Charles BurtTechnical Due Diligence
Available now · Fixed fee per deal · London-based · Remote-first

Technical due diligence before the money moves.

I’ve done due diligence from both sides of the table, as the founder being assessed and as the consultant doing the assessing. My biggest single finding was around £2m.

Get in touch → See the checklist

What is technical due diligence?

Technical due diligence is an independent review of a company’s technology before money changes hands. It assesses the architecture, codebase, security, and the team behind it. Investors and acquirers typically commission it after a term sheet has been agreed but before the deal completes.

Founders often commission it ahead of a funding round to identify and fix issues before investors uncover them.

Also offered as: software due diligence · code due diligence · tech due diligence.

When do you need technical due diligence?

3 situations bring people here. Under each, where I’ve done it before.

You’re investing or acquiring, and the deadline is set.

The commercial terms are agreed, the deal is moving forward, but one big question remains: is the technology actually worth what you’re paying for?

A technical due diligence review gives you an independent assessment of the codebase, architecture, security, and engineering team. It highlights hidden costs, key-person dependencies, technical debt, and any expensive rebuilds waiting around the corner. On startup technical due diligence, where the codebase is young, the weight shifts to key-person risk and the architecture choices the company will have to live with.

Technical due diligence on multi-million-pound operations

You’re raising, and technical DD is coming.

Sooner or later, investors will ask difficult technical questions. Who wrote the core platform? Who owns the IP? Can the technology actually support the growth projections?

Running the review before fundraising gives you the chance to fix issues, prepare evidence, and answer those questions with confidence.

Raised £450k+ as a founder · £50k in 2 weeks at a £1.25m valuation

You’ve hired a development team and want an independent review.

Perhaps you’ve outsourced development, possibly overseas, and months of work have gone into building the product. You’re paying the invoices, but you have no easy way to judge the quality of what’s being delivered.

An independent review tells you whether the code is maintainable, whether you genuinely own what you’ve paid for, and whether you’re getting value for money. If the product was largely built with AI tools, start at the AI code audit & rescue.

Assessed the ~30-person dev partner behind the McDonald’s app · ~£2m found (R/GA)

What the review covers.

The review looks at six areas, each tied to a way deals tend to go wrong.

Architecture. Does the design hold up at the next stage of growth — and if it doesn’t, where does it break first?
Scalability. I test the growth claims against the evidence: real load, real data volumes, and what scaling actually costs.
Security. A review of posture, not a penetration test. How secrets are handled, who has access to what, the risk sitting in third-party dependencies, and whether personal-data obligations are being met.
Code & ownership. I sample the code for quality, check that IP assignments are properly in place, and inventory the open-source licences in use — along with the terms that come with them.
Team & key-person risk. Who understands each critical system, and what happens if one person leaves.
Delivery & cost. How the team ships today, and what it will really cost to keep the roadmap moving.

The technical due diligence checklist.

In full, so you can use it with or without me: run your own review, brief another consultant, or prepare to be assessed.

Architecture

  • Does the diagram match the system that’s actually running?
  • Where are the single points of failure — and who owns each one?
  • Are development, staging and production properly separate?
  • What third-party services does it depend on, and on what terms?
  • Can the data model survive the growth plan?

Scalability

  • Is there evidence of how it behaves under load — or just claims?
  • How close is current usage to the capacity it was designed for?
  • What does each extra user or transaction actually cost?
  • Where are the known bottlenecks, and what’s the plan for each?

Security

  • Do secrets and keys live outside the codebase?
  • Who can access what — reviewed role by role?
  • Have the dependencies been scanned for known vulnerabilities?
  • Does personal-data handling stand up to GDPR?
  • Is there an incident history, and a response plan?

Code & ownership

  • Who wrote the core code — and do the contracts prove it’s owned?
  • Are contractor and dev-shop IP assignments in writing?
  • What open-source licences are in play, and do the terms hold up?
  • Does a sample of the code show tests, documentation, readability?

Team & key-person risk

  • How many people really understand each critical system?
  • If one person left tomorrow, what breaks?
  • Does the knowledge exist anywhere outside one person’s head?
  • Does the hiring plan match the roadmap?

Delivery & cost

  • What does a release look like, end to end?
  • How often does the team ship — and how does a rollback work?
  • Is the roadmap costed against real capacity?
  • What’s the run rate: infrastructure, licences, people?

What’s in the technical due diligence report?

The report works through the checklist line by line. Every problem it finds comes with two things: how serious it is, and what it will cost to fix.

It’s written for two audiences. The executive summary is in plain English, for the people signing the cheque. The technical appendix carries the evidence, for the engineering team who’ll act on it.

The part that moves valuations is the remediation roadmap: what to fix, in what order, and what each fix will cost.

How long does it take? A seed-stage review usually runs one to three weeks. A complex, multi-system target can run to eight.

What does technical due diligence cost?

UK fixed fees, as published by providers, scale with deal value:

Deal value under £1m
£10,000 to £25,000

Infrastructure and code review.

£1m to £10m
£25,000 to £60,000

Full architecture and delivery analysis.

Above £10m
£60,000 to £150,000+

End-to-end review of complex targets.

Rule of thumb
1 to 3% of deal value

The heuristic acquiring boards use. Senior day rates: £800 to £1,600.

How I price

Fixed fee per deal, in writing before we start. 3 things move the number: the size of the deal, the size of the system, and the deadline. Send all 3 and I’ll quote fee and timeline.

Get in touch →

Where I stand.

A technical review has a bad name for a reason: it’s usually run by an agency hoping to win the rebuild, so the findings can skew towards more work for them. This one is independent.

An agency’s review quietly skips two questions: whether the deal still makes sense, and who should fix what it finds. Here, both stay open.

The report is yours to take to any engineering team — including one I source. If you do ask me to handle the remediation, the audit fee credits against that work in full. The findings are the findings: they don’t change based on who fixes them. And if what the deal needs afterwards is ongoing technical leadership rather than a one-off fix, that’s a fractional CTO engagement.

On access: I sign an NDA before anything is shared, work with read-only credentials, and do supervised walkthroughs wherever the company prefers them. The findings go to whoever commissioned the review — and no one else.

Who this isn’t for

Companies with nothing built yet — no code means nothing to review. If you’re pre-build and want the feasibility, architecture and cost on paper first, that’s the venture readiness audit. And it’s not for anyone after a certificate that says everything is fine.

Done before, with the numbers.

3 engagements that map to the situations above.

Dev-partner assessment · R/GA · 2017

McDonald’s app: ~£2m in annual savings found in 3 months

Assessed the ~30-person development partner behind the global Happy Meal app: performance, processes, commercials. Found ~£2m in potential annual savings inside a 3-month contract.

R/GA answered with the offer of a permanent role heading the function
Board-level findings · NEOM (The Line) · 2021

Overdue programme, diagnosed and turned

Inherited an overdue programme on NEOM’s B2B digital-twin platform. Diagnosed team, delivery, architecture and platform; presented recommendations to the CEO and board.

Dependable delivery restored across a distributed international team
Architecture & cost · JP Morgan / Contex-City

Development cost cut 40%

Cut development cost 40% through architecture and process redesign on a JP Morgan / Contex-City engagement.

Delivered through the consultancy I founded and staffed

That consultancy ran technical due diligence on multi-million-pound operations and delivered for JP Morgan, HP, IBM, McDonald’s and EE. As a founder I raised £450k+, and I wound down Immersive Medical, my VR telemedicine company, when its NHS sponsor moved on and the funding ended. Full record: the work · the validation.

From first email to report.

01

Get in touch

Tell me the company, the deal stage and your deadline — two or three sentences is plenty.

02

Fixed fee & NDA

You get a fixed fee and a timeline in writing before anything starts. I sign the NDA first — nothing is shared until it’s done.

03

The review

I work through the six areas against the checklist — reviewing the code and interviewing the people who built it.

04

Report & walkthrough

You get the executive summary, technical appendix and costed roadmap, then I walk you through the findings on a call.

Questions investors and founders ask.

How much does technical due diligence cost in the UK?

Published UK fees scale with deal value: £10,000 to £25,000 for deals under £1m, £25,000 to £60,000 up to £10m, and £60,000 to £150,000+ above that. As a rule of thumb, boards budget 1 to 3% of deal value. I quote a fixed fee per deal, in writing before anything starts.

How long does technical due diligence take?

One to three weeks for a seed-stage company. A larger company with several systems to review can take up to eight. The timeline is agreed in writing alongside the fee.

What red flags are investors looking for?

The same problems keep coming up: code that lives in one person’s head and nowhere else; dev-shop work where the contracts don’t make clear who owns it; open-source code used in ways the licence doesn’t allow; growth claims that have never been tested under load; and systems that still work, but only because of people who have since left. The checklist above covers all of them.

How do I prepare for technical due diligence before a raise?

Run the same review on yourself before investors run it on you. Write down who wrote which code and under what contract, list your open-source licences, separate your test and live environments, and get what people know out of their heads and onto paper. I run that review for founders too: you find the problems before investors do, and you fix them on your own schedule.

Isn’t outsourced technical due diligence just liability-shifting paperwork?

It’s a fair challenge. Companies rarely fail because of their technology, and some investors skip the review. But this report is not a pass or fail stamp. It answers one practical question: after the deal closes, what will this technology cost me? That covers fixing what is broken, keeping it running as the company grows, and what happens if the people who understand it leave. The answer can change the price, or whether the deal happens at all. And if everything is sound, you find that out before you sign, not after.

Who can run technical due diligence on a company we’re investing in?

Someone who has built and run systems themselves, working independently — and they should earn their money from the review, not from what it finds. An agency makes money from finding problems to fix, so the findings can skew towards more work for them. This one is independent: the report is yours to take to any engineering team, including one I create. Build with me and the audit fee credits in full.

Tell me the company and your deadline.

Deal stage, size of the system, the date you need the report by. You get a fixed fee and a timeline, or a straight no if it isn’t a fit.

You’ll be dealing with someone who has sat in both chairs: the founder being assessed and the consultant doing the assessing.

LinkedIn · /in/charles-burt Full profile · charlesburt.me