Technical diligencefor private capital

Institutional-grade software intelligence, from acquisition to exit.

00 / 11

01What goes unpriced

Every software deal is priced on a codebase nobody read.

$350M
Off the purchase price

Undisclosed data breaches surfaced during late-stage diligence, after the price had been agreed rather than before.

Verizon / Yahoo · 2017

$30M
Unbudgeted, post-close

A platform acquisition where the target's ERP could not integrate. Found after signing, so it could not be negotiated into the price.

RSM case file

5–25%
Off the agreed price

Software transactions are re-traded on 30–40% of deals, once the buyer surfaces code, security or licensing exposure during diligence.

PitchBook · aggregate

None of these were hidden. They were simply never looked for. Technical diligence costs $40K–$300K and takes weeks, so it runs on the deal you have already decided to do, if it runs at all.

02Isolation architecture

Architecturally unable to see your code.

The target initiates the assessment, authorises the environment directly, and receives a signed record of everything that happened inside it. Our inability to reach the source is enforced by the architecture, not asserted by policy.

01Provable isolation
02Single-use access
03Sealed execution
04Verified teardown
REPOSITORYtarget's providerTARGETauthorises the runSEALED ENVIRONMENTeleven modules · critic passPOLICYthe only openingexirareport only
01 · Provable isolation

Isolation is enforced in hardware, not by policy.

The analysis engine is built, signed and locked to one verified version before anything starts. It runs on hardware that encrypts its own memory while the work happens, so neither the cloud provider nor Exira can read what is inside it. The target confirms the environment is running that approved version before releasing anything to it.

environmentmemory stays encrypted while it runs
versionsigned and locked before the run starts
accessno login, no remote shell, no support route
readable bynot the cloud provider, not Exira
confirmed bythe target, before anything is released
02 · Single-use access

Access is never issued to us.

The target authorises the environment directly. The key covers only the repositories it selects, and its private half is created inside the environment and can never be copied out, so it is cryptographically bound to that single run and worthless anywhere else. Exira is never a party to it. It lapses when the checkout finishes, and the target can withdraw it sooner.

authorised bythe target, straight to the environment
coversonly the repositories the target selects
private halfcreated inside, never copied out
exiranever a party to the credential
withdrawaltarget-side, at any time, without notice
03 · Sealed execution

Source never leaves the environment it lands in.

The repository is pulled over an encrypted connection straight from the target's own provider into storage that exists only for that run. Nothing routes through Exira. Analysis happens where the code already sits: inside the environment it is processed as data rather than run, and nothing the repository asserts can change how that analysis behaves.

transferprovider to environment, encrypted and direct
routingnothing passes through Exira
storageexists only for that run
handlingprocessed as data, never run
retentionnothing kept, model training included
04 · Verified teardown

The report leaves. The environment is destroyed.

Findings leave as a structured register, validated against a published schema. Evidence travels as file paths, line ranges and content hashes, so the report points at code without ever containing any. The environment and its keys are then destroyed, and the target receives a signed, tamper-evident audit record: what was authorised, what ran, what left, and when it was torn down.

leavesthe findings register and report, under NDA
evidencefile paths, line ranges, content hashes
never leavesthe checkout, the key, any working data
destroyedthe environment and its keys, on close
audit recordsigned, tamper-evident, issued to the target

03Coverage

Eleven modules, reconciled against each other.

Each module reads one dimension of the codebase. The findings that move deals are the ones that only surface when the modules are read against each other, so every assessment reconciles them before it reports.

M01

Key-person dependency

Where authorship concentrates, who has already left, and which systems still depend on them.

M02

Security & vulnerability posture

Dependency exposure, patch latency, secret handling, and which controls the pipeline actually enforces.

M03

Scalability & cloud architecture

Service boundaries, data flow, and what the architecture does at the next order of magnitude.

M04

Engineering organisation health

Throughput, review discipline and test practice, read from repository history rather than claimed.

M05

Compliance & regulatory posture

Which obligations are enforced in code, which are asserted on paper, and what needs verifying out of band.

M06

IP & licensing risk

Every dependency licence, how it combines with the product's own distribution, and what survives the transaction.

M07

Technology modernisation risk

Runtime, framework and platform versions against their support horizons, and the upgrades already overdue.

M08

AI & ML readiness

Whether AI capability is built in or bolted on: provider dependence, evaluation discipline, data foundations.

M09

Integration compatibility

The surface the product exposes and consumes, and the real cost of integrating it with an acquirer.

M10

FinOps & cloud cost efficiency

The architectural decisions that drive infrastructure spend, and whether cost control exists in code.

M11

Technical debt

Deferred work carried in the codebase, converted into remediation effort in engineering months.

The engine

Weighted by what moved a price

Models fine-tuned on completed assessments and the deal outcomes that followed. Every conclusion then clears an independent critic.

04The deliverable

What lands in the data room.

Every finding carries a disposition, a remediation estimate in engineering months, and a traceable evidence reference.

Assessment reportJune 2026 · 11 modules
Read
44,499commits
17,942files
552contributors
1.23Mlines
Raised
46findings
3cross-module
2to verify
2deal-blocking

Findings register

F-0131M02
F-0127M06
F-0118M03 × M11
F-0092M02
F-0071M06
F-0064M04
F-0055M11
F-0043M05
F-0031M09
F-0028M07

Material risk · cross-module

F-0118 · M03 SCALABILITY × M11 TECHNICAL DEBT · CROSS-MODULE

Three concurrent infrastructure migrations in flight

The event streaming backbone, the caching and job-queue layer, and the data access layer for user identity are simultaneously mid-migration. Each is individually justified and each is executed responsibly, with dual-write patterns that keep old and new systems in sync. The risk is not the migrations but their concurrent, in-flight state: three simultaneous transitions introduce operational complexity and a window of exposure to data inconsistency until each is closed out.

dispositionclose out or price before signing
remediation1–2 months streaming · 1–2 months cache · 2–3 months identity
evidence3 refs · dual-write helpers, migration config, routing fallback
criticupheld · severity unchanged · no contradictory evidence
Book a demo to walk the full assessment

05Where it fits

One engine, four moments.

At this cost and turnaround, technical diligence stops being something you commission once and becomes a screen, then a monitor, then a defence.

Screening · pre-LOI

Look before you commit

Run it on targets you would never resource a full engagement for. Firms doing this aren't just faster; they see more of the market.

Exclusivity

Findings while price is open

Architecture, security, licensing and remediation cost in engineering months, while there is still a number to move.

Hold period

Drift, tracked

Scheduled re-runs track debt accumulation, security drift and technical covenant signals months before they reach revenue.

Exit

Find it before they do

The same assessment, read from the other side: what a buyer's diligence would surface, while remediation is still a sprint.

2–3 weeks
Hours
Fits inside exclusivity
$40K–$300K
A fraction
Viable earlier in the funnel
Sampled scope
Eleven modules
Same coverage every run
One snapshot
Scheduled
Through hold, into exit

Book demo

Walk through a live target. See exactly what the assessment surfaces.

A thirty-minute session — we walk through a complete assessment module by module, then apply it to a target in your pipeline.