Techstacked Technical due diligence

Technical due diligence

The technical side of the deal.

We read the codebase, the infrastructure and the commit history, then write a report you can give to counsel or a lender. Every finding has a source, a cost, and what it does to the purchase price. If we couldn't see something, we say so rather than guess. Seven days, fixed fee. We get paid whether the deal closes or not.

Findings summary TS-0431 · REV 2
  • Critical $340,000 · 6 mo

    AGPL-3.0 dependency sits inside the billing core. Any distribution of the product triggers copyleft on proprietary code. Requires commercial relicense or rewrite before a strategic resale.

  • Elevated $180,000 · risk

    71% of commits to the payments and provisioning services trace to a single contractor, off payroll since Q3. No architectural documentation. Knowledge transfer is unpriced in the model.

  • Elevated $95,000 · 3 mo

    PostgreSQL 11 in production, past end-of-life. Two extensions in use have no supported equivalent on 15+. Upgrade path is untested and blocks the SOC 2 timeline.

  • Clear no adjustment

    Deployment and test discipline are genuinely strong: 74% coverage, automated rollback, no manual production access. This team is better than the codebase suggests.

Remediation absent from the seller's model $615,000
Illustrative composite. Figures and findings are representative of a typical engagement, not drawn from a single client.
Turnaround
7 days
Fee
$8K–15K
Billing
Half up front
Contingent on close
Never

Why this exists

Traditional technology diligence was built for larger transactions.

The established firms quote $25K–$150K on a four-to-eight week timeline, with a rush premium to fit an exclusivity window. That math works on a platform deal. Techstacked is built around the economics and timelines of lower-middle-market acquisitions, so the assessment actually gets bought.

Traditional advisory

$25K–150K

Four to eight weeks. Priced for platform deals and institutional sponsors.

What most buyers do

$0

A founder's word, a friend-of-a-friend code review, and hope. The default on most of these deals.

Techstacked

$8K–15K

Seven business days, fixed fee. Automated analysis does the volume; judgment does the rest.

Scope

What we look for, and why it moves a number.

01

License and dependency exposure

Copyleft contamination, abandoned packages, unpatched CVEs. The single most common finding that survives legal diligence untouched. This is exposure in the artifacts, not a legal opinion on title or enforceability.

02

Concentration and bus factor

Commit history by author across the life of the repository. If one departed contractor owns the core, you are buying a rewrite.

03

AI dependency and margin exposure

Whether the AI product is defensible or a thin wrapper, what happens to gross margin when the provider reprices, and where the lock-in sits.

04

Infrastructure cost curve

Whether hosting scales linearly with revenue or superlinearly with users. Determines whether the growth case survives contact with the bill.

05

Security posture and compliance cost

Secrets handling, authentication patterns, tenant isolation, and a costed path to SOC 2 if enterprise expansion is in the thesis. This is posture from the artifacts, not a penetration test or a certification.

06

Vendor concentration

Subprocessors, single points of failure, and contracts that reprice on change of control. Often the fastest post-close surprise.

07

Roadmap credibility

Whether the team and the architecture can plausibly ship what the growth model assumes, on the timeline it assumes.

08

Costed remediation plan

Every finding carries a dollar figure and a duration, written so it can move a purchase price: evidence, remediation, cost, timing, and the deal treatment. This is the section that goes into your renegotiation, so it is written to be forwarded.

Engagements

Three depths, matched to where the deal sits.

Fixed fee, agreed before we start. 50% on engagement, 50% on delivery of the report. Fees are never contingent on the deal closing: you get the finding either way, and a deal you walk away from is the assessment working. We do not sell remediation, staffing or engineering against the findings, so we do not make more money by finding more problems.

Engagement Fee Turnaround Deliverable
Screen Pre-LOI, or triaging several targets at once $4,000–5,000 3–5 days Ten-page red-flag memo. License exposure, concentration risk, obvious structural problems. Enough to decide whether to proceed.
Standard Most engagements Signed LOI, inside exclusivity $8,000–15,000 7–10 days Full written report across all eight scope areas, costed remediation plan, and a 90-minute readout with your deal team and lender.
Deep A platform you intend to build on, or a more complex hold $20,000–35,000 2–3 weeks Everything in Standard, plus engineering team interviews, architecture deep dive, and a costed first-year technical roadmap for the hold period.

Full engagement detail, by depth

Who we work with

Buyers the big firms won't quote.

Searchers and independent sponsors

The benchmark search acquisition is a $16M business bought around month 20. You have one shot and no in-house CTO. This is the engagement built for you.

Lower-middle-market private equity

Tuck-ins and add-ons that fall below your retained advisor's minimum but still carry real technical risk into the platform.

Brokers and marketplaces

Offer diligence as part of the process. Clean technical findings shorten time-to-close and kill the surprises that break deals in week six.

Private credit and lenders

You are lending against a software asset. We tell you whether the collateral is maintained or quietly decaying before the facility is drawn.

Process

Seven days, structured around your close.

Day 0

Scoping call

Thirty minutes on the thesis, the deal timeline, and what you are most worried about. Fee is fixed at the end of this call.

Day 1

Access

Read-only repository access, cloud billing exports, and the subprocessor list. We work under NDA with the seller directly if you would rather stay out of it.

Days 2–6

Analysis

Automated scanning across dependencies, licenses, and commit history, then manual review of everything the scanners flag and the architecture they cannot see.

Day 7

Report

Written findings with severity and costed remediation, delivered as a PDF built to be forwarded to your lender, your counsel, and the seller.

Day 8

Readout

Ninety minutes with your deal team. We defend every number, and we help you decide what is a price adjustment, what is an indemnity, and what is a walk.

Questions we get

The practical objections, answered.

What if the deal falls apart mid-diligence?

You still owe the balance, and you should still want the report. Fees are never tied to close. Contingent pricing would give us a reason to soften findings, which is exactly backwards. We also do not sell the remediation, staffing or engineering that the report costs, so a longer findings list does not become a larger follow-on invoice. A deal you walk away from because of what we found is the highest-return engagement we can deliver.

The seller won't give a stranger repository access.

Common, and workable. We sign directly with the seller under NDA and work from a read-only clone or an escrow snapshot rather than live production access. If the seller refuses any form of technical review, that refusal is itself a finding worth reporting.

How is this fast enough to be thorough?

Because the volume work is automated. Dependency graphs, license trees, CVE matching, and commit attribution are machine problems, and running them takes hours rather than weeks. The days are spent on the part that needs judgment: what the results actually mean for your thesis and your price.

We already have a technical co-founder who can look at it.

Then use them, on the architecture and the team, where their context is worth more than ours. What they usually cannot do inside an exclusivity window is the exhaustive license and dependency sweep, or produce a costed, independent document that a lender and a seller will both accept as neutral.

What are the limits of what you'll say?

We assess what the code and infrastructure show. We do not audit financials, verify revenue, or opine on valuation. A security posture review is not a penetration test. License analysis is not a legal opinion. Compliance readiness is not a SOC 2 audit. Technical costing is not a business valuation. Liability is capped at fees paid, we carry professional indemnity cover, and where evidence is thin we say so in the report rather than rounding a guess into a number.

Next step

Read a full report before you commit to anything.

We will send a complete redacted engagement (every section, every finding, the remediation model) so you can judge the work rather than the pitch. If you have a live deal, book a 30-minute scoping call and we will tell you on that call whether we can hit the window.