Technology Due Diligence
An independent review of software, architecture, team, security, scalability and technical debt before an investment or transaction decision.
Digital IP and provenance
A software provenance review tests whether the company can demonstrate ownership of the code it runs in production, by examining contributor records, agreements, licence obligations and commit history.
Who owns the production source code?
Do contractor and former-employee contributions have executed IP assignments?
Do open-source licence obligations affect the product or the transaction?
Is there a clean chain of title from each contributor to the company?
Do third-party dependencies carry terms that restrict use or distribution?
We request the evidence needed to test the technical position. The exact list depends on the matter.
We agree the code, components and time period in scope, and the specific ownership and licence questions the review must answer.
We collect repository history, contributor records, agreements, assignment documents and dependency manifests, and record how each was obtained.
We match contributions to contributors, check each contributor against an executed agreement or assignment, and assess the obligations attached to open-source and third-party components.
We classify each finding by risk and by confidence, and state the evidence that supports it and the evidence that was missing.
We set out the practical steps to close each gap, such as obtaining an executed assignment or addressing a licence obligation before completion.
Typically 2 to 3 weeks, depending on repository size and how complete the contributor records are
The review covers the full agreed scope; it is bounded by the evidence made available and does not warrant that every ownership gap will be found. Where the matter needs more, the engagement can extend to include:
Definition
We act as an independent reviewer. We do not write the code we assess, and we do not remediate the gaps we identify, so our findings carry no incentive to understate or overstate the position.
We record the evidence behind each finding and mark the confidence in it, so counsel and the board can judge the basis for every conclusion and where the evidence was incomplete.
The report is prepared for the party that instructs us. We state any conflict before accepting the engagement and confirm the reliance position in the engagement terms.
An independent review of software, architecture, team, security, scalability and technical debt before an investment or transaction decision.
A fixed-scope technical triage that establishes the facts and the next step when a matter needs an early, defensible technical view.
How we scope a review, preserve evidence, and classify each finding by risk and confidence.
How we manage conflicts, reliance and the separation between reviewing work and remediating it.
Provide a short outline of the decision, transaction or dispute. Do not submit confidential source code, credentials or personal information through the form.