Technical Due Diligence

$4,500 fixed

About two weeks from code access

You are acquiring a software company or a software asset and the codebase is most of what you are paying for. Before you close, an engineer who is not the seller should read it. I assess the code, the infrastructure, and the delivery process, and tell you plainly what you are buying, what it will cost to keep running, and where the risks are.

What you get

  • Written report: architecture, code quality, and maintainability, in plain language for the deal team
  • Security posture review, including secrets handling, auth, and exposed surface
  • Dependency and license audit, flagging anything that constrains a sale or relicense
  • Build, test, and deployment reality check: can a new team actually ship this?
  • Key-person risk: how much of the system lives only in the founder's head
  • Findings ranked by severity, each with an estimated cost to remediate
  • One follow-up call with your deal team to walk through the report

Fits acquisitions, acqui-hires, and investments where the software is a material part of the price. Codebases of any mainstream stack; scope confirmed before you pay anything.

Email me Sample report (soon)

Overnight Audit

$149 / $249

Report within 24 hours of repo access

A fast, honest read of one codebase, back in your inbox within 24 hours. An agent fleet runs the mechanical passes; a human engineer verifies every finding before it ships. $149 audits one repository. $249 is the App Store Rescue tier: everything in the audit, plus a decode of your App Review rejection and a resubmission plan.

What you get

  • Fresh-clone build and test run, reported honestly
  • Dependency and supply-chain scan with the exact advisory IDs
  • Secrets and config sweep (type and location only, never the value)
  • Severity-ranked findings with file-and-line evidence
  • A sequenced 30-day fix plan plus quick wins
  • Two full sample reports on public code you can read first

Fits a single repository. Read-only access to a private repo (or a tarball) is all it needs; the code never leaves my machines.

Process

How it works

  1. Email me the context What the code is, why you need it read, and your deadline. A repo link helps but is not required to start the conversation.
  2. Scope and price confirmed up front I confirm fit and the fixed price in writing before any payment. If the engagement is not a fit, I say so and point you somewhere better.
  3. You get the report A written report you can act on and share, delivered on the stated turnaround, plus the follow-up call where the offer includes one.

Questions first? Email [email protected] and I will answer them straight, including "this is not worth paying for."