Fixed-price
technical due diligence
for $1–5M online
acquisitions

A buyer-ready report on code, infrastructure, team risk, and compliance, delivered in days.

Executive VerdictIllustrative engagement
Proceed with caution
Cost-to-Replicate$410–520K
First-Year True Cost$187K
Bus factor1 person
Live findings drip · Day 3 of 7
Verified: hidden license problem in the billing system. Grounds to renegotiate; flagged same-day.
Verified: the "proprietary AI" is a rented third-party service you don't own.
Reported: one developer holds all the keys. If they walk, the business stops.

Deal-killers surface same-day, so you don’t wait for Day 7.

The status quo

What buyers do today

Four ways technical risk slips through a sub-$5M deal. All four end with the buyer paying for it.

Approach 1

Skip tech DD entirely

Accept undiagnosed risk. It's the most common outcome, and the most expensive when it goes wrong.

How this plays out

A buyer closes on a $1.8M SaaS, then learns the code can't legally be resold as-is. The fix costs more than the discount any seller would have given.

Approach 2

Hire a freelancer

A code review with no methodology behind it. The issues surface post-close, when your leverage is gone.

How this plays out

A $2K review says "code looks fine." Six months later the one developer who ran everything quits, and nobody can update the product.

Approach 3

Overspend on PE-tier DD

A $50K engagement kills the math on a $2M acquisition before it starts.

How this plays out

Diligence quoted at 2.5% of the purchase price. The buyer walks away from a business that was actually fine.

Approach 4

Stop at financial DD

The books can look perfect while the product hides a license problem, a one-person team, or an "AI" that's really rented software.

How this plays out

The accountants confirm the revenue is real. Nobody notices the "AI platform" is a thin wrapper around a service anyone can rent.

Why BearingGate

The full picture, at a fixed price

You're spending a lot on this deal already. Diligence shouldn't be another negotiation; the price and scope are fixed and public.

Fixed price, scope & timeline

Published on this page. No discovery call required to find out what it costs.

Sized for sub-$5M deals

Right-sized rigor for your deal economics: the depth of a full assessment, scaled to a sub-$5M budget.

Technical-first

Code, infrastructure, team, and compliance. Pair us with your QoE provider for the financials.

EU coverage built in

GDPR baseline in every full assessment. NIS2, EU AI Act, and DORA readiness as add-on modules.

Before you close, validate the technical risk. BearingGate delivers a buyer-ready report at a fixed price, built on a repeatable methodology that holds up under investment-committee scrutiny.
The deliverable

One report. Two documents. Two readers.

Every TrueBearing™ engagement is delivered as a pair: one document for the person signing the check, one for the person inheriting the codebase.

Document one

Executive Verdict

Plain language, buyer-facing. It gives you the verdict, the deal-relevant findings, Cost-to-Replicate and First-Year True Cost, and what to do about each, readable in one sitting.

6–10 PAGES · FOR YOU AND YOUR IC
Document two

Technical Dossier

Full evidence: scan output, architecture review, interview notes, license inventory, remediation estimates. Built for the engineer who takes over on Day 1.

20–40+ PAGES · FOR YOUR INCOMING CTO
Methodology

The seven pillars

Every full assessment covers all seven. No pillar is skipped because the codebase "looked fine".

Code & Architecture

Is the product well built, and can it grow with the business, or will it need an expensive rebuild?

e.g.Roadmap slipped three quarters running

Security

How easily could the business be hacked, and what happens if it is?

e.g.Prod credentials in repo history

Infrastructure, Ops & Cost

What does it really cost to run each month, and are there surprise bills coming?

e.g.$38K vendor renewal cliff in month 4

IP & Licensing

Do you actually own what you're buying, or is some of it borrowed, rented, or legally encumbered?

e.g.AGPL-3.0 in the billing service

Key-Person, Team & Knowledge Risk

Signature

If the founder walks away the day after closing, what breaks, and how fast can you recover? Includes the Founder Departure Day Simulation.

e.g.DNS on the founder's personal email

AI-Generated Code & AI-Washing

New for 2026

Is the "AI" real technology you'd own, or a rented service dressed up for the sale?

e.g."Proprietary engine" = one API call

Compliance

Is the business following privacy law, or are you inheriting fines and cleanup work?

e.g.Cookie banner ≠ actual trackers
Pillar six, in depth

The AI‑washing audit

In 2026, half the listings you'll see are "AI-powered". A few genuinely are; the rest are a system prompt away from being a commodity. Every TrueBearing report answers three questions the seller's deck won't.

Q1
Is "our AI" real?

Or is it a wrapped third-party API, one upstream pricing change away from erasing the margin you're underwriting?

Q2
Was the codebase AI-generated?

And does it carry the characteristic debt patterns: duplication, dead paths, tests that assert nothing?

Q3
Can the team maintain it?

Without ongoing AI assistance? Or does the institutional knowledge live in a chat history nobody saved?

How it works

Booked to buyer-ready in seven days

DAY 0

Intro call

We frame the engagement to your deal context, technical literacy, and operating plan, so the report speaks to your situation.

DAYS 1–2

Automated sweep

100% of the codebase scanned, synthesized, and prioritized by the TrueBearing algorithm.

Tooling · DeepSource · SonarQube · Snyk · Semgrep · Black Duck
DAYS 3–5

Human deep dive

A senior architect manually reviews every high-risk area and interviews the team. Deal-killer findings are alerted same-day, the moment they surface.

Frameworks · ISO 25010 quality model · ATAM (Carnegie Mellon SEI)
DAY 6

Dossier assembly

Findings consolidated, confidence tags assigned, both documents drafted and reviewed by the architect who did the work.

DAY 7

Verdict delivered

Executive Verdict and Technical Dossier, walked through live on your delivery call.

Deliverables · two documents, two readers · personal sign-off by the reviewing architect

Timeline shown for the TrueBearing™ Report. Pre-LOI Scan: 48 hours · TrueBearing Plus: 14 days.

Our coverage commitment100% automated coverage of the codebase + targeted human review of the areas that matter.
8–15 hours of senior architect time, augmented by the TrueBearing™ algorithm and automated tooling.
Confidence calibration

Every finding tells you how we know

Each finding is tagged inline: Verified (we tested it), Inferred (the evidence points there), or Reported (the seller told us). Your IC sees the evidence behind every finding, not just the verdict, so the report survives the questions it will be asked.

Production database has no tested restore pathVerified
Churn-critical cron jobs run from founder's laptopReported
Mobile app abandoned; store listing still liveInferred
CI pipeline green for 14 consecutive monthsVerified
Pricing

The full price list, no call required

If a diligence provider won't tell you the price before a call, ask yourself what else gets discovered late.

Tier 1

Pre-LOI Scan

$1,500

48-HOUR TURNAROUND

A fast read before you commit to exclusivity.

  • Automated stack & dependency scan
  • 1–2 page senior summary
  • Proceed / caution / walk signal
  • Credits in full toward Tier 2 within 30 days
Request a scan
Most buyersTier 2

The TrueBearing™ Report

$5,000

7-DAY TURNAROUND

The core product. Post-LOI, pre-close.

  • Full seven-pillar assessment
  • Seller & team interviews
  • Executive Verdict + Technical Dossier
  • Cost-to-Replicate & First-Year True Cost
  • Same-day deal-killer alerts
Book an intro call
Tier 3

TrueBearing Plus

$9,500

14-DAY TURNAROUND

For deals where the tech is the thesis.

  • Everything in The TrueBearing Report
  • Expanded code review
  • Day-60 delta report
  • 90-minute CTO delivery call
  • 2 post-close advisory calls
Book an intro call

Post-Close Health Check

Uptime & CVE monitoring, monthly report and call, hiring and vendor advisory.

$2,000 / MONTH

Penetration Testing

Full offensive security engagement, scoped separately from the report.

QUOTED

Compliance Modules

SOC 2, ISO 27001, HIPAA, NIS2, EU AI Act, DORA, WCAG/ADA, PCI-DSS readiness.

QUOTED PER MODULE
0.17%OF A $3M ACQUISITION

That's what $5,000 is: less than the broker fee, less than the legal fee, and the only line item that tells you whether the technology you're buying is worth what you're paying for it.

The walkaway refund schedule

Walk away from the deal, walk away from the engagement. Published and milestone-based: the further we've gone, the less comes back. No negotiation required.

60%before kickoff
40%after automated scans
25%after deep-dive begins
0%after critical-findings memo
The obvious question

"Why not just point AI at the codebase?"

You should, and we do. Automation is the floor of this engagement; the human judgment on top is the product.

What automation covers

  • 100% of the codebase, scanned with industry-standard tooling
  • Known vulnerabilities, secrets, and dependency risks
  • Full open-source license inventory
  • Code-quality and complexity metrics, repo-wide
  • Synthesis and prioritization via the TrueBearing™ algorithm

What it can't answer

  • "Should you still do this deal?" Deal-specific judgment.
  • "What will this cost you in Year 1?" A post-close projection.
  • "Is the CTO going to leave?" Key-person risk, via interviews.
  • "Does this GPL dependency mean you don't own the IP?" Legal exposure analysis.
  • "Was this codebase vibe-coded?" And what that means for maintainability.
Who we work with

Built for the people doing sub-$5M deals

Self-funded & SBA-backed buyers

"The seller's tech is a black box. If something is broken, I won't know until I'm running it. By then it's too late."

Don't close on a tech business you can't read.

Search funds & independent sponsors

"My IC will tear apart any DD report that looks ad-hoc, but I can't justify a $50K engagement on a $3M deal."

IC-grade technical due diligence, priced for the deals you actually do.

Lower-middle-market PE

"We can't fire the full-scale advisory bazooka at every $2M add-on."

Same rigor as your platform-level engagements, sized for add-on economics.

Strategic acquirers

"Our engineers can do code review, but they're not deal people."

Your engineers know your code. We know what a buyer needs to know about theirs.

Who's behind this

Operators who've run what you're buying

Every assessor on the bench has actually run a technology organization: built teams, carried technical debt, and made build-vs-buy calls with real money on the line. They're the operators a buyer wishes they had on staff.

Bryan O'Neil, Founder & Principal Architect
Founder & Principal Architect

Bryan O'Neil

Seventeen years in the M&A industry, an original co-founder of Centurica and FE International and Tech Lead at Quiet Light, Bryan lives and breathes online business acquisitions. Having also founded and invested in 12 SaaS businesses, he's developed a proprietary framework to evaluate them. That framework stands behind every TrueBearing™ verdict.

Reijo Sirila, Diligence Lead

Reijo Sirila

Diligence Lead

Founder-CTO who's built and scaled multiple software platforms, Reijo's idea of fun has been running technical diligence on deals for years — far before AI was a thing.

David Barnett, Infrastructure, Ops & Cost

David Barnett

Infrastructure, Ops & Cost

A seasoned fractional COO who spots dangerous operational patterns in his sleep. No stone is left unturned when David reviews and signs off your TrueBearing™ verdict.

Wei Tan, AI Code & IP / Licensing

Wei Tan

AI Code & IP / Licensing

Built ML products before it was fashionable. He can tell genuine in-house AI from an API wrapper in an afternoon, and reads a dependency license chain like the contract it actually is.

Every report is reviewed and personally signed by the lead architect on your deal. You get the names and credentials of everyone who touched your assessment. No anonymous "analyst team", and every finding has an author.

Sample report

Read a verdict before you book one

A sample Executive Verdict on an illustrative deal: the verdict, the headline numbers, the confidence tags, exactly as a buyer receives them.

A member of the team emails you the sample within one business day. No drip sequence, no SDR follow-up afterward.

Executive VerdictSAMPLE
VerifiedInferredReported

Don't close on a tech business you can't read.

A 20-minute intro call scopes the engagement to your deal. If we're not the right fit, we'll say so on the call.