Transactions · Technical Due Diligence
Before you buy the company, verify the system underneath it.
Independent technical and cybersecurity due diligence for private equity, strategic acquirers, investment committees, and boards. The engagement tests technical reality against the investment thesis. The product is not a security report. It is independent evidence relevant to the decision to buy.
01 · The Questions
The questions the data room won't answer.
The seller wants the best valuation. Management believes its story. The deal team wants to execute. None of that implies bad faith. It means the buyer still benefits from one party with no stake in the outcome asking what is actually true. Before capital moves, I answer:
Has the environment already been compromised?
What material security exposure transfers at close, and what does it cost to retire?
Does the architecture actually support management's growth assumptions?
What technical debt becomes the buyer's problem on day one?
What does the company actually own, versus license or depend on?
Are the cost assumptions credible, or is the model carrying infrastructure the business does not need?
Where is key-person dependency dangerous?
What must be fixed before close, and what can wait until the first 30, 90, or 180 days?
What would have to be true for the investment thesis to hold, and which assumptions are doing the most work?
02 · AI Claims
When AI is material to the thesis.
Many deals now carry an AI claim: a proprietary platform, a transformation plan, a cost model built on GPUs. When the claim is material to the valuation, it gets the same treatment as everything else. Is the proprietary platform a defensible system, or three APIs and a prompt? Where did the training data come from, and what rights actually exist? Do the infrastructure economics survive contact with real workloads? What happens when the key ML engineer leaves, or the model vendor changes terms?
I build and secure this class of system in my own operating work. The claims get tested against how these systems actually behave, not against the vendor's demo.
03 · Deliverables
Written for the investment committee.
Investment Committee Memo. The independent conclusion, written for the room where the decision is made.
Technical Findings. The evidence behind every conclusion.
Management Questions. What to ask the team before you wire, and what a good answer sounds like.
Scoped to the transaction · expedited timelines available
I did acquisition-related security testing and technical examination at NCC Group before doing this work independently. Employers are not clients, and confidential matters stay confidential.
04 · For Sponsors
One methodology across the portfolio.
For firms that face these questions repeatedly, a standing program replaces one-off diligence: a baseline across portfolio companies, periodic reviews, a diligence allocation for live deals, and portfolio-level risk reporting to the partnership. Structured to the fund.