before you sign
Technical due diligence: the whole codebase read before you sign
Our platform reads the target's entire codebase in days, and engineers with 25+ years in production tell you what it is worth. In 5–10 days you have the risks ranked, the people it depends on named and a priced plan to fix it.
Within 48 hours: the scope, a fixed price, the report date and an NDA ready for your deal team.
Slides, a vendor questionnaire and a CTO who says the code is fine.
- target codebaseunknown
- seller claimsunverified
- key-person riskunmeasured
- licence exposureunknown
5–10 days from repository access to the final report
Code map, ranked risk register, key-person and licence exposure, a priced plan to fix it.
- code mapwhole repository
- risk registerranked
- cost to fixpriced
- board memoplain language
How the diligence runs
- 01days 1–2
Access and scope
Read access to repositories, CI and infrastructure accounts. When the code cannot leave the building, we run the platform air-gapped on our own hardware inside the target's premises.
- 02days 2–5
Machine pass
The platform parses every language in the tree: call graph, dependencies and their licences, known vulnerabilities, commit history by author, dead code and test coverage.
- 03days 4–8
Engineer review
Senior engineers work through what the machine flagged, interview the target's engineers and check every answer against the code. Where the answers and the code disagree, the code wins and the report says so.
- 04days 7–10
Report and readout
A ranked risk register, the code map and a priced plan to fix each finding, presented to your deal team. The cost of the fixes is a number you can take into the negotiation.
What the platform reads, what our engineers judge
Mapping the codebase and its dependencies
Platform
Every repository and language, including the service nobody mentioned in the data room.
Licence exposure
Platform
Every third-party package and its licence, with copyleft code inside a shipped product flagged by file.
Security exposure
Both
The platform finds known vulnerabilities and leaked secrets. An engineer checks which of them are reachable from outside.
Key-person risk
Both
Commit history shows who wrote each module. Interviews show who is the only one who can still change it.
Ranking the risks
Engineer
By what each one would cost you after closing, in money and in days of work.
Pricing the fix plan
Engineer
A fixed price per phase, ready for your deal model or for the seller's side of the table.
Each finding cites the file and commit it came from, so the target's team can verify it and your lawyers can quote it.
Who reads the target's code
Engineers with more than 25 years of production experience, and the best people to tell you what a codebase will cost after closing. They have built and rescued systems in every stack a target is likely to hold, from COBOL batch to Kubernetes clusters. Our platform reads the whole tree in days, so their time goes on judgement: which findings are routine and which ones change the price.
Fixed price, the report date in the engagement letter, NDA before access. The work can run air-gapped inside the target's premises on our hardware, and the code stays in the building.
Questions deal teams ask
Can you work inside our deal timeline?
Yes. The report lands 5–10 days after access, and when the deal is moving fast you hear about red flags in the first days, as soon as we find them. Put the signing date in your request and we plan back from it.
The target will not let its code leave the premises.
It stays where it is. We bring our own hardware and run the platform air-gapped inside the target's building, with no connection out. Only the report leaves. Ask for the on-site option in your quote today.
What exactly is in the report?
A map of the system, a risk register ranked by cost after closing, key-person risk by module, licence and security exposure, and a priced plan to fix every finding. Your committee reads the summary in an hour and your CTO checks the evidence line by line. Get a quote and have it on your desk within 10 days.
How do you judge a codebase you have never seen?
The platform reads all of it, in every language, in days. Engineers with 25+ years in production then go through what it found and interview the people who wrote it. Very little in a source tree surprises people who have spent their careers inside them. Start the clock today.
Can you also fix what you find?
Yes. Every finding comes with a fixed price, and after closing the same team does the work: security fixes, licence clean-up, a rewrite into Go, Rust or TypeScript in 30 days. Your model gets a real number for post-close work. Ask for both in one quote.
Know what you are buying
Until someone reads it, the code is the one part of the deal your side has taken on trust. Share the target and the signing date today. Within 48 hours you have the scope, a fixed price and the report date, and the report itself lands 5–10 days after access.
An engineer replies with the scope and questions about access. NDA signed before any file changes hands.