wwff.tech Let's talk
TECHNICAL DUE DILIGENCE

Before you write the cheque, know what you're buying.

Independent technical due diligence on AI-built software, for investors and acquirers. A straight answer on whether the thing works, what shape it's really in, and what it will cost to make it safe to own.

A working demo is not a working business.

More and more of the products crossing a deal desk were built fast, with AI coding tools, by small teams or solo founders. That's not a red flag on its own — it's how good products get to market now. But it changes what diligence has to look for. The traction is real and the demo runs; the question is what's underneath, and whether it can carry the growth your money is supposed to buy.

The usual failure isn't that the product is bad. It's that nobody has yet done the engineering a real user base needs, so the cost of that work is still sitting on the balance sheet, unpriced — and sometimes there's a security or data problem that becomes your problem the day the deal closes.

What the diligence covers

The questions I answer

  • Is it secure enough to put your name next to? Who can reach the data, and how exposed is it today?
  • Will it scale past where it is, or does it fall over at the next order of magnitude?
  • Can a team actually maintain and extend it, or is it held together in ways only its author understands?
  • How much of it is the AI tool's defaults, and what breaks when you change them?
  • What's the real cost and timeline to make it safe and solid — the number that belongs in the model?

What you receive

  • A written report, ranked by risk to the investment, in plain English with the technical detail underneath
  • A Keep / Fix / Rebuild verdict on the codebase, with the reasoning shown
  • A remediation estimate: what it takes to close the critical gaps, in time and money
  • A call to walk through it with you — or with the founders, if that helps the deal

How it works with a deal

It's the same review as a Defuse engagement — code, configuration and architecture — framed for a buyer rather than a builder, and written so it stands up in a data room. I work from a read-only copy of the code wherever possible, under NDA, and I'm happy to speak to the founders directly: good diligence should help a fair deal happen, not just hunt for reasons to walk.

Scope and fee are set per deal, since timelines and what's at stake vary. Tell me roughly what you're looking at and by when, and I'll come back with a shape and a price.

Questions people ask

Can you turn it around on a deal timeline?

Usually. Tell me the date you need it by. A focused read for a go/no-go decision is faster than a full remediation-grade report, and I'll tell you honestly what's achievable in the window.

Do you work for the buyer or the seller?

Most often the buyer, but a founder preparing to raise or sell can commission the same review to find problems before an investor does. I say who I'm acting for, and I don't do both sides on the same deal.

Is this a penetration test?

No — it's broader and earlier: security, architecture and maintainability together. If the deal needs a formal pen test as a condition, I'll say so and help you scope one.

Will the founders see it?

That's your call. Shared carefully, the report can be the basis of a constructive conversation about price and remediation rather than a weapon. I'll format it accordingly if that's the plan.