Investment funds and fundraising

Technical due diligence

An independent view of what a company's technology is really worth: what it can carry, what it will cost to evolve, and where the risks sit that no product demo will ever show you.

Key facts

  • €4,900 for the audit and a written report, typically within two weeks.
  • The question is not "is the code elegant" but "can this technology carry the plan being presented, and at what cost".
  • Four axes: technical debt, security and compliance, key-person dependency, ability to hold the volume and pace announced.
  • Written, quantified and prioritised deliverable: what blocks the deal, what can be fixed afterwards, what is acceptable as it stands.
  • Independence: I have no interest in the deal closing. If my view is negative, it is written as such.

Why a fund audits the technology

Financial and legal diligence are reflexes; technical diligence is still often handled with a one-hour conversation with the CTO. That is surprising, because in a software company technology is both the principal asset and the place where the risks hardest to detect from outside are hiding.

A product demo shows what works. It does not show what the next feature will cost, whether the team can double without collapsing, whether a single developer holds all the keys, or whether a security flaw makes the deal reputationally risky.

The technical audit answers one simple question, the only one that matters to an investor: can the technology carry the plan the company is presenting, and if not, what does the gap cost.

What I examine

The audit follows four axes, with one consistent logic: do not judge elegance, measure risk and cost.

Technical debt first — not as an aesthetic judgement but as an amount. Which parts of the system slow every change down, by how much, and what a clean-up would cost. Then security and compliance: access and secret management, personal data exposure, legal basis for processing, unmaintained dependencies.

The third axis is the most often overlooked and the most dangerous: key-person dependency. How many people understand the core of the system, what is documented, and what concretely happens if the principal author leaves next month.

The fourth is the ability to deliver the plan: does the architecture support the stated volume, do infrastructure costs grow in proportion to revenue or faster, can the team absorb the planned hires.

The deliverable

You receive a written document, not an oral presentation to interpret. It runs to about fifteen pages and opens with the one thing an investment committee will certainly read: a one-page summary with an explicit opinion.

Findings are sorted into three categories, because putting everything in one list helps nobody decide. What blocks the deal. What can be fixed afterwards, with an order of magnitude for cost and time. What is acceptable as it stands and requires no action.

Added to that are the questions to put to the technical team at the debrief and, if the deal proceeds, a first hundred days technical plan.

One point of method: I do not issue a favourable opinion out of courtesy. A fund engaging me is buying a counterweight, not a rubber stamp.

For founders: preparing your due diligence

The exercise can be prepared for, and companies that prepare get better terms — not because their technology is better, but because an investor always discounts what they do not understand.

Four things before entering discussions. Document the architecture in two pages a non-technical reader can follow. Take an honest view of your technical debt and be able to quantify it: acknowledging a problem and presenting your plan inspires more confidence than denying it. Check that nothing critical depends on a single person. And put compliance in order, personal data handling in particular.

I also run this audit on the company side, ahead of a raise. Same format, different purpose: the report lets you fix what can be fixed and prepare your answers on the rest.

The four axes examined

AxisQuestion askedWarning signal
Technical debtWhat does the next feature cost today?Delivery times lengthening with a constant headcount
ArchitectureDoes the system support the volume in the plan?Infrastructure costs growing faster than revenue
Security and complianceWhat happens in the event of a data breach?Secrets in the code, no access management, no established legal basis
Key-person dependencyWhat happens if the lead developer leaves?One person understands the core, nothing is documented
Team and paceCan the team absorb the planned hires?No review process, no organised skill development

Every finding in the report is attached to one of these axes and classified as blocking, fixable or acceptable.

What this view is grounded in

Ten or more projects a year

In FinTech, PropTech, EdTech and applied AI, from prototype through to production.

See all work

A practising technical director

I hold the CTO role inside client companies: I audit systems I should be capable of taking over.

See all work

Coddect

Automated document analysis: turnaround divided by 14, costs divided by 30.

See all work

Frequently asked questions

How much does technical due diligence cost?

€4,900 at Workfutur for the audit and its written report, whatever the size of the target. That is the audit and scoping price shown on the pricing page: there is no hidden fund-specific rate card.

How long does it take?

Two weeks as a rule, from first access to the code repositories to delivery of the report. An accelerated one-week version is possible when the deal timetable demands it, at the cost of less depth on the secondary axes.

What access do you need?

Read access to the code repositories, whatever documentation exists in whatever state, a view of the infrastructure and its costs, and two interviews: one with the technical lead, one with a developer from the team. That second conversation is often the more instructive one.

What if your opinion is unfavourable?

It is written as such, with the evidence behind it. I have no interest in the deal closing, and a courtesy report would destroy the only thing that gives this exercise value. An unfavourable opinion is not always a refusal, incidentally: it often quantifies a discount or a condition precedent.

Do you work with the company after the investment?

Yes, frequently: the report leads to a hundred-day plan that I can execute as fractional CTO inside the portfolio company. In that case I flag it at audit time, so the potential conflict of interest is on the table rather than discovered later.

Do you run this audit for the company itself, before a raise?

Yes, and it is a good investment. Same method, same price, but the report serves to fix what can be fixed before discussions open and to prepare your answers on what cannot be fixed in time.

Next step

Got a project to turn into a product?

Book 30 minutes, or describe your idea in a few lines. We reply within 5 business days with free scoping — scope, risks, timeline and engagement pricing.