Technical Due Diligence
Know what you are buying before you sign. Independent technical due diligence on a target's security, systems, code and people, with findings you can price into the deal.
Service Details
Technical due diligence tells you what you are buying before you commit. You get an independent review of the target’s security, systems, code and technical team, written for a deal team rather than engineers, with each risk sized so you can price it.
Acquisitions, investments and mergers carry risks that rarely show up in the data room. We find them while you still have room to negotiate. This service is part of our strategy and advisory services.
INFO
Every finding comes with a severity, an estimated cost to fix and a recommendation: price it in, cover it with a warranty, or fix it after completion.
What we look at
A security review alone misses half the picture. You get a view of the whole technology operation:
Infrastructure and security
Cloud and on-premises estate, identity and access, backups, monitoring and how well the target could withstand and recover from an attack.
Code and software
Architecture, code quality, open-source licensing, technical debt and whether the platform can scale to meet your growth plan.
People and process
Team skills, key-person dependencies, delivery practices and the capability gaps you would need to fill after completion.

Risks that rarely appear in the data room
Sellers present their technology at its best. These are the issues we most often find once we look underneath:
- Unpatched or unsupported systems — that would need replacing soon after completion.
- Weak identity controls — such as shared admin accounts or no multi-factor authentication.
- Untested backups — that would not restore a working business after ransomware.
- Open-source licence conflicts — that put ownership of the product's IP in question.
- Compliance gaps — against GDPR, PCI DSS or sector rules that bring regulatory exposure with them.
- Single points of failure — where one engineer holds critical knowledge.
How a review runs
We agree scope with your deal team, work with the target under NDA and report on your timeline. You get a clear summary for decision-makers and the technical detail your advisers need.
Scope
Agree priorities, access and deadlines with your deal team
Assess
Interviews, document review and hands-on technical checks
Report
Risks ranked by severity and cost, ready for negotiation
After completion
Due diligence findings are only useful if someone acts on them. We can turn the report into a 100-day plan, run a deeper security posture review, carry out penetration testing on the acquired estate, or provide a fractional CISO or CTO while you hire.
Investing across a portfolio? See how we support private equity sponsors, or read about our deal security solution, which carries findings through to post-acquisition integration. Boards wanting ongoing oversight can use our board advisory service.
Frequently asked questions
Planning a deal?
Tell us about the target and your timeline. You get a review scoped to your deal, with findings ready while you can still negotiate on them.