Consulting / Technical due diligence

Technical due diligence

You are about to buy, fund or partner with a technology company. Our certified auditors combine governance knowledge with deep technical skill and hands-on experience, and assess the target against a well-designed methodology: how the technology is built, what it costs to run, who can maintain it, what the licence and security exposure is — and what it would take to fix. Impartial, in plain language, on a deadline, so you can make the best decision.

What you receive
  • Architecture, code-quality and scalability assessment with evidence
  • Infrastructure and run-cost review (cloud bills, single points of failure)
  • Security posture: vulnerabilities, secrets handling, compliance gaps
  • Team and key-person risk, licence and open-source exposure
  • Red-flag list, remediation cost estimate and a negotiation-ready summary
Typical triggers
  • A term sheet is signed and the exclusivity clock is running
  • You are buying a company whose product is the software
  • A portfolio company is raising and the lead wants an independent view
  • You need a second opinion on a vendor proposal or a large ICT investment
How an engagement runs
  1. 1
    Data room & interviewsRepository access, architecture walkthroughs, CTO and lead-engineer interviews
    2–3 d
  2. 2
    AssessmentCode, infrastructure, security and process review against a fixed checklist
    3–5 d
  3. 3
    ReportFindings graded by deal impact; cost to fix; open questions
    2 d
  4. 4
    Deal supportAvailable for calls with the target and your lawyers
    as needed
Consulting

Other consulting services

Security auditing
ISO 27001 · ISO 22301 · DORA · pentest

Audits and certification readiness for ISO/IEC 27001, ISO 9001 and ISO 22301, DORA compliance for financial entities, penetration testing — and the technical submissions your regulator or the National Bank of Slovakia asks for.

Read more →

Risk and impact assessments

Risk and business-impact analyses by experts certified by the Slovak National Security Authority (NBÚ) and ISACA (CRISC) — using ISO/IEC 27005, ISO 31000 and Cybersecurity Act methodologies, with controls your team can realistically run.

Read more →

AWS configuration & scaling

Well-Architected reviews, IAM and network hardening, cost cuts and autoscaling designs from an AWS Partner who runs business-critical applications on it every day. The applications we work on grow to tens of terabytes — with response times and costs kept under control.

Read more →
Contact

A consultation with one of our engineers

Tell us what you are dealing with. Within two working days you get a concrete proposal with scope and price.

  • Reply from a senior engineer or lead auditor, not an account manager
  • Fixed scope and price before any work starts
  • ISO 9001 and ISO 27001 certified processes, NDA on request