Methodology
AI reads everything. I decide what matters.
Here is how a diligence actually runs: what the agents do, what I do, and why the two together beat either one on its own.
The engagement
Five business days, day by day.
Day 1: Scope & setup
A 60 to 90 minute call with the company’s leadership. I get read-only access to the repos, infrastructure and product docs, and point the agents at the actual stack.
Day 2: Read the technology
Agents go through the whole codebase: code quality, security, architecture, dependencies, infrastructure. That’s thousands of data points, every repo and not just a sample, ranked by how much they matter.
Day 3: Read the product
I go through the product and commercial side: the materials, the usage and cohort data, and short interviews with the product, engineering and commercial leads to get the context documents never capture.
Day 4: Judgement
This is the part that counts. I go through every finding by hand, decide what actually matters at this stage, and write it up: what it is, why it matters, and what to do about it.
Day 5: Delivery
You get the full report and a 60-minute walkthrough of every finding, its business impact, and a fix-it plan. For investors, a short summary written for the investment committee.
What I assess
Every engagement, two frameworks.
A diligence is far more than a code review. I assess fourteen areas across two frameworks, technology and product, and rank every finding red, amber or green by what it means for the deal.
The technology framework. A conditional AI/ML layer applies when the product is built on AI or machine learning.
Code, Architecture & Technical Debt
Code quality, system design, scalability and technical debt. Whether it is sound, and holds up as the company grows.
Infrastructure & Delivery
Cloud, infrastructure as code, environments, and how code reaches production. Whether the foundations are solid and releases are safe.
Security & Data Protection
Authentication, secrets, vulnerabilities and how sensitive data is handled. Where the company is exposed, and whether it is compliant.
Reliability & Business Continuity
Monitoring, incident response, backups and disaster recovery. Whether the business survives when something breaks.
Engineering Practice & Team
How the team builds, tests and documents, and who holds the critical knowledge. Whether it can deliver the roadmap.
Dependencies, IP & Compliance
Third-party services, open-source licences, code ownership and certifications. Whether the company owns what it sells.
Product, Roadmap & Economics
Roadmap realism and the unit economics of the technology. Whether the build still matches the revenue story.
Full Suite: the two, connected
The point of one operator running both is that the findings read each other. I translate technical findings into commercial consequences, and test the product strategy back against what the technology can actually do, across four lenses. The connection runs both ways, and a gap in either direction is a finding.
Cost
Tech to product. Infrastructure cost and cost-to-serve set gross margin and the pricing floor.
Product to tech. The pricing the product wants sets the cost the architecture has to hit.
Capability
Tech to product. Architecture and the data model decide what you can package, tier and scale to.
Product to tech. The target customer sets the architectural bar the technology has to clear.
Speed
Tech to product. Release cadence sets how fast the product can learn its way to fit.
Product to tech. A product built on iteration demands the delivery tooling to support it.
Ownership
Tech to product. What is owned, depended on or licensed decides whether the moat is real.
Product to tech. The moat the product claims sets what must be built and owned in-house.
The honest answer
What the AI actually does.
Agents read the code, the infrastructure and the docs faster and more completely than any human team could. They flag patterns, surface anomalies, and point at what looks like risk. That part is real, and it’s most of the grunt work.
But AI doesn’t know which of those findings matter to your business, which decisions are reasonable for your stage, or how to write a recommendation you can actually act on. That’s my job. I read every flag, throw out the noise, and when something needs a human to verify it, I say so and I check. The judgement is the point, not the scan.
Speed
Five days, not five weeks. Nobody in the middle of a deal has five weeks.
Coverage
Every line of code, not a sample. The agents don’t skim and they don’t get tired.
Cost
A fraction of what the Big Four charge, without the forty-page deck that says nothing.
Judgement
The findings come from someone who still ships production software, not someone who only reviews it.
Want to see the methodology in practice?
Download a full sample report. It has the same structure, depth, and format as a real engagement.