Technical Due Diligence
An opinionated assessment across every major aspect of a company’s technology: where the strengths are, where the risk sits, and what neither side has noticed yet.
How a project works
I assess the condition of a company’s technology and what it will take to support its plans. The scope depends on the investment, the company’s stage, and the questions that could affect the decision.
For a Focused Memo, I request specific outputs from the company’s existing systems. A few queries against the issue tracker and a script run against the codebase can reveal significant risks without requiring access to repositories or the full ticket history. A Full Report normally includes more direct code review, a broader examination of the architecture, deployment and production environments, and the overall engineering organization.
Questions Become Findings In an Exchange
- Questions
From Consultant to Target before first call
- Answers
Target answers before or during call
- Dialog
Open discussion about questions and issues
- Clarification
Target can add information and refute negative findings
- Report
Presented to Client in writing and in conversation
The flow of information
I begin by preparing a set of questions for the target company and sending them before the first call. Ideally, the company answers them in advance, allowing the call to concentrate on clarification and follow-up.
This saves time because the first answer to many diligence questions is that someone needs to check a system, consult a colleague, or retrieve a document. Handling those requests before the call makes better use of everyone’s time. It also gives the company an opportunity to provide considered answers rather than responding from memory.
The target company’s first responsibility is running its business, and diligence should not interfere with critical operations. Therefore, written questions may be answered during calls if that’s a better use of time.
Before finalizing my report, I give the company an opportunity to respond to any finding I expect to flag as a significant concern. This allows factual misunderstandings to be corrected and relevant context to be considered. I prefer that the Target companies should not feel blindsided by a report, since the relationship between my Client and its prospective Target is important.
The Difference Between Quick vs. Deep Analysis
| Engagement | Prepare | Examine | Discuss | Report |
|---|---|---|---|---|
| Focused MemoOne main cycle | 2–3 questions in each of 8–10 categories. Questions are selected for the company and investment. | Question-and-answer review. The assessment relies on information supplied by the target. | Two calls. Answers and clarification, followed by open discussion of unresolved questions and potential findings. | Actionable immediate guidance for potential investors. |
| Full ReportThree to four cycles | 3–8 questions in each of 10–12 categories. Questions may include sector-specific research and tests of claimed advantages. | Supervised examination. This may include code, cloud consoles, invoices, project trackers, and other relevant systems. | Two to four calls. This normally includes multiple team members and a detailed review of findings and evidence. | A detailed study of the technology, organization, and risks. This may include the magnitude of remediation costs and competitive analysis. |
Focused Memo
A Focused Memo normally begins with twenty to thirty questions and involves one primary cycle of exchange.
The first call addresses the company’s answers and the questions requiring clarification. The second call provides an opportunity to resolve anything still outstanding and to discuss concerns identified during the first round before I complete the memo.
Full Report
A Full Report examines each practice area in greater depth, usually with three to eight questions per area and direct contact with additional members of the company’s team.
Rather than relying on statistics from the codebase and project-management system, I may ask a team member to share a screen and navigate through those systems under the company’s supervision. I do not request passwords or unsupervised access to repositories, cloud accounts, or internal systems.
I may ask the company to run analytical software against its codebase and provide the results. I may also request a supervised review of cloud-service consoles or invoices from material technology providers, including hosting companies, content-delivery networks, and AI services.
A Full Report normally involves three or four cycles of questions, evidence, clarification, and response. The resulting report is typically ten to twenty pages.
Questions tailored to the company
My questions come from a body of work that I have developed over years of diligence engagements and continue to revise as engineering practices and commonly used systems change.
I adapt that material to the company’s sector and the purpose of the investment. When the engagement includes validating intellectual property or a claimed competitive advantage, I also conduct prior research specific to the company’s products and market.
Coverage
The scope and depth of review depend on the engagement. Areas of assessment include:
- Security
- Testing
- Dependencies
- Code and comment quality
- Scale and availability
- Fault isolation
- Disaster recovery
- Cloud readiness
- Monitoring and logging
- Privacy and compliance
- Accessibility
- Documentation
- Process management
- Organizational knowledge
- Implementation risk
What the assessment contains
The deliverable is a written document, either a Focused Memo or a Full Report, followed by a call to discuss the findings. It explains the significant risks, their likely consequences, and the work needed to address them.
The assessment takes the company’s stage into account. A seed-stage startup is not expected to have the logging, redundancy, and scaling maturity required of a nine-figure business.
My reports include an at-a-glance view, in ‘stoplight’ format. This analysis characterizes the magnitude of risk or deficiency across many aspects of the company’s technical status, using color codes. Each row contains a concise explanation of the reasoning for the flag.
- Red
A high-risk situation has been identified, definitely requires attention.
- Yellow
A deficiency exists, which will need to be addressed in the near future.
- Green
This aspect of the Company appears to have no short-term issues.
Findings can be quite varied
Consumer credit
After several rounds of a CTO failing to answer basic questions, it became evident that a company’s employees had all left.
ERP data storage
An established provider was losing market share; I assessed how quickly legacy customers could exit, and the cost to modernize.
Weather forecasting
A precision-farming company used proprietary microclimate analysis. I assessed the market opportunity and the cost of extending its service beyond its home region.
Development Tools
When a startup’s answers were suspiciously good, I discovered the CTO had been asking an AI instead of answering honestly.
Understanding by Inference
A Focused Memo does not always require direct access to a company’s systems. I can learn a great deal from version control statistics without seeing the repository, and assess the health of a development team from issue-tracker history without reading every ticket.
I ask for specific queries that reveal how contributions are distributed, where knowledge is concentrated, and how much effort goes into sustaining existing software rather than adding new capabilities. Patterns in pull-request approvals and review comments help establish whether code review is substantive or ceremonial.
For a Full Report, I normally review code directly. For a Focused Memo, carefully chosen queries can reveal the company’s challenges and trajectory while limiting the access required and the demands on busy engineers.
When the findings are ready
A Focused Memo typically takes three to five days. It addresses the immediate investment questions and identifies findings that may warrant further investigation or affect valuation.
A Full Report usually requires two to three weeks. It includes a broader examination of the technology, engineering organization, and cost structure.
Timelines assume prompt responses from the target company.