The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
Technical due diligence gives buyers, investors and their advisors independent evidence about a target's software: whether it is maintainable, what risks could affect future investment and where additional expenditure is likely after completion.
Synthetic example. Your audit is scoped to your question.
Technical due diligence is an independent assessment of a target company's software and engineering capability, carried out before an acquisition or investment completes. It informs commercial negotiations, warranties and post-deal planning. It does not value the business; that remains with your financial advisors.
It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.
The software is part of what you are paying for, and you need to know its condition before completion.
Private equity, venture or angel investors validating that the platform matches the pitch.
Buying a product line, a customer platform or a codebase as an asset.
Understanding the engineering work needed to integrate, scale or separate systems after completion.
Whether the platform can support the growth assumptions in the investment case.
Material debt that will need investment, separated from acceptable compromises.
Security controls and practices, and where personal data handling needs attention as the business changes hands.
Unsupported frameworks, third-party components and licences that could create cost or risk.
How much depends on a few individuals, and how knowledge is shared and recorded.
Repositories, cloud accounts and operational access the business actually controls.
Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.
Architecture documents, data-room material and management presentations reviewed first.
Sessions with the target's technical leadership to test claims and understand context.
Deeper assessment of repositories and cloud configuration as the seller allows access.
Material risks, open questions and their likely operational implications, in time for your decision.
See how findings are presented in our anonymised sample report.
| Area | Supporting authority | How it shapes the audit |
|---|---|---|
| Data protection during mergers and acquisitions | Data sharing code of practice: due diligence following mergers and acquisitionsUK Information Commissioner's Office | Identifies where personal data, its lawful basis and its security arrangements need attention when systems change hands. Legal conclusions remain with your advisors. |
| Secure development practices and software acquisition | Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology | Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software. |
| Application security review and verification | Application Security Verification Standard (ASVS)OWASP Foundation | Frames application security findings as verifiable requirements across authentication, access control, input handling and data protection, rather than a superficial vulnerability scan. |
| Cloud reliability, security, cost and operational maturity | Azure Well-Architected FrameworkMicrosoft | Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency. |
These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.
An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.
We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.
Due-diligence questionsRepository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.
Information securityWorking copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.
Data residencyAssemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.
Visit the Trust CentreWhere personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.
Yes. Scope is agreed against your deadline, and depth is adjusted to the access the seller can provide in the time available. Where time is short, we prioritise the risks most likely to affect the decision.
That is common early in a process. We start with documents, interviews and demonstrations, then go deeper as access is granted. The report states plainly which conclusions are verified and which remain uncertain.
Yes. We provide the technical evidence and explain its likely operational implications, so your advisors can reflect it in valuation, warranties and contract terms. Those decisions remain with them and with you.
Our deepest expertise is .NET and Azure. For targets on other stacks we will tell you honestly whether we are the right reviewer for the code itself, while architecture, operational and control findings remain broadly applicable.
One evidence-based method, applied to the decision in front of you. Each specialist assessment can run on its own or as part of a comprehensive audit.
Pre-acquisition and pre-investment technical due diligence on software businesses and platforms.
Tell us about the transaction, the timetable and what access is likely. We are happy to sign an NDA before receiving any details about the target.
Discuss Your Requirements All Software Audit ServicesCyber Essentials Plus certified · NDA as standard · UK-based team · Microsoft Partner · No obligation to appoint us for remediation