Due diligence

Know exactly what you're buying

Technical due diligence is a buyer-side audit of what a target company actually owns and runs online. When you acquire a company, you acquire its website, its code, and every account those depend on. We audit all three from the buyer's side and hand you a plain-English report: what's solid, what needs work, and what's worth raising at the table. This is technical due diligence only — not legal or financial.

Your accountants and attorneys have their half. This is the other half.

A deal team can read a P&L and a contract cold.

The technology is the piece that usually arrives as a screenshot and a founder's word for it — and it's often the asset the whole purchase price rests on. We go through the site, the code, the hosting, and the accounts the way an owner would on day one, then write down what we found in language you can hand straight to your lawyer, your lender, or the seller.

What's included in a diligence engagement

Code and stack review

What the software is actually built on, how current it is, how much of it is custom versus off-the-shelf, and how realistically another team could pick it up and keep going.

Site health and performance audit

Load speed on real phones, mobile behavior, search visibility, and accessibility exposure — measured, not estimated, so seller claims about the site can be checked against numbers.

Ownership and access inventory

Domains, DNS, hosting, code repositories, analytics, ad accounts, email, and any paid tools — who legally holds each one today and what has to move at closing for you to control them.

Dependency and license check

The third-party software the site leans on, including open-source components (free code the business reuses) and paid subscriptions. We flag anything that expires, doesn't transfer, or carries terms a buyer should read.

Security and data-handling review

Where customer data lives, who can reach it, and what's obviously exposed. A technical read on the risk — your counsel still owns the legal privacy opinion.

Cost-to-carry estimate and risk register

Every finding ranked by severity with the rough effort to fix it, so what we found converts into a number you can price into the offer or hold back at closing.

How a diligence engagement runs

  1. 1

    Scope and access

    We agree what's in scope, sign whatever NDA the deal requires, and work from whatever access the seller grants. Where access is limited, we say so and audit from the outside.

  2. 2

    Audit

    Hands-on review plus automated scans across the site, the code, the infrastructure, and the accounts. We record what we verified ourselves and what we could only take on the seller's word.

  3. 3

    Findings call

    We walk you and your deal team through what we found before anything is final, so you can ask follow-ups and redirect us while the deal is still live.

  4. 4

    Report and deal support

    You get the written report with the ranked risk register. We stay available to answer your advisers' questions and to re-check anything the seller agrees to fix before closing.

The same way we run every engagement — how we work →

A good fit if

  • You're acquiring a business whose website is the product
  • You're buying a site or app and want a second technical opinion
  • Your legal and financial diligence is covered and the technical half isn't
  • You need a defensible number for what taking the technology over will cost
  • The seller has made claims about traffic, speed, or code you'd like verified

Questions we get about technical diligence

No — and we're deliberate about that line. We cover the technical side: the website, the code, the hosting, the accounts, and the data. Contracts, intellectual-property ownership, regulatory compliance, and the financial statements belong to your attorney and your accountant. Our report is written to sit alongside theirs and cover the part their scope doesn't.
Both the price and the schedule move with how large the codebase is and how much access the seller provides, so we'll give you a firm number and schedule after the first conversation. Deals run on deadlines, so tell us your date and we'll tell you honestly what we can cover by then.
That's common, especially early. A great deal can still be assessed from the outside — performance, search footprint, public infrastructure, and the visible parts of the stack. We report what we verified and label what we couldn't, rather than filling gaps with guesses.
On a due diligence engagement, the acquirer — we work for you and the findings go to you. If you're on the other side of a deal and want your own site valued or tidied up before it goes to market, that's a separate engagement and a separate team.

Tell us what you're looking at.

Start your project

A few quick questions — about two minutes.