Digital IP & Software Provenance Review
A review of contributor records, agreements, licence obligations and commit history to test whether the company owns the code it uses.
Assurance for transactions and investment
A Technology Due Diligence engagement identifies the material risks in a target's software, architecture, team, security, scalability and technical debt before an investment or transaction decision.
Does the target own the code it ships, and which third-party components does it depend on?
Will the architecture support the expected growth in users, data and transactions?
What is the security posture, and are there known exposures that remain unremediated?
How much technical debt exists, and what investment is required to address it?
Is the business exposed to key-person risk in its engineering team?
We request the evidence needed to test the technical position. The exact list depends on the matter.
We agree the decision the engagement supports and the questions that must be answered, then fix the scope in writing before work starts.
We request access to repositories, cloud accounts, records and metrics, and note what was provided and what was withheld.
We examine the code, architecture, security posture, engineering practice and team structure against the claims made about them.
We classify each finding by materiality and assign a confidence rating based on the evidence reviewed.
We set out the practical next step for each material finding, including its likely effect on price, terms or completion conditions.
Typically 2 to 4 weeks, depending on the size of the codebase and the access provided
The review covers the full agreed scope; it is bounded by the evidence made available and does not warrant that every defect will be found. Where the transaction needs more, the engagement can extend to include:
Definition
Where a technology audit or due diligence already exists, or the findings call for action, our Fractional CTO / CISO advisory carries the work forward: senior technology leadership, direction for onshore and offshore development teams, and the change management to bring a program back on track or restructure the software function.
Advisory work stays separate from the assurance engagement, so the review remains independent of the outcome.
We are engaged for the review only. We do not build, sell or resell the systems we examine, and we do not take commission from vendors named in a finding.
The diligence report is prepared for the party named in the engagement letter. Reliance by any other party is not granted unless we agree it in writing beforehand.
Where we later provide advisory work, we keep it separate from any matter we have assured, so the review remains independent of the outcome.
A review of contributor records, agreements, licence obligations and commit history to test whether the company owns the code it uses.
An assessment of architecture, resilience, security boundaries and whether reported subscription and revenue figures reconcile with the systems.
How we scope an engagement, handle evidence and assign a confidence rating to each finding.
Our engagement terms, conflict checks and reliance position for a diligence report.
Provide a short outline of the decision, transaction or dispute. Do not submit confidential source code, credentials or personal information through the form.