
Large volumes of AI-written code with no tests or review history are harder to maintain and reason about. We assess how much of the system the team can actually explain and change safely.
Key-person and process risk
No CI, no code review, manual deploys, and knowledge held by one founder all affect how quickly a new team can operate the product after close.
Hidden rewrite cost
Some codebases need targeted fixes; others need a partial rebuild. We separate the two so the remediation estimate is grounded in the code, not in guesswork.
What the due diligence report includes
A fixed-scope engagement that produces two layers of output: an executive summary for decision-makers and detailed findings for engineers.
How a due diligence engagement works
- 1
Scope and access
We agree the questions the review must answer, sign an NDA if needed, and receive read-only repository and infrastructure access.
- 2
Codebase and infrastructure review
We review the code, configuration, dependencies, and deployment setup, prioritising the flows that carry revenue and user data.
- 3
Team conversation
A short technical interview with the engineering lead clarifies intent, roadmap, and anything the code alone cannot explain.
- 4
Report and walkthrough
You receive the executive summary and detailed findings, followed by a call to discuss severity, remediation effort, and open questions.
Founder pre-diligence checklist
Start here before you book anything. If any of these fail or you are not sure how to check, that is the signal to get a second pair of eyes.
- Every production secret is in a secrets manager or environment config, and none appear in git history.
- You can produce a dependency list with licences, and nothing copyleft is shipped in a way you cannot explain.
- A second engineer can set up the project locally and deploy it from documentation alone.
- Users cannot access another user's or tenant's data when tested with two accounts.
- Database backups exist, are automated, and have been restored at least once.
Want a scored version? Take the free vibe code security check or work through the 25-point launch checklist.
Frequently asked questions
Related services and guides
Code audit services
Our full code audit process and deliverables.
Code audits for startups
Pre-launch and pre-raise reviews for early-stage teams.
Supply chain security audit
Dependency, licence, and CI pipeline review.
Code audit pricing
How fixed-scope audit pricing works.
Case studies
Examples of real audit engagements.