Before the term sheet
You've seen the pitch and the metrics. Has anyone senior actually read the code that produces them? A short review now is cheaper than a surprise after close.
For investors & acquirers
Independent technical due diligence on software companies. I assess the codebase, the team and the real risk — then give you a report you can put in front of an investment committee, in language everyone in the room understands.
Independent — no stake in the deal · NDA before anything else · Senior engineer, start to finish
You've seen the pitch and the metrics. Has anyone senior actually read the code that produces them? A short review now is cheaper than a surprise after close.
The data room says one thing; the repository says what's true. I verify that the product, the tech debt and the team match what's being sold.
A company you've already backed is missing deadlines or burning through engineers. I find out whether it's the code, the team, or the plan.
The roadmap promises 10× scale. I tell you whether this codebase can deliver it — and what it will cost if it can't.
Every engagement covers the areas below, weighted to your deal. You get a rating and a plain-English finding for each — no jargon without a translation.
Is the system built to do what the company claims — and what breaks first at 10× the load?
What's slowing the team down, what's about to break, and what it will cost to fix.
Authentication, injection surfaces, secret handling, and how customer data is actually protected.
Who really wrote this? Commit history doesn't lie about bus factor.
How safely and how often can this team ship? The pipeline tells the truth.
What it costs to run per customer today, and at the scale in the deck.
Open-source obligations, contributor IP, and anything that compromises what you're buying.
Whether the plan being sold is one this codebase and this team can deliver.
Findings by area, each with a Low / Moderate / Elevated rating and a plain-English explanation. Technical appendix for your engineers; executive summary for everyone else.
Every material risk, rated and prioritised, with remediation effort estimated in sprints — so you know what's a deal point and what's a post-close fix.
Which items belong in the term sheet (retention, escrow, warranties), which belong in a 90-day plan, and which you can safely ignore.
A call to walk your team through it, and two weeks of follow-up questions included. Reports can be shared with co-investors and LPs under your NDA terms.
Deals don't wait, and neither does this. A typical engagement runs five to ten working days from access to debrief — scoped to what your timeline allows.
Day 0. Free, no obligation. You tell me about the deal, the company and your timeline; I tell you exactly what I can assess in it, at a fixed price.
Days 1–2. NDA signed (yours or mine), then read-only access to repositories, CI and infrastructure — arranged with the target so their team barely notices.
Days 3–8. I read the code, the history, the pipelines and the infrastructure. You get a mid-point flag if I find anything that should change your negotiating position immediately.
By day 10. Written report delivered, walked through on a call, with a two-week window for follow-up questions.
Need it faster? Compressed reviews for tight exclusivity windows are possible — say so on the scoping call.
To show exactly what you'd receive, I ran the full methodology on a real, publicly available codebase: Umami, an open-source web analytics platform with a commercial company behind it — 58,000 lines of TypeScript, a real product, real findings. Prepared from public code only; client engagements go much deeper.
| Area | Rating | Headline |
|---|---|---|
| Architecture | Low risk | Clean monolith with a credible scaling path. |
| Code quality & testing | Low risk | TypeScript throughout, unit + e2e suites. |
| Security | Moderate | Weak secret default and legacy tokens need fixing. |
| Delivery & CI/CD | Moderate | E2E tests and dependency scanning not gated. |
| Team & key-person | Elevated | ~70% of all commits from one founder. |
| Licensing & IP | Low risk | MIT core; open-core boundary to verify. |
Overall: Moderate risk — investable, with conditions.
Specimen prepared from public source code (v3.2.0, August 2026) to demonstrate structure and depth. Not investment advice; findings may since have been addressed by the maintainers.
I'm not the seller's agency, the buyer's banker, or anyone's reseller. I don't take success fees. You get the same report whether the answer helps the deal or kills it.
Nothing starts before confidentiality is signed — yours or mine. Access is read-only, scoped, and revoked the day the engagement ends. Reports are shareable with your co-investors and LPs under your NDA terms.
No juniors, no offshoring, no hand-offs. The person who scopes the work, reads the code and writes the report is the same person — me.
I'm George Brooks — a senior full-stack and product engineer based in Oxford. I've spent 15+ years building and scaling software: platforms grown past 10,000 customers, and complex, data-heavy applications used in demanding, high-stakes environments. I've sat on the building side of "can this codebase deliver the roadmap?" more times than I can count — which is precisely the question your diligence needs answered.
Diligence by committee dilutes judgement. A big-firm review is assembled by juniors and signed by a partner who never opened the repository. Here, one senior pair of eyes sees everything — the code, the history, the pipelines — and one accountable person tells you what it means. For engagements that genuinely need a second specialist (deep pen-testing, for instance), I'll say so and bring one in under the same NDA.
Fixed price, quoted after the scoping call, based on codebase size and how deep your timeline lets me go. Typical engagements are priced comparably to a few hours of your lawyers' time — and answer questions the lawyers can't.
I keep capacity for deal-driven work: starting within days is usually possible, and most engagements complete in 5–10 working days. If you're inside a tight exclusivity window, say so — compressed reviews are possible with narrowed scope.
Yes. Reports are written to be read by non-technical decision-makers and can be shared under your NDA terms. Many clients circulate the executive summary to the committee and keep the technical appendix for their own engineers.
For a full review, yes — read-only repository and infrastructure access, arranged so it's low-friction for their team. Where cooperation isn't possible yet (pre-term-sheet), I can do a limited outside-in review of public code, deployed artefacts and team signals, clearly labelled as such.
The team (authorship concentration, bus factor, review culture — the commit history is remarkably honest), the delivery pipeline, the infrastructure and its costs, licensing and IP hygiene, and whether the roadmap being sold is deliverable by this codebase and team.
Completely. No success fees, no ongoing relationship with the target, no reselling. If the code is good, the report says so; if it isn't, the report says that too.
That happens. Outside-in reviews use only public material and require no contact with the company. Tell me the constraints on the scoping call and I'll design the scope around them.
A sentence is enough — stage, rough timeline, and what's worrying you. Everything you send is treated as confidential from the first message, NDA or not. I'll reply the same working day.