Technical due diligence
Before you sign, you want to know what you are actually buying: the state of the code and infrastructure, the security and licensing liabilities it carries, how dependent the product is on a handful of people and what it will cost to get it where the seller says it is.
What you get
- Assessment of architecture, code, infrastructure and operational practices
- Security overview: vulnerabilities, incidents, regulatory compliance, open liabilities
- Licensing and open-source risks, vendor and key-person dependencies
- Technical-debt estimate and the cost of paying it down; risks ranked by impact on the deal
- Report for the investment committee and a list of conditions for the agreement
When to get in touch
- You are buying or funding a technology company
- You are taking over a product or team from a vendor
- You want an independent view of your own platform before a sale or funding round
How it works
- 01
Request list
What we need to see, who to talk to, the deal timeline
Duration: 1 d - 02
Assessment
Data room, interviews, code and infrastructure review
Duration: 3–8 d - 03
Report
Findings, risk valuation and recommendations for negotiation
Duration: 2 d
Other services
All services →Audit and regulatory readiness
Gap analysis, internal audit and certification readiness for ISO/IEC 27001 and ISO 22301, audits under NIS2 and the Czech Cybersecurity Act, DORA compliance assessment — including preparation of the documentation the regulation requires.
Read more →AWS audit
A review of your AWS environment against the AWS Well-Architected Framework and security benchmarks: identity and access, network, encryption, logging, backups, resilience and cost — with a prioritised remediation plan.
Read more →Risk assessment
Information-security risk analysis, business-impact analysis (BIA) and vendor risk assessment under ISO/IEC 27005 and the requirements of NIS2 and DORA — with a register you can actually maintain.
Read more →Thirty minutes that save you months
Tell me what you are dealing with — an audit before certification, a letter from the regulator, a customer requirement, or just not knowing where you stand. Within two working days you get a concrete proposal with scope and price.
- You talk directly to the auditor who does the work
- Fixed scope and price before anything starts
- NDA on request, deliverables in Czech or English