What I assess: architecture, code quality, security, scalability, cloud cost, team
The question behind every review is simple: can this technology support the business plan you are investing in, and what will it cost to fix if it can’t? I look at six areas and score the risk in each.
I read the code and infrastructure myself and talk to the technical founder or CTO. Claims in the pitch deck are checked against what is actually running, and cloud findings draw on my AWS Certified Solutions Architect – Professional background.
- Architecture: how the system is built, where it is fragile, and whether it fits the next stage of growth
- Code quality: structure, test coverage, dependency health, technical debt and how quickly changes can ship safely
- Security: access control, secrets, encryption, data protection, known vulnerabilities and SOC 2 or ISO 27001 readiness
- Scalability: what breaks at ten times today’s load, and what it would take to fix
- Cloud cost: current spend, unit economics per customer, and waste that can be removed
- Team: key-person risk, delivery process, documentation, and whether the team can deliver the roadmap
Technical due diligence for AI startups: model, data, evaluation and vendor lock-in risk
AI startups need a different set of questions, because the value in an AI pitch is often hard to see from the outside. My evaluation and red-teaming work on frontier LLMs and coding agents means I know how AI systems are tested, and how tests can flatter them.
Where the AI product is central to the investment case, I can add a short hands-on red-team of the product, using the same methods as my AI red teaming service.
- Model: is there a proprietary model, a fine-tuned one, or a well-prompted wrapper around a third-party API, and what is actually defensible?
- Data: where training and retrieval data came from, whether the company has the rights to use it, and how personal data is handled
- Evaluation: whether accuracy claims can be reproduced, and whether test data has leaked into training or prompts
- Vendor lock-in: dependence on one model provider, exposure to price changes and model deprecations, and inference cost against gross margin
- AI security: prompt injection, data leakage and unsafe agent actions that could become a liability after the deal
Sample report structure (risk-scored findings)
The report is written for an investment committee, not for engineers. Each finding says what the issue is, why it matters to the deal, how likely and how serious it is, and the likely effort to fix it. Technical detail sits in appendices for your advisers or the target’s team.
- Executive summary: overall rating, the three to five issues that matter most, and a clear recommendation
- Risk register: every finding scored by likelihood and impact, rated red, amber or green
- Area-by-area findings across architecture, code, security, scalability, cloud cost, team and AI
- Deal implications: issues to raise before signing, possible conditions, and items for a post-deal 100-day plan
- Remediation plan: prioritised fixes with effort estimates
Timeline and how deal confidentiality and NDAs work
The timeline depends on the size of the codebase and how quickly the target can give access. If your deal has a hard deadline, tell me on the first call and I will scope the review to fit it, stating clearly in the report what was and was not covered.
Confidentiality is built in from the start. I sign an NDA before any discovery, with you and with the target if needed, and deals can run under a project code name. I ask for read-only access to code and cloud accounts, which can be revoked as soon as the report is delivered. Findings go only to the party that commissioned the review. I do the work myself, so your deal information isn’t passed to an agency team or junior staff.
Who it’s for: angels, VCs, PE, corporate acquirers
Large technology due diligence firms are built for large deals. Seed to Series B rounds, angel syndicates and smaller acquisitions still carry real technical risk, but often don’t justify a large firm’s fee. That is the gap I fill: a senior reviewer, a fixed or capped price and a report you can act on.
- Angel investors and syndicates who want an independent technical opinion before committing
- VCs checking a technical founder’s claims, especially for AI-first companies
- Private equity firms assessing platform risk and the cost of scaling
- Corporate acquirers running a code audit before acquisition or integration
- Founders preparing for investor due diligence who want to find the issues first
What you get
- A board-ready report written for a non-technical investment committee
- An executive summary with an overall rating and a clear recommendation
- A risk register with every finding scored by likelihood and impact
- An AI-specific section on model, data, evaluation and vendor lock-in, where relevant
- A prioritised remediation plan with effort estimates, usable as a post-deal 100-day plan
- A readout call with your partners or investment committee to answer questions
How it works
Step 01 · Days 1–2
Scope and NDA
A call to understand the deal, the target and your concerns, then NDAs and a written scope with a fixed or capped price.
Step 02 · Week 1
Access and review
Read-only access to code, cloud and documentation, plus the data room. I review the architecture, code, security, infrastructure and any AI components hands-on.
Step 03 · Weeks 1–2
Team sessions
Working sessions with the CTO or technical founder and key engineers to test what I found and understand the roadmap.
Step 04 · Weeks 2–3
Report and readout
The written report, then a readout call with your investment committee. Urgent red flags are raised with you as soon as I find them, not held for the report.
Proof
“What truly sets Arslan apart is the ability to communicate complex technical concepts in a clear and accessible manner.”
Ivan Zoria
Software Engineer
“Steady progress, predictable delivery, and code that’s easy to review and integrate.”
Sean Metcalf
Founder, getKaivo
“His knowledge of security, cryptography, and database design was of crucial importance to our product’s successful development.”
Rod Ast
CEO & Founder, 911 Vault
Price
From £3,500. Fixed scope and a fixed or capped price, agreed in writing under NDA. Every engagement starts with a free 1-hour intro call, and you get a written scope with a fixed or capped price before any work starts.
FAQ
How much does technical due diligence cost in the UK?
My technical due diligence starts from £3,500 for a fixed scope. The final price depends on the size of the codebase, the number of products and whether AI components need hands-on testing. You get a fixed or capped price in writing before any work starts.
Will the target company know you are reviewing them?
Usually yes, because a proper review needs access to code and time with the technical team. I can sign an NDA with the target as well as with you, and keep contact limited to the people the deal team agrees on. If access isn’t possible yet, I can start with an outside-in review of the product, public footprint and data room.
Can you do due diligence on an AI startup?
Yes, and it is where my background is most useful. Alongside the standard review, I check whether the model is genuinely proprietary, whether the data is properly licensed, whether evaluation results can be reproduced and how exposed the company is to a single model provider.
Will the report make sense to non-technical partners?
Yes. It opens with a plain-English summary, an overall rating and the few issues that matter for the deal, with jargon kept to the appendices. I also walk your partners or investment committee through it on a readout call.
Can founders hire you to prepare for investor due diligence?
Yes. The same review, done before a raise or sale, shows you what an investor’s adviser is likely to find while there is still time to fix it. You get the same risk-scored report and a remediation plan you can start on straight away.
Do you check SOC 2 or GDPR readiness as part of due diligence?
Yes, at the level an investor needs: whether the controls exist, whether they match what the company tells customers, and what it would take to close the gaps. If the target needs hands-on help afterwards, that is a separate readiness engagement.