Skip to content

Due Diligence

Use this workflow for pre-acquisition technical assessment, partnership evaluation, investment memos, or vendor/platform selection.

Pre-Investigation

  1. Define the deal thesis.
  2. Confirm the memo timeline.
  3. Clarify access boundaries.
  4. Name the business-side concerns.

Investigation Phases

PhaseFocusEvidence
Surface assessmentPublic activity, docs, tests, security posture, technical writing.Public repo signals, docs, advisories, recent activity.
Deep code reviewArchitecture, data flow, auth, integrations, infrastructure, quality.Code paths, dependency state, CI/CD, tests, ownership.
Risk assessmentImpact, mitigation, confidence, integration cost.Findings table with observed vs reported facts.

Checklist

  • Confirm code or architecture-doc access.
  • Assess dependencies and security posture.
  • Review auth and data handling.
  • Estimate scalability and integration complexity.
  • Identify team structure and bus factor.
  • Quantify technical debt where possible.
  • Produce a go/no-go recommendation with top risks.

Memo Shape

  1. Executive summary.
  2. Technical overview.
  3. Strengths.
  4. Risks and concerns.
  5. Integration estimate.
  6. Recommendations.

CDP operating memory.