Technical due diligence on the code, not the pitch

An independent read of a codebase before you buy, invest, or commit to a rewrite: scored out of ten across ten dimensions, with the findings priced. The 29 codebases we did not write averaged 4.21 out of 10 on a first read — 3 of them cleared 7.

Hire ExpertsHire Experts

What a diligence engagement covers

  • Diligence before a cheque clears

    The read an investor or acquirer needs and rarely gets: what the codebase is, what it would cost to keep, and which of the seller's claims the code supports. Our scored reports run to a number out of ten across ten dimensions, so two targets can be compared on the same scale rather than on two consultants' prose.

  • Diligence on a team you are about to inherit

    Often the more useful version. The code is a proxy for how the team worked: whether anyone wrote a test, whether secrets are in the repository, whether deployment is a script or a person. That tells you what the first six months after the deal actually involve.

  • A second opinion on your own product

    Boards ask for this before a raise, and CTOs ask for it before a rewrite argument they expect to lose. We score our own repositories on the same scale and publish the number — 6.03 out of 10 across 57 of them — so you can see what we consider a passing grade before you hear ours about you.

  • The remediation plan, priced

    Findings ranked by what leaving them alone costs rather than by severity label, with an estimate against each. A diligence report that ends at "technical debt is high" transfers no information to a deal model.

How a diligence read runs

  1. Before we start

    Read access, and half an hour with someone who can say what the product is meant to do. Without that second part an audit grades style instead of risk — it will flag a long function and miss that the architecture cannot carry the roadmap the deal is priced on.

  2. Days 1–2

    Our own audit bot reads the repository and scores it across ten dimensions: quality, security, architecture, testing, documentation, DevOps, dependencies, error handling, performance and technical debt. It ran 156 times against client repositories between September 2025 and January 2026, so the scale is calibrated against real codebases rather than against an idea of a good one.

  3. Days 3–5

    An engineer who maintains production systems reads what the bot flagged plus the parts it cannot judge: whether the data model matches the business, where the load will land, what the deployment story really is. The bot finds symptoms; a person works out which ones matter to your deal.

  4. End of the week

    The report and a call to argue about it. The argument is the valuable part — a number without someone to challenge it is what made us stop selling this as software.

  5. After

    You own the report. Take it to your own team, to the seller, or to another vendor. If you would rather we had no stake in what happens next, say so before we start and we will price the audit as the only deliverable.

How the work is scoped

  • One codebase, one week

    The common shape. A week for a typical repository, two if it is large or split across many services, and a fixed price because the scope genuinely is fixed.

  • A portfolio on a schedule

    What we run on our own estate: every repository scored on a cadence and an engineer reading the deltas, so a codebase that is drifting is visible before it is a rewrite. 220 runs across 57 repositories is what that looks like in practice.

  • Audit, then hands

    Where you already know you need the work done. We still write the report first, so the list of what we are fixing exists before anyone bills for fixing it.

Who reads the code, and on whose clock

Where the team sits

More than half our engineers now sit in Latin America, with most of the rest in Eastern Europe. On diligence the overlap is the deliverable as much as the report is: findings are worth most while they are fresh and the deal is still open, and a call the same day beats a document a week later.

How people get here

The engineers who do this came through the same funnel as everyone else here — about one hire per 130 applications on the front-end side and 157 on the back end. There is no cheaper tier of reviewer, because a review is worth what the reviewer has already broken in production. The audit practice this grew out of carries the rest of that history, including the years we ran it as a product.

Frequently Asked Questions

Ready to get started?

Contact us at [email protected] or fill out the form

get-started-hero

Company Details

Additional Information