New! Listen to Concept to Cloud - Real stories from the trenches of software engineering

Offer · Technical Due Diligence

The technical due diligence your investment committee actually needs.

Two to three weeks of senior engineering diligence, pre-deal or post-close. Platform, team, security, cost, and roadmap read in the language your IC already uses. Quantified remediation plan, fixed cost ranges, walk-away recommendation if the honest answer is walk away.

Book a 30-minute call

2 to 3 weeks · $50,000 · fixed fee · credited in full against the build if we do the remediation

What the memo covers

A memo, not a redlined template.

Every assessment produces a 12-20 page board-ready memo plus a raw-findings appendix. Written by the senior engineer who did the diligence, not routed through a partner.

Overall risk rating

Green, yellow, or red on the deal thesis. Three deal-changing risks called out by name with cost-to-remediate ranges.

Architecture read

Data flow, service boundaries, single points of failure, dependency risk, replatform difficulty. An ATAM-style trade-off analysis of where the architecture bends under the deal thesis, diagrammed, not narrated.

Team read

Key-person risk, seniority mix, tenure curve, culture signals. Who is load-bearing and what happens if they leave inside the hold period.

Security and compliance

Audit posture, sensitive-data handling, secrets management, access controls, incident history. What is a Day-1 problem vs. a Q4 problem.

Cost read

Cloud spend attribution, vendor lock-in, contract cliffs, where the money is going and where it will go once volume grows.

Roadmap credibility

Can this team ship what the plan says they will ship, on the timeline the model assumes. Honest answer, no waffle.

Process

Two to three weeks, start to signed memo.

1

Kickoff and access

Days 1-2

NDA signed, data-room access confirmed, deal thesis briefing from the deal team, contact protocol agreed with the target's engineering lead.

2

Read and interview

Days 3-7

Code, cloud accounts, incident history, dependency graph, architecture docs, team interviews. Findings logged as we go.

3

Synthesise and quantify

Days 8-9

Findings shaped into the memo. Risk rating, top-three deal-changers, remediation cost ranges, roadmap credibility, walk-away signal if there is one.

4

Delivery and Q&A

Day 10

Memo sent, live walkthrough with the deal team, IC-facing summary if you need one, and a first-week playbook mapped for post-close if you go through with it.

Who buys this

Three buyers, same discipline.

Pre-deal

Operating partner in a live LOI

You have a target in diligence and the tech is core to the thesis. The assessment confirms the thesis, reprices it, or kills the deal. Two to three weeks, memo in your IC pack.

Post-close

Portco CTO in month three

You inherited the platform, the value-creation clock is running, and you need a defensible technical baseline you can take to the board. The assessment produces the baseline plus a first-year roadmap.

Sell-side prep

Founder preparing for exit

You want to know what the buyer's DD team will find before they find it. The assessment produces a "friendly DD" surfacing the issues while you have time to fix or reframe them.

Sample findings (redacted)

What the memo actually reads like.

A sanitised sample of the kinds of finding that go in the top-three deal-changers section. No client details, but the grammar and price ranges are typical.

Deal-changer · Red

One engineer owns the payment pipeline end to end

The service that handles 100% of revenue-bearing transactions has one committer on the last 18 months of history. No documentation, no runbook, one production incident he resolved by SSHing into a box at 3am and editing config in place. Departure risk is the deal thesis risk.

Remediation cost: $85K-$140K (three-month engagement to document, add a second owner, and set up incident tooling)

Deal-changer · Yellow

AWS spend is 3.4x what the workload justifies

Reserved instance coverage under 5%, three orphaned RDS clusters, staging environment running production-sized workloads 24/7. Not a walk-away, but the cost model in the CIM is off by roughly $260K/year. Fixable in a quarter with the right ownership.

Remediation cost: $35K-$60K (six-week engagement with an SRE) · Annual savings: $220K-$300K

Deal-changer · Yellow

Roadmap and delivery velocity do not match

The 100-day plan assumes shipping two major features per quarter. Git history shows one major feature per quarter over the last four quarters. Not a lie, but the current team cannot execute the pitched roadmap at current headcount. Either the plan needs to be rescoped or three senior engineers need to be added, ideally before the LOI is signed.

Remediation: Rescope plan (free) or budget $600K/year for three senior hires

Questions PE firms ask first

The honest answers before you commit.

What are the key components of a technical due diligence checklist?
Seven areas: architecture and scalability, code quality and technical debt, team and key-person risk, security and compliance posture, infrastructure cost, roadmap credibility, and IP ownership. Our ten-business-day read scores all seven and prices the top risks with cost-to-remediate ranges. A checklist that doesn't end in dollar figures is a questionnaire.
What are red flags in due diligence?
The five that most often change a deal: one engineer holding the whole system in their head, releases that depend on a person rather than a pipeline, security posture that stops at a pen-test PDF, cloud spend growing faster than revenue, and a roadmap the engineering team quietly disbelieves. Any one of these moves valuation; two or more usually reprice the deal. The discipline is the same whether the data room labels it technical, tech, or IT due diligence.
How is this different from a Big-4 or boutique DD firm?
We are engineers, not consultants. You get senior operators reading the code, the pipelines, the cloud accounts, and the incident history, not a partner-and-associate model where the analysis is done by a junior. The output looks like what an engineering leader would write for their own board, not a redlined template. And the price and timeline are set before we start.
What size of company does this fit?
Lower and middle market. Roughly $10M-$250M revenue, engineering teams of 5-50. Below that we usually cost more than the diligence value. Above that the target likely has an internal function that will resent us, and you probably need a bigger firm anyway. The sweet spot is a target where the tech is core to the thesis but the engineering org is small enough to review in two to three weeks.
Can you run this pre-deal, inside a live LOI window?
Yes, and most reads are pre-deal. We compress to two to three weeks, work off data-room access plus one engineering call with the target, and hand you a memo commercial and legal can sit alongside on the risk register. If the target refuses engineering access, we can still deliver an external-signal read: hiring patterns, tech-blog history, public incidents, dependency choices, cloud footprint. It is a weaker view but it is a real one.
What does the deliverable actually look like?
A 12-20 page memo plus an appendix. The memo covers: overall risk rating, top three deal-changing risks with cost-to-remediate ranges, architecture read, team read, security and compliance read, cost read, roadmap credibility. Appendix has the raw findings, the interview notes, and any code observations. Everything is written in the language your investment committee already uses.
Do you take a finder or referral fee from the sell side?
No. We are paid by you, fixed fee, and we have no relationship with the target, the banker, or the CEO before the engagement. If the honest view is that this deal should be walked away from, you hear that.
What happens if we go on to buy the company?
You have a first-week playbook the moment you close. The remediation plan we wrote maps directly to a 100-day-style path. If you want us to run it, we do (see Modernise and Build). If you want us to hand it to your operating team or a different builder, we do that too. The assessment is yours regardless of who executes.
Do you sign an NDA?
Yes, we sign either your NDA or ours before we look at anything. Data-room access is on your terms.

Send Tom a few lines about the deal.

The target, the platform, the timeline. A senior engineer will write back honestly about whether this is the right engagement.

Book a 30-minute call