GLOSSARY

What Is Technical Due Diligence?

Technical due diligence is the assessment of a software asset before an acquisition, investment or major engagement — evaluating code quality, architecture, security, dependencies and key-person risk to understand what a buyer is actually acquiring.

Who does it and what it covers

Acquirers, private-equity and venture investors, and agencies taking over a client system. It covers the state of the code, the architecture and its scalability, security exposure, third-party and licence dependencies, and how much of the knowledge sits with one or two people.

Done well, it is grounded in the repository itself rather than in a founder's description of it — the two often differ.

What the output is used for

Adjusting the price, quantifying integration and remediation cost, and deciding what has to be true before or shortly after a deal closes.

Common questions

What is technical due diligence?

It is the pre-deal assessment of a software asset — code quality, architecture, security, dependencies and key-person risk — to establish what a buyer or investor is actually acquiring.

What is checked in a software code audit for an acquisition?

Code quality and maintainability, architecture and scalability, security exposure, third-party and licence dependencies, test coverage, and how concentrated the critical knowledge is among the team.

How long does technical due diligence take?

It varies with deal size and codebase complexity, from a few days to several weeks. Automated analysis of the repository shortens the discovery phase considerably.

Related

  • Shareable reportsShare a live, public snapshot of a repository's dead code, health score and key-person risk with a single link and no login. Use it to brief a stakeholder, walk a tech audit, or hand off context to a new lead.
  • Codebase health scoreTrack codebase health as one number from 0 to 100, deducted across six measured dimensions: dead code, zombie code, file size, test coverage, secrets exposure and duplication. Every deduction is capped and shown.
  • Bus factor & key person riskKnow what you lose before someone quits. Mapnostics reads your git history to show who really owns each part of your codebase, and exactly what knowledge walks out the door if they leave.
  • Technical due diligence, grounded in the code
  • Bus factor / key-person risk — glossary
  • Codebase health score — glossary

See it in your own codebase.

Analyze my codebase →

No credit card required · Free tier available