Now scanning · 14 repos · acme-robotics42 contributors · 180k LOC4 critical · 7 high · 23 mediumReport DD-2026-04-18 · Rev 1.0Now scanning · 14 repos · acme-robotics42 contributors · 180k LOC4 critical · 7 high · 23 mediumReport DD-2026-04-18 · Rev 1.0
▚ Technical Due Diligence · AI-assisted · Human-verified

Read the code
before you sign the term sheet.

Subsystems gives investors a full technical picture — codebase health, architectural risk, and organizational fragility — in 72 hours. Every finding is cited to a file, a commit, a person.

Turnaround
72 hrs
Median repos
14
Findings cited
100%
FIG. 01 · Service topology
Live scan
auth-svcapi-gwpayments*queuelegacy-db*cdncacheworkermetrics
10 nodes · 12 edges2 risk paths detected
§ 01 — The scan

We read every line, so you don't have to.

Before a human writes a word of the report, our scanners traverse the full repo graph — static analysis, dependency audit, authorship heatmap, test inspection. What you're about to see runs in real time on every engagement.

subsystems ▸ scan ▸ acme-robotics● running · 00:02:41
§ 02 — How it works

Three days from NDA to final report.

You hand us a repo URL. We hand back a signed PDF and a 60-minute read-out with your deal team. No portal logins, no “AI insights” dashboards.

day 0–1
01

Scope & access

NDA, repo access, target-contact intro. Scope is fixed at the start — no surprise line items.

day 1–2
02

Scan & verify

AI agents map the code graph, surface findings, and draft evidence. A senior engineer verifies every critical before it lands in the report.

day 3
03

Read-out & deliverable

Live 60-minute session with your deal team, followed by a signed PDF, raw data export, and a Q&A window through close.

§ 03 — Outside-in

Meet subsurface.
Our OSINT scanner for what's already leaking.

Before we touch the repo, subsurface maps what the internet already knows about the target. Leaked credentials, exposed endpoints, forgotten subdomains, SBOM matches against public CVE feeds, employees pasting proprietary code into public gists. What an attacker would find in an afternoon — we find in ten minutes.

▚ subsurface · v2.4target: acme.ioscan · 09:42:18 UTC● liveinternaledgepublic
leaked key · AWS
s3 bucket · public read
staging.acme.io
sbom · clean
gist · prod config
subdomain · forgotten
Live · 14 of 14 layers · 2m 41s
Exposure, before the NDA ink dries.

subsurface runs in parallel with the code review. It probes 14 public layers — DNS, cert transparency, code hosting, paste sites, container registries, leaked credential dumps — and weights each hit against its blast radius inside the target's stack.

SSF-0114AWS access key in public gist · 4 mo old · still validcrit
SSF-0098S3 bucket with prod backups · world-readablecrit
SSF-0071Forgotten staging-2021.acme.io · exposes unauth adminhigh
SSF-006612 employee emails in HaveIBeenPwned · same-password riskhigh
SSF-0042SBOM scan · 180 deps · 0 critical CVEspass
Layers probed
14
Hits
37
Critical
3
Scan time
2:41
§ 04 — The deliverable

A report you can put in front of an investment committee.

Every finding is cited. Every verdict is one sentence. Hover the sample to see what a critical finding looks like in context.

subsystems · Acme RoboticsDD-2026-04-18
The codebase is ship-worthy.
The org is not.
Evidence-based review of codebase health, architectural risk, and organizational fragility across 14 repositories and 42 contributors.
FDG-0031Circular dep: billing ↔ authcrit
FDG-0019Bus-factor = 2 on platformcrit
FDG-0042Unpinned pg client · CVEhigh
FDG-0058No test coverage · workershigh
FDG-0031 · Critical · payments/

Circular dependency across billing and auth

Blocks clean extraction of billing as an independent service. Price 2–3 engineer-weeks into the transition SOW.

What's inside

A document, not a dashboard.

Delivered as a signed PDF your partners can read on a plane. Citations link back to raw evidence — commits, files, authorship graphs — for anyone who wants to dig.

  • 01Executive summary with composite score and verdict
  • 02Architecture overview with full service topology
  • 03Findings: critical → low, each with evidence and price-in
  • 04Organizational health: bus factor, commit concentration
  • 05Action matrix and signed sign-off
§ 05 — The framework · EVOFIT v0.3.1ALPHA

Fitness is a trajectory, not a snapshot.

EVOFIT scores a company as an evolving system. Five dimensions derived from Wong et al.'s three modes of selection (PNAS 2023). Not a checklist — an assessment of whether the producing mechanism is strengthening or decaying.

▚ Evolutionary Fitness · Acme RoboticsSeries B · 74 / 100
Archetype
Coral
maturing from Vapor → drift toward Organism
Selection signature · trajectory-weighted
C · 25R · 30A · 45 ★
ΔC +2 · ΔR +3 · ΔA +10
Prognosis · 12 mo
▲ ACCELERATING
Five dimensions · derived from Wong et al.
Capability1st-order · static persistence
Validated configurations that resist decay. What still works if everyone takes two weeks off.
Resilience2nd · dynamic persistence
Dissipation · autocatalysis · homeostasis · information processing.
Adaptability3rd · novelty generation
New functions that did not previously exist. Structural optionality preserved for the next.
Engineleading indicator
The generative mechanism. Team, tooling, practices, leadership, AI maturity.
Extinctionenvironmental gate
CLEAR / ELEVATED / CRITICAL. The asteroid does not care about your functional information.
Wong et al., PNAS 120(43), 2023 · “On the roles of function and selection in evolving systems”
Scored against the investor fitness function. ALPHA — pending validation against ≥3 engagements.
§ 06 — What we check

Six lenses. One opinion.

We don't hand you a spreadsheet of 400 metrics. We surface what's material to the deal — and tell you what to do about it.

Code quality

Complexity, duplication, type coverage, linter debt. Weighted against the codebase's language and age.

Architecture

Service topology, import cycles, coupling, fan-in/out, and the unphysical connections nobody drew on a whiteboard.

Test discipline

Coverage in the paths that matter, not global averages. Flakiness, CI health, mutation-test viability.

Dependencies

Stale deps, vulnerabilities, unmaintained upstreams, supply-chain exposure. Pinned by severity, not count.

Org & process

Bus factor, commit concentration, PR hygiene, review latency, on-call load, documented runbooks.

Security posture

Secrets, auth boundaries, SBOM, OWASP exposure. We read your security docs, then verify them against the code.

They caught a hidden cycle in the payments layer that would have cost us the first two quarters post-close. Repriced the deal by 4%. Paid for itself eight times over.
Rachel Ortiz
Partner · Northfield Capital
Engagement · NFC-0087
Repos scanned22
Turnaround68 hrs
Critical findings6
Price adjustment−4%
§ 07 — FAQ

Questions investors ask.

If yours isn't here, ask it during the intro call — we'll tell you honestly whether we're the right fit.

01Do you need the target's cooperation?+

Ideally yes — read-only repo access, a 30-min call with an engineering lead, and docs access. Where the seller is cautious, we've run productive engagements on repo access alone. We won't proceed on screenshots.

02How is this different from a traditional technical DD firm?+

Speed and citability. Traditional DD takes 3–6 weeks and delivers a narrative. We take 72 hours and deliver evidence — every claim traces to a file, a commit, or a contributor.

03What languages and stacks do you cover?+

TypeScript, JavaScript, Python, Go, Rust, Ruby, Java, Kotlin, Swift, C#. If your target is 90% COBOL, we'll tell you at intake.

04Is the AI actually writing the verdict?+

No. AI agents do the traversal, evidence gathering, and first-pass findings. A senior engineer reviews, verifies, and writes the verdict. Every critical finding is signed off by a named human.

05What does it cost?+

Fixed fee per engagement, scaled to codebase size. Typical deal sits between $18k and $60k. We publish the scope and price before you sign.

▚ Ready when you are

Sign the term sheet with eyes open.

Intro call is free. 72-hour turnaround if you're under contract pressure. We'll tell you on the first call whether we can help.

Book a diligence engagement See sample report