Due diligence
Know exactly what you're buying
Technical due diligence is a buyer-side audit of what a target company actually owns and runs online. When you acquire a company, you acquire its website, its code, and every account those depend on. We audit all three from the buyer's side and hand you a plain-English report: what's solid, what needs work, and what's worth raising at the table. This is technical due diligence only — not legal or financial.
Your accountants and attorneys have their half. This is the other half.
A deal team can read a P&L and a contract cold.
The technology is the piece that usually arrives as a screenshot and a founder's word for it — and it's often the asset the whole purchase price rests on. We go through the site, the code, the hosting, and the accounts the way an owner would on day one, then write down what we found in language you can hand straight to your lawyer, your lender, or the seller.
What's included in a diligence engagement
Code and stack review
What the software is actually built on, how current it is, how much of it is custom versus off-the-shelf, and how realistically another team could pick it up and keep going.
Site health and performance audit
Load speed on real phones, mobile behavior, search visibility, and accessibility exposure — measured, not estimated, so seller claims about the site can be checked against numbers.
Ownership and access inventory
Domains, DNS, hosting, code repositories, analytics, ad accounts, email, and any paid tools — who legally holds each one today and what has to move at closing for you to control them.
Dependency and license check
The third-party software the site leans on, including open-source components (free code the business reuses) and paid subscriptions. We flag anything that expires, doesn't transfer, or carries terms a buyer should read.
Security and data-handling review
Where customer data lives, who can reach it, and what's obviously exposed. A technical read on the risk — your counsel still owns the legal privacy opinion.
Cost-to-carry estimate and risk register
Every finding ranked by severity with the rough effort to fix it, so what we found converts into a number you can price into the offer or hold back at closing.
How a diligence engagement runs
- 1
Scope and access
We agree what's in scope, sign whatever NDA the deal requires, and work from whatever access the seller grants. Where access is limited, we say so and audit from the outside.
- 2
Audit
Hands-on review plus automated scans across the site, the code, the infrastructure, and the accounts. We record what we verified ourselves and what we could only take on the seller's word.
- 3
Findings call
We walk you and your deal team through what we found before anything is final, so you can ask follow-ups and redirect us while the deal is still live.
- 4
Report and deal support
You get the written report with the ranked risk register. We stay available to answer your advisers' questions and to re-check anything the seller agrees to fix before closing.
The same way we run every engagement — how we work →
A good fit if
- You're acquiring a business whose website is the product
- You're buying a site or app and want a second technical opinion
- Your legal and financial diligence is covered and the technical half isn't
- You need a defensible number for what taking the technology over will cost
- The seller has made claims about traffic, speed, or code you'd like verified
Often paired with buy-side diligence
Questions we get about technical diligence
Tell us what you're looking at.
A few quick questions — about two minutes.
