For investors & acquirers

Know what you're buying, before you commit.

Independent technical due diligence on software companies. I assess the codebase, the team and the real risk — then give you a report you can put in front of an investment committee, in language everyone in the room understands.

Independent — no stake in the deal  ·  NDA before anything else  ·  Senior engineer, start to finish

15+ yrsbuilding & shipping software
10,000+customers scaled on platforms I've built
5–10 daystypical engagement, matched to deal timelines
1 pair of eyesthe person you brief is the person who reviews the code
When this matters

Four moments where a technical view changes the deal

Before the term sheet

You've seen the pitch and the metrics. Has anyone senior actually read the code that produces them? A short review now is cheaper than a surprise after close.

seed · Series A · angel syndicates

Before an acquisition

The data room says one thing; the repository says what's true. I verify that the product, the tech debt and the team match what's being sold.

M&A · acqui-hire · corporate development

Portfolio health check

A company you've already backed is missing deadlines or burning through engineers. I find out whether it's the code, the team, or the plan.

post-investment · board request

Before a follow-on round

The roadmap promises 10× scale. I tell you whether this codebase can deliver it — and what it will cost if it can't.

Series B+ · growth equity
Scope

Eight areas, one clear picture

Every engagement covers the areas below, weighted to your deal. You get a rating and a plain-English finding for each — no jargon without a translation.

Architecture

Is the system built to do what the company claims — and what breaks first at 10× the load?

architecture · data model · scaling path

Code quality & tech debt

What's slowing the team down, what's about to break, and what it will cost to fix.

readability · testing · debt inventory

Security

Authentication, injection surfaces, secret handling, and how customer data is actually protected.

authN/authZ · secrets · OWASP

Team & key-person risk

Who really wrote this? Commit history doesn't lie about bus factor.

authorship · bus factor · hiring needs

Delivery & CI/CD

How safely and how often can this team ship? The pipeline tells the truth.

pipelines · release cadence · rollback

Infrastructure & cost

What it costs to run per customer today, and at the scale in the deck.

cloud spend · unit economics · vendor lock-in

Licensing & IP

Open-source obligations, contributor IP, and anything that compromises what you're buying.

licences · SBOM · IP assignment

Roadmap credibility

Whether the plan being sold is one this codebase and this team can deliver.

feasibility · timeline risk · dependencies
Deliverables

A report the whole room can read

01

Written report

Findings by area, each with a Low / Moderate / Elevated rating and a plain-English explanation. Technical appendix for your engineers; executive summary for everyone else.

02

Risk register & red flags

Every material risk, rated and prioritised, with remediation effort estimated in sprints — so you know what's a deal point and what's a post-close fix.

03

Recommendations mapped to the deal

Which items belong in the term sheet (retention, escrow, warranties), which belong in a 90-day plan, and which you can safely ignore.

04

Verbal debrief + question window

A call to walk your team through it, and two weeks of follow-up questions included. Reports can be shared with co-investors and LPs under your NDA terms.

How it works

Built for deal timelines

Deals don't wait, and neither does this. A typical engagement runs five to ten working days from access to debrief — scoped to what your timeline allows.

01

Scoping call

Day 0. Free, no obligation. You tell me about the deal, the company and your timeline; I tell you exactly what I can assess in it, at a fixed price.

02

NDA & access

Days 1–2. NDA signed (yours or mine), then read-only access to repositories, CI and infrastructure — arranged with the target so their team barely notices.

03

The review

Days 3–8. I read the code, the history, the pipelines and the infrastructure. You get a mid-point flag if I find anything that should change your negotiating position immediately.

04

Report & debrief

By day 10. Written report delivered, walked through on a call, with a two-week window for follow-up questions.

Need it faster? Compressed reviews for tight exclusivity windows are possible — say so on the scoping call.

See the real thing

Don't take my word for it — read a report

To show exactly what you'd receive, I ran the full methodology on a real, publicly available codebase: Umami, an open-source web analytics platform with a commercial company behind it — 58,000 lines of TypeScript, a real product, real findings. Prepared from public code only; client engagements go much deeper.

Cover of the sample technical due diligence report on Umami
Sample report · 6 pages · PDF
AreaRatingHeadline
Architecture Low risk Clean monolith with a credible scaling path.
Code quality & testing Low risk TypeScript throughout, unit + e2e suites.
Security Moderate Weak secret default and legacy tokens need fixing.
Delivery & CI/CD Moderate E2E tests and dependency scanning not gated.
Team & key-person Elevated ~70% of all commits from one founder.
Licensing & IP Low risk MIT core; open-core boundary to verify.

Overall: Moderate risk — investable, with conditions.

Specimen prepared from public source code (v3.2.0, August 2026) to demonstrate structure and depth. Not investment advice; findings may since have been addressed by the maintainers.

Independence & confidentiality

Your interests, and only your interests

No stake in the deal

I'm not the seller's agency, the buyer's banker, or anyone's reseller. I don't take success fees. You get the same report whether the answer helps the deal or kills it.

NDA-first, always

Nothing starts before confidentiality is signed — yours or mine. Access is read-only, scoped, and revoked the day the engagement ends. Reports are shareable with your co-investors and LPs under your NDA terms.

Senior all the way down

No juniors, no offshoring, no hand-offs. The person who scopes the work, reads the code and writes the report is the same person — me.

George Brooks
Who's reviewing

One senior engineer is exactly what due diligence needs

I'm George Brooks — a senior full-stack and product engineer based in Oxford. I've spent 15+ years building and scaling software: platforms grown past 10,000 customers, and complex, data-heavy applications used in demanding, high-stakes environments. I've sat on the building side of "can this codebase deliver the roadmap?" more times than I can count — which is precisely the question your diligence needs answered.

Diligence by committee dilutes judgement. A big-firm review is assembled by juniors and signed by a partner who never opened the repository. Here, one senior pair of eyes sees everything — the code, the history, the pipelines — and one accountable person tells you what it means. For engagements that genuinely need a second specialist (deep pen-testing, for instance), I'll say so and bring one in under the same NDA.

— George
Investor-specific questions

Good to know

What does it cost?

Fixed price, quoted after the scoping call, based on codebase size and how deep your timeline lets me go. Typical engagements are priced comparably to a few hours of your lawyers' time — and answer questions the lawyers can't.

How fast can you start, and how fast can you finish?

I keep capacity for deal-driven work: starting within days is usually possible, and most engagements complete in 5–10 working days. If you're inside a tight exclusivity window, say so — compressed reviews are possible with narrowed scope.

Can the report be shared with co-investors, LPs or the board?

Yes. Reports are written to be read by non-technical decision-makers and can be shared under your NDA terms. Many clients circulate the executive summary to the committee and keep the technical appendix for their own engineers.

Do you need the target's cooperation?

For a full review, yes — read-only repository and infrastructure access, arranged so it's low-friction for their team. Where cooperation isn't possible yet (pre-term-sheet), I can do a limited outside-in review of public code, deployed artefacts and team signals, clearly labelled as such.

What do you assess besides the code?

The team (authorship concentration, bus factor, review culture — the commit history is remarkably honest), the delivery pipeline, the infrastructure and its costs, licensing and IP hygiene, and whether the roadmap being sold is deliverable by this codebase and team.

Are you independent?

Completely. No success fees, no ongoing relationship with the target, no reselling. If the code is good, the report says so; if it isn't, the report says that too.

What if the deal is confidential even from the target?

That happens. Outside-in reviews use only public material and require no contact with the company. Tell me the constraints on the scoping call and I'll design the scope around them.

Start here

Tell me about the deal

A sentence is enough — stage, rough timeline, and what's worrying you. Everything you send is treated as confidential from the first message, NDA or not. I'll reply the same working day.

Treated as confidential from the first message. Submissions go to a private Google Form I check daily.

Thanks

I'll be in touch the same working day.