Undisclosed data breaches surfaced during late-stage diligence, after the price had been agreed rather than before.
Verizon / Yahoo · 2017
Institutional-grade software intelligence, from acquisition to exit.
01What goes unpriced
Every software deal is priced on a codebase nobody read.
Undisclosed data breaches surfaced during late-stage diligence, after the price had been agreed rather than before.
Verizon / Yahoo · 2017
A platform acquisition where the target's ERP could not integrate. Found after signing, so it could not be negotiated into the price.
RSM case file
Software transactions are re-traded on 30–40% of deals, once the buyer surfaces code, security or licensing exposure during diligence.
PitchBook · aggregate
None of these were hidden. They were simply never looked for. Technical diligence costs $40K–$300K and takes weeks, so it runs on the deal you have already decided to do, if it runs at all.
02Isolation architecture
The target initiates the assessment, authorises the environment directly, and receives a signed record of everything that happened inside it. Our inability to reach the source is enforced by the architecture, not asserted by policy.
The analysis engine is built, signed and locked to one verified version before anything starts. It runs on hardware that encrypts its own memory while the work happens, so neither the cloud provider nor Exira can read what is inside it. The target confirms the environment is running that approved version before releasing anything to it.
The target authorises the environment directly. The key covers only the repositories it selects, and its private half is created inside the environment and can never be copied out, so it is cryptographically bound to that single run and worthless anywhere else. Exira is never a party to it. It lapses when the checkout finishes, and the target can withdraw it sooner.
The repository is pulled over an encrypted connection straight from the target's own provider into storage that exists only for that run. Nothing routes through Exira. Analysis happens where the code already sits: inside the environment it is processed as data rather than run, and nothing the repository asserts can change how that analysis behaves.
Findings leave as a structured register, validated against a published schema. Evidence travels as file paths, line ranges and content hashes, so the report points at code without ever containing any. The environment and its keys are then destroyed, and the target receives a signed, tamper-evident audit record: what was authorised, what ran, what left, and when it was torn down.
03Coverage
Each module reads one dimension of the codebase. The findings that move deals are the ones that only surface when the modules are read against each other, so every assessment reconciles them before it reports.
Where authorship concentrates, who has already left, and which systems still depend on them.
Dependency exposure, patch latency, secret handling, and which controls the pipeline actually enforces.
Service boundaries, data flow, and what the architecture does at the next order of magnitude.
Throughput, review discipline and test practice, read from repository history rather than claimed.
Which obligations are enforced in code, which are asserted on paper, and what needs verifying out of band.
Every dependency licence, how it combines with the product's own distribution, and what survives the transaction.
Runtime, framework and platform versions against their support horizons, and the upgrades already overdue.
Whether AI capability is built in or bolted on: provider dependence, evaluation discipline, data foundations.
The surface the product exposes and consumes, and the real cost of integrating it with an acquirer.
The architectural decisions that drive infrastructure spend, and whether cost control exists in code.
Deferred work carried in the codebase, converted into remediation effort in engineering months.
Models fine-tuned on completed assessments and the deal outcomes that followed. Every conclusion then clears an independent critic.
04The deliverable
Every finding carries a disposition, a remediation estimate in engineering months, and a traceable evidence reference.
Findings register
Material risk · cross-module
The event streaming backbone, the caching and job-queue layer, and the data access layer for user identity are simultaneously mid-migration. Each is individually justified and each is executed responsibly, with dual-write patterns that keep old and new systems in sync. The risk is not the migrations but their concurrent, in-flight state: three simultaneous transitions introduce operational complexity and a window of exposure to data inconsistency until each is closed out.
05Where it fits
At this cost and turnaround, technical diligence stops being something you commission once and becomes a screen, then a monitor, then a defence.
Run it on targets you would never resource a full engagement for. Firms doing this aren't just faster; they see more of the market.
Architecture, security, licensing and remediation cost in engineering months, while there is still a number to move.
Scheduled re-runs track debt accumulation, security drift and technical covenant signals months before they reach revenue.
The same assessment, read from the other side: what a buyer's diligence would surface, while remediation is still a sprint.
Book demo
A thirty-minute session — we walk through a complete assessment module by module, then apply it to a target in your pipeline.