Technology due diligence,
underwritten on evidence.

A guide for private equity and corporate M&A. Why technology now decides whether a deal returns, why it is still diligenced from slides and interviews, and how Axiarete's agents read the target's estate itself, price every finding for the investment committee, and carry the picture past close into a value plan tracked to run-rate.

A target's technology estate, from deck to exit. Illustrative.
What the deck said

In brief. Technology due diligence is the assessment of a target's technology before a transaction: its architecture, code and technical debt, cybersecurity, software supply chain and licensing, infrastructure and run-rate cost, data and AI readiness, and the team that runs it. Its purpose is to tell the buyer what the technology is worth, what it will cost to fix and what could go wrong, in time to change the price, the structure or the decision. AI-driven technology due diligence replaces the two-to-four-week review of slides, a data room and a code sample with AI agents that read the target's estate itself and price every finding in the terms an investment committee uses: remediation cost, run-rate upside and value at risk. Axiarete AI operates this model for private equity funds and corporate acquirers, and after close the same picture becomes the value creation or integration plan, tracked to run-rate.

Five things to take from this guide

  1. The math of the deal has changed. Bain's Global Private Equity Report finds a typical buyout that needed about 5% annual EBITDA growth to return 2.5x in the 2010s now needs 10 to 12%, with holding periods near seven years and 32,000 unsold companies worth $3.8 trillion awaiting exit. Value must now be built in the operating company, and the operating company runs on its technology.
  2. Technology is still diligenced from the deck. A conventional tech DD reads a management presentation, a data room and a sample of the code in two to four weeks, and the report is filed at signing. What was missed is discovered in month three, on the buyer's own P&L.
  3. The cost of missing is now a matter of record. Verizon cut $350 million from its price for Yahoo after breach disclosures; the UK regulator fined Marriott £18.4 million over a compromise that had been running inside Starwood since 2014, through the 2016 acquisition. Forescout's 2019 survey of 2,700 decision makers found 53% had seen a critical security issue put a deal in jeopardy and 65% reported buyer's remorse over what they inherited.
  4. AI-driven technology due diligence has four defining properties: the estate read itself, not the deck; every finding priced for the IC; one picture that survives signing; and agents that deliver the value plan after close under human approval.
  5. Inside operating companies, Axiarete customers report more than 100 critical risks discovered and remediated across a legacy estate, more than 20% of a 500-system portfolio confirmed for reduction, and a mainframe modernized 80% faster at half the quoted cost. That is the work a fund needs to know about before it signs, and to have done before it exits.

The math of the deal changed. Diligence did not.

"The tech DD said 'no red flags.' We found them in month three, on our own P&L."The situation this guide is written for

For most of the 2010s a buyout could be underwritten on the assumption that the exit multiple would be higher than the entry multiple. That assumption has gone. Bain's analysis is direct: a typical investment that once needed roughly 5% annual EBITDA growth to deliver a 2.5x return over a five-year hold now needs 10 to 12%, and holds have stretched toward seven years. Returns have to be built inside the operating company, and every operating company is, to a first approximation, a set of applications, data and infrastructure with a business attached.

10–12%annual EBITDA growth a typical deal now needs for a 2.5x return, against about 5% in the 2010sBain Global PE Report
$3.8Tof unsold portfolio companies awaiting exit, some 32,000 businesses, with holds near seven yearsBain Global PE Report
53%of decision makers have seen a critical cybersecurity issue put a deal in jeopardy; 65% report buyer's remorseForescout, 2019, 2,700+ respondents
$350Mcut from Verizon's price for Yahoo after breach disclosures surfaced between signing and closeYahoo 8-K, February 2017

Against that arithmetic, technology due diligence has changed remarkably little. It is still, in most processes, a two-to-four-week engagement conducted from a management presentation, a data room, a set of interviews and a sample of the code, producing a report with a red-amber-green summary that is filed at signing. Bain's review of a decade of software buyouts found that revenue growth drove about half of value creation and multiple expansion most of the rest, while margin improvement contributed almost nothing; the operating lever the new math depends on is precisely the one diligence has told buyers least about. The same Forescout survey found only 36% of respondents strongly agreed their IT team was given adequate time to review a target's security before an acquisition completed.

The gap is not one of competence. Advisors do sound work within the window and the access they are given. The gap is structural: a process designed to produce a document by signing cannot see the estate whole, cannot price what it finds in the currency the committee uses, and has no way to carry what it learned into the plan the buyer will actually execute.

This year has sharpened the point. Bain's midyear report records technology deal value falling 70% between the fourth quarter of 2025 and the first quarter of 2026 as fewer large software transactions cleared, the first of what it calls a triple shock, and the one it attributes to an AI-driven rout in software valuations. The question an investment committee now asks of any software or technology-enabled target is whether its product is exposed to AI or built on it: what the code actually does, what it depends on, and how much of the roadmap the deck attributes to AI exists in the repository. That is a question about the estate, and it cannot be answered from the presentation that raised it.

The technology due diligence checklist: what a complete review covers

Technology due diligence is the assessment of a target's technology before a transaction, to establish what it is worth, what it will cost to fix, and what could go wrong. For a software or technology-enabled business the checklist runs to six areas and the team that operates them, and the discipline lies in pricing them together, because a finding in one is usually a liability in another.

Architecture and scalability CAN IT CARRY THE PLANWhether the platform can support the growth the investment case assumes, and what it would cost to make it able to. The most expensive finding is the one that requires a rewrite the model did not fund.
Code and technical debt REMEDIATION COSTWhat the software actually does, how much of it is understood, and what it costs to change. Technical debt sits at 20 to 40 percent of the value of a typical technology estate, and only some of it is under the revenue being bought.
Cybersecurity VALUE AT RISKVulnerabilities that are reachable and exposed, controls that are absent, and evidence of compromise past or present. The buyer inherits every one at close, and the regulator's view is that it bought them knowingly.
Supply chain, IP and licensing CAN IT BE OWNEDA software bill of materials, the license of every component, and the copyleft obligations that can reach proprietary code. The IP being valued is only as clean as its dependencies.
Infrastructure and run-rate RUN-RATE UPSIDECloud and hosting spend, duplicated platforms, end-of-life systems and the savings available from consolidation: the earnings the value plan can bank in year one.
Data and AI readiness THE NEXT MULTIPLEWhether the data is usable, the integrations reliable and the estate legible enough for AI to act on it; and, for the AI the target already ships, which models it depends on, on what terms, and how much of the capability in the deck exists in the code. Increasingly the basis of the exit story, and the hardest area to assess from a presentation.

A seventh area, the team, runs through all six. Knowledge held by two engineers who might leave at close is a form of technical debt, and a diligence that does not locate it will price the company as if the knowledge were written down.

What the investment committee actually needs to know

An investment committee does not need to know that a target has "significant technical debt" or a "moderate cybersecurity risk." It needs three numbers for every material finding, with the evidence behind them: what it will cost to fix, what fixing it returns to run-rate, and what is at risk if it is left. The illustration below shows the same target twice: as its management presentation described it, and as the estate showed it once read.

AreaAssessmentFor the investment committee
—value at risk
—remediation to close
—run-rate upside, annual

What a priced finding changes: price, structure, conditions, plan

A finding is only useful to a deal team if it can be turned into one of four instruments, and pricing is what makes that possible. A remediation cost with evidence behind it supports a price adjustment, in the same way a quality-of-earnings finding does. A value at risk that cannot be closed before signing supports structure: a specific indemnity, an escrow or holdback, or a negotiated position with the representations and warranties insurer, whose policy will in any case exclude what diligence has already found. An exposure that can be closed supports a condition: remediation before close, or a covenant to complete it within a defined period after. And a run-rate upside supports the plan: an initiative with an owner, a sequence and a number the fund will look for in the first quarter's results. A finding that arrives as a color supports none of these, which is why it so often changes nothing.

The same discipline serves the other side of the table. A sponsor preparing an exit, or a corporate preparing a carve-out, is better served by a vendor technology due diligence built on the same evidence a buyer will demand, with the entanglements that decide transition service agreements, shared platforms, shared identities, shared data, already mapped and priced. The technology story a seller cannot evidence is the one a buyer discounts.

When diligence misses, the buyer pays twice

Once in the price that should have moved and did not, and again on the operating P&L after close. Two transactions show the mechanism from the public record.

  • Verizon and Yahoo, 2017: $350 million between signing and close

    Verizon agreed to buy Yahoo's operating business for $4.83 billion in July 2016. Between signing and close, Yahoo disclosed two historical breaches, one affecting at least 500 million accounts and one affecting more than a billion. Verizon negotiated a $350 million reduction in the price, with Yahoo agreeing to share future liabilities from the breaches. Two facts matter for a diligence process: the compromises had occurred in 2013 and 2014, years before the deal, and neither was visible in the diligence that priced it.

  • Marriott and Starwood, 2016: the compromise that came with the company

    Marriott completed its acquisition of Starwood in September 2016. An attacker had been inside Starwood's reservation systems since 2014 and remained there, undetected, until 2018, by which point records relating to some 339 million guests had been exposed. In its 2019 statement of intent the UK Information Commissioner's Office said Marriott had failed to undertake sufficient due diligence when it bought Starwood; the final penalty, issued in 2020, was £18.4 million. Marriott did not create the exposure; it bought it, and the regulator's position was that it should have known what it was buying.

Most misses are less public and more expensive. The platform that cannot scale to the plan; the license that does not transfer; the integration held together by a nightly file nobody mentioned; the two engineers whose departure at close takes the product's knowledge with them. Forescout's finding that 65% of decision makers report buyer's remorse over inherited security concerns is the measured version of a conversation every operating partner has had. Axiarete's own review of fifty major security incidents found that in many of the cases the compromised system was not known to be in use at all, which is the natural condition of an acquired estate.

Why technology due diligence fails to change the deal

Conventional technology due diligence fails to change the price, the structure or the plan for five structural reasons, none of which is the quality of the advisor.

  • 1. It reads the deck, not the estate

    Management presentations describe the technology as its owners understand it, which is rarely the technology as it runs. A sample code review covers what the target chose to show. Interviews record what the interviewees know. None of these is evidence of what the estate contains, and the material findings are, by definition, the ones nobody in the room knew to mention.

  • 2. It is sized to the window, not the question

    Exclusivity is measured in weeks, and a human team can read only so much in weeks. The scope is cut to fit: a sample of repositories, a questionnaire on security, a spreadsheet of licenses supplied by the target. The question the committee is asking, what will this technology cost us and what is it worth, is answered for the fraction that was looked at.

  • 3. Findings arrive as colors, not numbers

    A red-amber-green summary cannot move a price. "Elevated technical debt" is not a figure a committee can net against EBITDA; "$4.2 million to remediate, $6.1 million a year in run-rate upside, $18 million at risk under order-to-cash" is. Diligence that does not price its findings leaves the deal team to guess, and deal teams, under time pressure, guess in favor of the deal.

  • 4. It expires at signing

    The report is a deliverable. It is filed when the deal closes, and the value creation plan or integration plan is built afterward by a different team, from the target's own documentation, rediscovering in month three what diligence found or should have found in week two. Nothing carries across the line.

  • 5. Cyber, code, licensing and cost are diligenced apart

    A security firm assesses vulnerabilities, a technical advisor reviews architecture, counsel reviews licenses, and a consultant estimates cloud savings, each from a different partial view. The exposures that decide deals live between them: the end-of-life component that is at once a vulnerability, a piece of technical debt, a license obligation and a cost. Nobody prices it whole, so nobody prices it.

The five failures have one shape. Each is the consequence of a process that must be completed by human readers inside a fixed window and then handed over. Reading an estate whole, pricing every finding in business terms, and carrying the picture from letter of intent to exit is work of a scale and continuity that AI agents can now perform and diligence teams never could.

What the buyer knows about the technology, from letter of intent to exit

The conventional curve rises during diligence, stops at signing, and is rebuilt from scratch after close, usually with an unpleasant step in month three. An evidence-based picture is complete before the investment committee meets and stays current through the hold, so the value plan is executed against the estate as it is.

LOIICSigningCloseMonth 3Exit What the buyer knows Evidence-based: complete before the IC, current through exitConventional: the report expires at signing
Where the value leaks. Illustrative curves. The shaded area is what the buyer paid for without knowing, and the month-three step is where it is usually discovered.

What AI-driven technology due diligence actually means

AI-driven technology due diligence uses AI agents to read the target's technology estate itself, its code, software supply chain, runtime, infrastructure and licenses, rather than the deck and a sample; to price every finding in the terms an investment committee uses; and to carry the resulting picture past signing into the value creation or integration plan, where agents deliver it under human approval. This is a different exercise from producing the familiar report faster, or from putting a language model behind a questionnaire. The report was never the constraint on conventional diligence; the window, the sample and the handover were, and those are what the agents remove.

Four properties distinguish an agentic diligence from an AI-assisted one.

The estate, read itself. Every repository, dependency, running service, host and license the target grants access to is read in the diligence window; a human team covers a fraction. What the software actually does, what it depends on, what it costs to run and what obligations attach to it are established from the systems rather than from the people presenting them. The findings that decide deals are rarely in the data room, and they are found because the reading is complete, not because someone thought to ask.

Every finding priced for the committee. Each material finding arrives with three numbers and the evidence behind them: what it costs to remediate, what remediating it returns to run-rate, and what is at risk if it is left, tied to the revenue or process it sits under. Cyber, technical debt, licensing, infrastructure cost and AI readiness are priced in one memo, because they describe one estate. The committee can net the technology against the model rather than color it.

One picture that survives signing. The map of the estate built in diligence is not a deliverable; it is the first page of the value creation plan for a fund or the integration plan for an acquirer. Every priced finding becomes a sequenced initiative on the day the deal closes, and the integration or value creation team starts from the estate as it is, not from the target's own documentation.

Agents that deliver; humans that approve. After close, the same agents that read the estate carry the plan: retiring the duplicated platform, remediating the priced exposure, consolidating the run-rate, through the operating company's own change control with a named person approving each change. Savings are tracked into the run-rate where the fund measures them, and the picture is kept current to exit, where it becomes the evidence behind the technology story a buyer will diligence in turn.

Tech DD, IT DD, cyber DD and agentic diligence: what the terms mean in practice

The market uses several terms and they do not describe the same scope. IT due diligence traditionally covers the target's internal systems, vendors and IT organization. Technology due diligence, tech due diligence or tech DD, adds the software the company sells or runs on: code, architecture, dependencies, scalability. Software due diligence and source code due diligence are the narrower forms of the same review, confined to the product and its codebase. Cyber due diligence assesses vulnerabilities, controls and evidence of compromise. AI-driven or agentic technology due diligence is different in kind rather than scope: agents read the estate whole across all three, price what they find for the committee, and carry the picture into execution after close. The useful question to ask of any provider is what remains the day after signing: a filed report, or a plan already in motion. Axiarete AI was built for the second, and it is the basis on which deal teams increasingly compare it with advisor-led reviews and cyber assessments.

Advisor-led review, cyber assessment, or agentic platform

The same six questions, applied to the three ways buyers have diligenced technology.

Advisor-led technology reviewCyber assessment and code scanAgentic platform (Axiarete)
What is readDeck, data room, interviews, a code sampleA questionnaire and a scan of what is providedThe estate itself: code, supply chain, runtime, infrastructure, licenses
CoverageWhat fits the windowWhat was scannedWhole, inside the exclusivity window
How findings arriveRed, amber, greenSeverity scoresRemediation cost, run-rate upside, value at risk, with evidence
Cyber, debt, licensing, costSeparate workstreamsCyber onlyPriced together, as one estate
After signingA filed reportA filed reportThe value creation or integration plan, with the picture kept current
Who executes the planThe portfolio company, from scratchThe portfolio companyAgents plus forward-deployed engineers, under the company's change control

Read, price, underwrite, deliver: one picture from LOI to exit

How Axiarete turns a target's technology from a section of the deck into a priced position in the model, and then into a value plan the same platform executes and tracks to run-rate after close.

Code Supply chain Runtime Infrastructure the target's estate, as it runs Living graph of the target what it does, what it costs, what is at risk Axiarete Read · Price · Underwrite remediation cost, upside, value at risk agents propose; the committee decides IC decision Value plan Integration Exit story After close, the same agents deliver the plan through the company's change control. Every initiative is measured in the run-rate, and every result updates the picture.
The picture that survives signing. The platform that read the estate in diligence executes the plan after close and keeps the picture current, so a fund underwrites, operates and exits on the same evidence.

How Axiarete approaches technology diligence and value management

Axiarete AI is an agentic AI platform for application portfolio rationalization, modernization and discovery, built by former Fortune 500 CIOs and running in Fortune 500 and government production environments. The work a fund needs done before it signs, reading an estate whole, pricing its debt and its exposure in business terms, and finding the run-rate a value plan can bank, is the work the platform does inside operating companies every day. Tech Diligence & Value Management brings it to the deal: agents read, price and underwrite before close, and deliver after it, with the investment committee and the operating company approving every decision.

Evidence, not the deck
Within the exclusivity window, agents read the target's code, software supply chain, runtime, infrastructure and licenses in their entirety; a human team covers a sample. What the software does, what depends on it, what it costs and what obligations attach to it are established from the estate itself, and every conclusion is traceable to the evidence behind it.
Priced for the investment committee
Every material finding arrives with remediation cost, run-rate upside and value at risk, tied to the revenue or process it sits under and netted against the model. The committee receives a position it can price, structure around or walk away from, not a color.
Cyber, technical debt, IP, savings and AI readiness, as one estate
The five workstreams that conventional diligence runs apart are one picture here, because the end-of-life component that is a vulnerability is also a piece of technical debt, a license obligation and a cost. Software and AI bills of materials, copyleft exposure, reachable vulnerabilities, duplicated platforms and the data's fitness for AI are assessed together and priced together.
Reports expire at signing. The graph does not.
The picture built in diligence becomes the value creation plan for a fund or the integration plan for an acquirer on the day the deal closes. Every priced finding is already a sequenced initiative, ordered by return and by the estate's actual dependencies, so the plan starts from evidence, without a second discovery.
Delivered, and measured where the fund measures it
After close, Axiarete's agents carry the plan through the operating company's own pipelines, approval gates and change calendar, with a named person approving each change: retiring what is duplicated, remediating what is exposed, modernizing what the plan depends on. Savings and risk removed are tracked into the run-rate where the fund measures them, through the hold, to exit.
For funds and for acquirers
A fund underwrites against a value plan and an exit, so upside and value at risk drive the price and the 100-day plan, and the same picture across portfolio companies lets an operating team run technology as a portfolio lever. A corporate acquirer underwrites against integration, so dependencies, duplicated platforms and data flows drive a plan that can be delivered without disrupting the business that was bought. The platform prices and delivers both.
AxiareteForge: execution capacity, delivered as a product
A value plan is only as good as the capacity to execute it, and portfolio companies rarely have it to spare. AxiareteForge addresses this as services-as-software: forward-deployed architects scope the plan against the live picture of the estate; forward-deployed engineers deliver alongside the agents from the first week after close. Nano sprints eliminate a class of risk, micro engagements capture the first-quarter run-rate wins, and long-term programs carry modernization and portfolio optimization through the hold.
Governed for the deal room
Diligence runs under the deal's NDA and clean-team arrangements, in a dedicated tenant per engagement, with access withdrawn if the deal does not proceed. Target code and data are never used to train models, every output is explainable and auditable, and after close a named person approves every change that touches the estate. Axiarete is SOC 2 Type II, ISO 27001 and ISO 42001 certified and HIPAA compliant. Read the governance model.

Proof: the work a fund needs done, already done inside operating companies

Results reported by Axiarete customers. Customer identities are withheld under NDA. See the full customer impact page. Each is the kind of finding a buyer would want before signing and the kind of outcome a value plan is built to deliver.

ReadThe whole estate's debt, exposure and cost in one picture, including the systems in no inventory.
PriceEvery finding as remediation cost, run-rate upside and value at risk, tied to the business it sits under.
DeliverAgents carry the plan through the company's change control; savings land in the P&L, not in a projection.
  • Fortune 500 semiconductor manufacturer

    Rationalization timelines reduced from years to weeks

    Modernization had stalled on missing documentation and scarce experts across roughly 500 systems. Axiarete rebuilt the application knowledge base, identified what to retire, consolidate and modernize, and validated each recommendation with the system owners.

    15%+savings impact across applications and infrastructure
    20%+of the portfolio confirmed for reduction
    250Kengineering hours delivered
    "In 3 months, Axiarete has given us a complete compass for how we want to govern, optimize and manage our 500 systems. This is game changing."Chief Architect, IT
  • Fortune 100 financial services

    Critical technical risk identified and remediated

    A decades-old legacy footprint carried critical risks conventional tools could not see. Axiarete surfaced them, tied each to its business consequence, and moved remediation from months to days.

    100+critical risks discovered and remediated
    50–80%less engineering effort per issue
    Daysnot months, from discovery to fix
    "What Axiarete has delivered in just 2 weeks, with very little effort from us, is truly incredible. We never had this level of intelligence in our portfolio — or the know-how to reduce technical debt."Enterprise Technical Debt Program Leader
  • Fortune 1000 property management

    One live view of the entire estate

    An application estate previously documented in static files and managed manually now operates from a single, continuously updated view of cost, health and risk.

    >5%cost savings inside the first three months
    10+structural improvements validated to cut incidents
    Full TCOvisibility, down to business function
  • State government

    Mainframe modernization: 80% faster, at half the cost

    Statutory programs still ran on COBOL, CICS and IMS, maintained by specialists the state had retired and re-engaged. Systems integrators quoted three to five years. Axiarete analyzed every program, business rule and data path, migrated four decades of records intact, and delivered a production-grade replacement.

    95%faster analysis across COBOL, CICS, IMS and BMC
    100%accuracy decoding features, functionality and business rules
    80%reduction in time to modernize

From letter of intent to exit: how the engagement runs

The engagement is scoped to the deal's timetable, not to a standard report. The following is the technology due diligence and value management process Axiarete runs with funds and acquirers, at the level of its four phases. Select a phase.

Diligence: read and price, inside the exclusivity window

Weeks 1 to 3

Under the deal's NDA and clean-team terms, agents read the target's code, supply chain, runtime, infrastructure and licenses in their entirety, and establish what the software does, what depends on it, what it costs and what is exposed.

Output: a complete picture of the target's estate, with every material finding priced and evidenced.

How to choose a technology due diligence provider in 2026

The best technology due diligence providers and platforms in 2026, whether they describe the work as tech DD, IT due diligence, cyber due diligence or technology risk assessment, share five traits: they read the target's estate itself rather than the deck and a sample; they price every finding as remediation cost, run-rate upside and value at risk; they assess cyber, technical debt, licensing, cost and AI readiness as one estate; they leave the buyer with a plan in motion rather than a filed report; and they can deliver that plan after close under the company's own change control. Advisor-led reviews and cyber assessments each address one or two. Axiarete AI was built around all five, and is increasingly evaluated by deal teams alongside, and in place of, both.

Ten questions to put to any technology due diligence provider, with the characteristics of a strong answer.

1How much of the target's code, dependencies and running estate will you actually read?

A strong answer: all of it that the target grants access to, within the window. A sample is an estimate of the estate; the material findings are usually outside the sample.

2Will your findings arrive as colors or as numbers?

A strong answer: as remediation cost, run-rate upside and value at risk for each material finding, with the evidence behind each, so the committee can net the technology against the model.

3Are cyber, technical debt, licensing, infrastructure cost and AI readiness assessed together or by separate teams?

A strong answer: together, as one estate, so the component that is at once a vulnerability, a debt, a license obligation and a cost is priced once and whole.

4Can you find what the target's management does not know about?

A strong answer: yes, because the estate is read, not described: the undocumented integration, the system in no inventory, the license that does not transfer.

5What remains the day after signing?

A strong answer: the value creation or integration plan, with every priced finding already a sequenced initiative, and the picture of the estate kept current. A filed report is not an adequate answer.

6Who executes the plan after close, and through whose change control?

A strong answer: agents and forward-deployed engineers, through the operating company's own pipelines and approval gates, with a named person approving each change.

7How are savings and risk removed measured?

A strong answer: tracked into the run-rate where the fund measures them, through the hold, rather than projected in the diligence report.

8How is the target's confidentiality protected, and what happens if the deal does not proceed?

A strong answer: a dedicated tenant per engagement under the deal's NDA and clean-team terms, no target code or data used for training, and access withdrawn at the end of the window.

9Can the same picture serve the exit?

A strong answer: yes: a current, evidence-based picture of the estate at exit is the technology story a buyer's own diligence will confirm rather than dispute.

10What is the AI's role: recommend, or act under approval? Is every action auditable?

A strong answer: in diligence, agents read and price and the committee decides; after close, agents act, a named person approves, and every action carries an explainable audit trail.

Technology diligence is the first page of the value creation plan

The value plan for a company acquired in 2026 will lean on technology whether or not the deal team intends it to: on the platform's ability to carry growth, on the run-rate that consolidation releases, on the risk that remediation removes, and increasingly on whether the estate is legible enough for AI to act on. None of that can be planned from a deck, and none of it should be discovered in month three.

This is why Axiarete treats the picture of the target's estate as the durable asset of a transaction and the diligence memo as one of its outputs. The same evidence that prices the deal sequences the plan, the same platform delivers the plan, and the same picture, kept current, is what the next buyer will find when it diligences the company in turn. A fund that underwrites, operates and exits on one set of evidence has removed the largest unpriced variable in the model.

Reports expire at signing. The graph does not.

Frequently asked questions about technology due diligence in private equity and M&A

What is technology due diligence?

Technology due diligence (tech due diligence, or tech DD) is the assessment of a target company's technology before a transaction: its architecture and scalability, code quality and technical debt, cybersecurity posture, software supply chain and open-source licensing, infrastructure and cloud cost, data and AI readiness, and the team that runs it. Its purpose is to tell the buyer what the technology is worth, what it will cost to fix, and what could go wrong, in time to change the price, the structure or the decision.

What is the difference between technology due diligence, IT due diligence and cyber due diligence?

IT due diligence traditionally covers the target's internal systems, vendors and IT organization. Technology due diligence adds the software the company sells or runs its business on: its code, architecture, dependencies and scalability. Cyber due diligence assesses vulnerabilities, security controls and evidence of past or ongoing compromise. In an agentic program the three are one picture, because they describe the same estate and their findings price the same deal.

What is AI-driven technology due diligence?

AI-driven technology due diligence uses AI agents to read the target's technology estate itself, its code, supply chain, runtime, infrastructure and licenses, in place of management presentations, data-room documents and a sample code review. Every finding is priced in the terms an investment committee uses: remediation cost, run-rate upside and value at risk. Axiarete AI operates this model for private equity funds and corporate acquirers, and after close the same picture becomes the value creation or integration plan, tracked to run-rate.

Can AI perform due diligence on a target's source code?

Yes, and it is the only way to cover the whole codebase instead of a sample. AI agents can read every repository the target grants access to, establish what the software actually does, locate technical debt, vulnerabilities and license obligations, and map dependencies and data flows, within a diligence window measured in weeks. Access is governed by the same clean-team, NDA and dedicated-tenant arrangements that apply to any diligence advisor, and no target code is used to train models.

What does technology due diligence cover for a software or technology-enabled company?

Six areas, priced together: architecture and scalability; code quality and technical debt; cybersecurity and vulnerabilities; software supply chain, intellectual property and open-source licensing, including copyleft exposure; infrastructure, cloud spend and run-rate cost; and data and AI readiness. A seventh, key-person and team dependency, is assessed alongside, because knowledge held by two engineers is a form of technical debt.

What should a technology due diligence checklist include?

A complete technology due diligence checklist covers seven areas: architecture and scalability against the growth the investment case assumes; code quality, technical debt and the cost to change; cybersecurity, including reachable vulnerabilities, missing controls and evidence of compromise; software supply chain, intellectual property and open-source licensing, with a current software bill of materials; infrastructure, cloud spend and run-rate cost; data and AI readiness, including the AI the target already ships; and key-person and team dependency. Each item should be priced as remediation cost, run-rate upside and value at risk, and the findings should be assessed together rather than by separate workstreams.

How do technology due diligence findings change a deal?

Priced findings translate into four instruments. A remediation cost with evidence supports a price adjustment, as a quality-of-earnings finding does. A value at risk that cannot be closed before signing supports structure: a specific indemnity, an escrow or holdback, or a negotiated position with the representations and warranties insurer, whose policy will exclude what diligence has already found. An exposure that can be closed supports a condition: remediation before close or within a defined period after. A run-rate upside supports the value creation plan. Findings that arrive as red, amber or green support none of these, which is why conventional technology due diligence so rarely moves the price.

What is AI due diligence in an acquisition?

AI due diligence assesses the AI a target already uses or sells and the estate's readiness for AI. For the AI it ships: which models and providers it depends on, on what commercial and data terms, what governance and audit trail exist, and how much of the AI capability described in the management presentation exists in the code. For readiness: whether the data is usable, the integrations reliable and the estate legible enough for agents to act on it. After the AI-driven correction in software valuations Bain recorded in the first half of 2026, this has become a standard investment committee question, and it can only be answered from the estate itself.

Does Axiarete support sell-side or vendor technology due diligence?

Yes. A sponsor preparing an exit, or a corporate preparing a carve-out, can commission the same evidence-based picture a buyer will demand: the estate read whole, findings priced, and the entanglements that decide transition service agreements mapped in advance. For a portfolio company already operating on the platform, the exit picture is current by construction, not assembled for the process.

How long does technology due diligence take?

Advisor-led technology due diligence typically runs two to four weeks and reviews a sample of the code, a data room and a set of management interviews. An agentic approach reads the whole estate in the same window or less, with a priced findings memo available to the investment committee inside the exclusivity period, and continues after signing rather than expiring at it.

How is technical debt valued in an acquisition?

Technical debt is valued the way an investment committee values any liability: as a remediation cost, as a drag on the earnings growth the case depends on, and as value at risk if it causes an outage, a breach or a failed integration. McKinsey's survey of CIOs put technical debt at 20 to 40 percent of the value of the technology estate; in a deal, the question is which of that debt sits under the revenue the buyer is paying for, and what it will cost to remove.

What is cyber due diligence in M&A, and why does it matter?

Cyber due diligence assesses the target's vulnerabilities, security controls and any evidence of past or ongoing compromise, because the buyer inherits all of it at close. Forescout's 2019 survey of more than 2,700 IT and business decision makers found 53% had encountered a critical cybersecurity issue during a deal that put it in jeopardy, and 65% reported buyer's remorse over security concerns inherited with the purchase. Verizon cut its price for Yahoo by $350 million after breach disclosures; Marriott was fined by the UK regulator over a compromise that had been running inside Starwood since before Marriott bought it.

What is open-source and licensing risk in a technology acquisition?

Most commercial software is largely open source, and some open-source licenses (copyleft licenses such as the GPL) impose obligations that can reach the target's proprietary code. Black Duck's 2025 analysis found 86% of commercial codebases contained vulnerable open-source components. A buyer needs a current software bill of materials, the license of every component, and an assessment of which obligations attach to the product being acquired, before the IP is valued.

How does technology due diligence connect to the value creation plan?

In a conventional process it does not: the diligence report is filed at signing and the value creation plan is built separately after close, often rediscovering what diligence found. In an agentic program the picture of the estate built during diligence is the value creation plan's first page, with every priced finding becoming a sequenced initiative, and the same platform measures the plan's impact through the hold period to exit.

What is post-merger technology integration, and why does it fail?

Post-merger technology integration is the work of combining an acquired company's systems, data and applications with the acquirer's. It fails when the integration plan is built from what the target's management described instead of what the estate contains: the undocumented integration, the duplicated platform, the license that does not transfer. An evidence-based picture of both estates, built before close, is what allows integration to be sequenced by dependency and delivered without disrupting the business the buyer paid for.

How does technology due diligence differ for private equity and corporate M&A?

The questions are the same; the use of the answers differs. A fund underwrites the technology against a value creation plan and an exit, so run-rate upside and value at risk drive the price and the 100-day plan. A corporate acquirer underwrites against integration, so dependencies, duplicated platforms and data flows drive the plan. Axiarete prices the findings for both and carries them past close: value creation tracked to run-rate for a fund, integration sequenced by dependency for an acquirer.

How does Axiarete protect target confidentiality during diligence?

Diligence access runs under the deal's NDA and clean-team arrangements. Each engagement runs in a dedicated tenant, target code and data are never used to train models, every output is explainable and auditable, and access is withdrawn at the end of the diligence window if the deal does not proceed. Axiarete is SOC 2 Type II, ISO 27001 and ISO 42001 certified and HIPAA compliant.

How do we start with Axiarete on a live deal?

Engagements are scoped to the deal's timetable. Within the exclusivity window, Axiarete reads the target's estate and delivers a priced findings memo for the investment committee: value at risk, remediation cost and run-rate upside, with the evidence behind each. After close, the same picture becomes the value creation or integration plan, and its impact is measured through the hold. Request a confidential conversation at info@axiarete.ai.

Underwrite the next dealon evidence.

Bring a live process, or the last one that surprised you in month three. Within the exclusivity window Axiarete reads the target's estate and returns a priced position for the investment committee; after close, the same picture becomes the plan, and the plan is tracked to run-rate.

What a first conversation covers

  • How the diligence window is scoped to the deal's timetable, and what access is required under NDA and clean-team terms
  • What the priced findings memo contains: value at risk, remediation cost and run-rate upside, with evidence
  • How the picture becomes the value creation or integration plan on day one, and how its impact is measured through the hold
  • The security package: SOC 2 Type II, ISO 27001, ISO 42001, tenancy and data handling for deal work