Business criticality
Revenue dependencies, operational processes, customer journeys, concentration risk and technology alignment to the investment thesis.
Investor & board advisory
A structured framework for testing whether a target's technology can support the investment thesis and for translating technical findings into valuation, deal, integration and 100-day decisions.
Revenue dependencies, operational processes, customer journeys, concentration risk and technology alignment to the investment thesis.
Application architecture, hosting, integration patterns, bottlenecks, observability, scalability assumptions and material single points of failure.
Identity, privileged access, vulnerability management, incident history, backups, disaster recovery, monitoring and recovery evidence.
Data ownership, quality, lineage, privacy, AI use cases, model/provider dependencies, governance, retention and portability.
Ownership, employee/contractor assignment, open-source obligations, third-party licences, transferability and source/repository control.
Unsupported technology, deferred maintenance, test coverage, build/deploy reliability, architecture constraints and remediation backlog.
Team structure, critical knowledge, retention, outsourcing, privileged access, documentation and dependency on individuals or suppliers.
Spend, contractual commitments, renewal/exit terms, concentration, data portability, service dependencies and shadow technology.
Roadmap credibility, release cadence, defects, delivery controls, SDLC, metrics, incident learning and product/technology governance.
Run-rate technology cost, deferred investment, remediation ranges, migration cost, integration cost, synergies, separation costs and 100-day priorities.
Every material finding should record evidence, consequence, likelihood/uncertainty, time horizon, estimated remediation range where supportable, dependency on the deal thesis, and a recommended disposition: deal condition, valuation consideration, 100-day action, longer-term improvement, or accepted risk.
Management assertion, documentary evidence, configuration/technical evidence and independent observation are not treated as equivalent. Findings must identify the evidence basis and material limitations. The framework is not a substitute for legal, financial, regulatory or specialist penetration-testing advice.