Software Due Diligence
at its best

We inspect what lies beneath the surface. And translate it into a decision that holds.
Software due diligence is the independent technical inspection for business-critical software. Buyers do not just acquire source code. They inherit architectural decisions, technical debt, security risks and years of future development costs. From the outside it is almost impossible to tell whether the software is genuinely robust or simply works in a controlled demo. We examine code, architecture, documentation and development processes. Our findings are translated into a clear basis for decisions that management and investors can act on.
Technical clarity before the acquisition decision.
Whether acquisition, investment or the takeover of an existing codebase. We put the software on the ramp and show what is really under the bonnet. You will learn which risks you are buying, which costs are coming your way over the next few years and whether purchase price and technical condition actually match. Presented clearly for management, investors and technical teams.
From code analysis to a decision paper for management and investors.
Code & architecture
We examine what the software is actually built on:
- Code quality: structure, readability, duplication, complexity and test coverage. We measure rather than estimate and place the results in an industry context.
- Architecture assessment: Modularity, coupling, scalability. We assess whether the architecture supports the planned roadmap or whether a rebuild is coming.
- Technology stack: How current are the frameworks, languages and runtimes in use? Outdated components are predictable costs, provided you know about them.
Technical debt & future costs
We make visible what the software will cost over the coming years:
- Assessment: Where were shortcuts taken deliberately and where by accident? We distinguish between a calculated compromise and a genuine risk.
- Effort estimate: We quantify the remediation effort in person-days, which makes it negotiable.
- Capacity for further development: How quickly can new features be added? We assess whether the roadmap is technically realistic at all.
Security & dependencies
We examine which risks come with the deal:
- Vulnerability analysis: Known security gaps in the code and in the libraries it depends on.
- Open-source licences: Which licences are in use and what obligations do they create? Copyleft components can block entire business models.
- Third-party dependencies: Critical libraries without active maintenance, single points of failure, vendor lock-in.
Documentation & development processes
We assess whether the team can deliver, not just the code:
- Documentation maturity: Is the software maintainable without the original developers? The bus factor determines its value after the handover.
- CI/CD and test automation: How reliably does a change reach production? We review build pipelines, test coverage and release frequency.
- Process maturity: Requirements management, code reviews, defect handling. Processes say more about the future than the current state of the code.
Assessment & basis for decisions
We translate technical findings into a decision.
- Risk assessment: All findings prioritised by impact and likelihood. Not a list of defects, but a ranking.
- Cost-benefit context: Do purchase price, technical condition and future viability match? We provide the basis for the price negotiation.
- Management summary: Clear for executives and investors. Without the jargon, but without losing substance.
Our approach:
Clarity in four steps.
01 Scoping (1 day): We define scope, access and the question at hand. What exactly needs to be assessed and what will the result be used for?
02 Analysis (5 to 10 days): Static code analysis, architecture review, interviews with the development team, review of documentation and processes.
03 Assessment: We prioritise the findings by risk and cost impact and place them in the context of the deal.
04 Debriefing: A presentation for management and investors, plus the full technical report for your technical team.

Anyone buying software is buying yesterday's decisions.


