Know exactly what you're investing in — before you wire the money.
A polished demo and a confident founder hide a lot. I give investors and acquirers a senior, independent read on the technology behind a deal — the architecture, the code, the security posture, and the team — so the surprises surface before the round closes, not eighteen months after. Software due diligence for investors, written by someone who has built and run the real thing.
The technology is where the expensive surprises hide. A clean cap table and strong revenue can sit on top of an architecture that won't scale, a codebase one key engineer away from collapse, or licensing exposure that surfaces in the next funding round. Technical due diligence is how you find out before you commit — not after. I assess the system the way I'd assess one I was about to take over as CTO, then tell you plainly what's solid, what's fragile, and what it will cost to fix.
Screening a target, or a founder gauging your own readiness? Run the free DD-Readiness Check → for an instant read on the 8 dimensions I diligence.
- I've built and run what I assess — architected and led the engineering behind platforms that raised $33M+ and scaled across 8 international markets
- 20+ years as a founder, CTO, and technology advisor across Europe and the Middle East
- Built and led engineering teams of up to 150 across e-commerce, SaaS, and food-tech
- I don't broker the deal — my only job is to tell you the truth about the technology
- Investor-grade diligence delivered on real deals — including the technical read behind a venture-backed marketplace's raise
- Findings at altitude: what each risk means for the round, the roadmap, and the valuation — not a wall of jargon
What technical due diligence covers
A thorough technology due diligence engagement looks past the pitch and into the system itself. I work across every area where a deal's technical risk actually lives:
Architecture & scalability
Whether the design holds up at 10x the current load — or quietly assumes it never will. Bottlenecks, single points of failure, and the rework scaling will force.
Code quality & maintainability
How the code is actually written: structure, test coverage, documentation, and how easily a new team could pick it up and keep shipping.
Security & compliance
Vulnerabilities, data handling, access controls, and exposure against the standards the business is held to — before an incident or auditor finds them.
Infrastructure & cost efficiency
Cloud and deployment setup, reliability under real load, and whether the infrastructure spend is proportionate or quietly eating the margin.
Technical debt
The shortcuts taken to ship fast — and what they'll cost to unwind. The debt that will slow the next 18 months, quantified rather than hand-waved.
Engineering team & process
Whether the people and the practices can deliver the plan you're funding. Delivery cadence, hiring health, and how the team performs without heroics.
IP, licensing & open-source exposure
Who actually owns the code, and what's been pulled in from open source. License conflicts and IP gaps that can complicate a future exit.
Roadmap & key-person risk
Whether the product roadmap is credible against the architecture — and how much of the business lives in one person's head.
Red flags I surface
Every diligence is specific to the company, but the warning signs repeat. Common red flags I surface include:
- A roadmap that depends on a rewrite the team keeps postponing
- Critical systems only one engineer fully understands — and no documentation if they leave
- Test coverage and CI that exist on paper but aren't actually run before releases
- Infrastructure costs scaling faster than usage, with no clear path to fix it
- Security basics missing — unpatched dependencies, secrets in the repo, no access controls
- Customer or personal data handled in ways that won't survive a compliance review
- Open-source components under licenses that conflict with a future sale
- Unclear IP ownership — code written by contractors with no assignment in place
- "Velocity" that's really firefighting, with deploys feared rather than routine
- A demo that works only on the happy path, with the hard cases quietly unbuilt
What you receive
Diligence is only useful if it's decision-ready. You get findings a partner or investment committee can act on, not a jargon dump:
- Findings report: a clear, prioritized assessment of the technology — what's solid, what's fragile, and why it matters to the deal.
- Risk rating: the critical risks ranked by likelihood and impact, so you know which findings are dealbreakers and which are manageable.
- Remediation roadmap: what it will take to fix the gaps — scope, sequence, and rough cost — so you can price the risk or build it into the plan.
- Infrastructure & cost view: how the systems are deployed and what they cost to run, with the inefficiencies that scale into a real number.
How it works
Scoping call (20 min) — scope, timeline, and access.
Fixed-fee proposal within 24 hours.
Findings in 3–5 working days from access (larger targets quoted at scoping).
When to commission technical due diligence
- Pre-term-sheet: a fast, focused read to decide whether the technology justifies going deeper on a deal.
- Confirmatory diligence: the thorough assessment before you commit capital, validating that the technical story holds up.
- Pre-acquisition: a full software due diligence for acquirers — integration risk, hidden liabilities, and what you're really buying.
- Post-investment health check: an independent CTO due diligence on a portfolio company, to catch technical risk before it becomes a write-down.
Why an independent operator
Most technical due diligence is run by people who have read a lot of codebases but never had to own one. I've built and run what I assess. As co-founder and CTO of The Cloud and founder of NatWeb Solutions, I architected and led the engineering behind platforms that raised $33M+ and scaled across 8 international markets — and I still build and run my own products today, including LoanPilot. Most recently I executed a full production backend rebuild in days using AI-assisted development — the read you get is calibrated to what modern delivery actually looks like (see the case study). I know the difference between a calculated shortcut and a time bomb because I've shipped both.
And I'm independent. I don't broker the deal, I don't take a cut of it, and I have no stake in whether it closes. My only job is to tell you the truth about the technology — clearly enough that you can act on it. That independence is the whole point: it's the difference between a report written to reassure and one written to inform.
Who this is for
- VCs, PE firms, and angels validating the technology before they commit capital
- Acquirers who need to know exactly what they're buying — and what it will cost to integrate
- Investment committees who want an independent, senior read on technical risk and opportunity
- Founders preparing their technology to withstand investor or acquirer diligence
Raising rather than investing? I also prepare founders to pass the diligence I run — narrative, metrics, architecture, and data room. Investor Readiness →
Don't leave the technology to a demo and a hope. Get a confidential, senior, independent assessment before you invest, acquire, or scale — focused on the business outcome, not the buzzwords.
Fixed fee — scoped to deal size, quoted within 24 hours of a 20-minute call.
Get a senior, independent read before you wire.
I read every message and reply personally.




