We find the money hiding in the code.

Buy-side technical diligence for software acquisitions of $5 million and up. Evidence-grade findings drawn from the codebase, its full history, and its supply chain — each paired with the deal mechanism it justifies.

Flat $15,000Ten business days

Proof

Proven findings move terms in your favor.

Vlerick M&A Monitor 2026 — 158 M&A specialists, Belgian market, surveyed January–February 2026: final price came in below the initial offer in 49% of transactions, up from 27% a decade ago — a shift the researchers attribute in part to stronger due diligence.

Run the math: a $15,000 instrument against a transaction of $5 million and up. One confirmed finding that moves the price a fraction of a point pays for the report several times over — and every finding left buried is value that closes in the seller's column.

When findings don't move price, they move structure: escrow sizing, indemnity scope, closing conditions. And when they're serious enough, they end deals — diligence findings are the single largest cause of collapsed letters of intent.*

What we find, we prove. What we prove, you take to the table.

For a buyer who wants control of the deal, in-depth technical diligence isn't an option; it's a necessity in today's changed code-authoring environment.

* Axial Dead Deal Report 2025, 75 lower-middle-market transactions.


The problem

Every seller's asset gleams. Polish is free now.

A software product performs identically in every test you can run from the outside — whether the backend is secure or wide open, whether the architecture scales to the growth you're underwriting or folds under it, whether the code is crafted or held together by accident. The flaws that cost you money after close rarely surface in use. AI raised the surface quality of everything, which means the surface now tells you nothing about what you're buying.

And what sits beneath the surface has changed more in three years than in the previous twenty.

Three people and a model now ship the surface area of thirty.

Model-written code fails in characteristic ways: endpoints that run fine with no authorization behind them, credentials committed where anyone with history access can read them, injection flaws the industry spent twenty years learning to avoid, dependencies that import someone else's vulnerabilities — and design-level gaps no scanner catches, wrapped in code that looks right.

The flaws also moved up a level. Research on AI-assisted development at Fortune 50 enterprises found syntax and logic errors falling sharply while design-level security flaws grew 153%.* Out of the lines, into the architecture. Scanners read lines.

By 2026, asking how much of a codebase a model wrote answers nothing; nearly all of it is model-touched. The decision-relevant question is narrower: where does model-written code sit on the surfaces you're buying — and whose license came with it.

That question is what the AI Tech Report is built to answer.

* Apiiro, research on AI-assisted development at Fortune 50 enterprises, 2025.


The product

The AI Tech Report (AITR)

$15,000 flat10 business days

Buy-side technical diligence for software acquisitions of $5 million and up. Runs parallel to your QoE — same window, same order of magnitude, the code side of the same question.

We assess the target's codebase, repository history, supply chain, and team dependencies across four evidence bases, verify what we can reproduce, and deliver a deal instrument.

The AITR leads with our recommendation: a scored assessment of the asset's condition and what it means for your transaction — the full continuum from clean and ready, through price for repair, to not production-grade, with the reasoning behind every point on it. Behind it, every material finding is paired with the lever it justifies at the table, and every finding carries its confirmation status on its face.

The recommendation

The asset's condition, scored, with reasoning and remediation.

Deal levers

Every material finding paired with the deal mechanism it justifies — escrow, indemnity, closing condition, price — or no action, on the record.

Confirmation status on every finding

Every finding is reproduced by an independent method or labeled unconfirmed on its face, with a recommended treatment attached — a serious unconfirmed finding arrives at the table as a closing condition. Clean surfaces are documented as clean: a quiet report is certainty, not silence.

Insurance-aware findings

Confirmed findings on surfaces your RWI policy excludes carry that coverage gap as their stated deal mechanism. Uninsured exposure priced as uninsured exposure.

AI provenance on critical surfaces

A map, not a percentage. Where model-written code with no human revision sits on the surfaces that carry your value case — auth, data handling, payments, the integration path.

Copied-code license exposure

Sometimes a target's code wasn't written at all — it was copied wholesale, license included. We detect public-corpus overlap carrying a foreign license in-file, beyond declared dependencies, and state the facts for your counsel's determination.

Security and supply chain

Authentication, data handling, secrets across full repository history, transitive CVEs, malicious-dependency matching, infrastructure-as-code misconfiguration.

Repository history forensics

Rewritten-history detection, commit-signature census, mailmap-corrected key-person and truck-factor analysis, change-coupling architecture drift. Honest history raises confidence in every other history-derived number in the report.

Architecture review

Structure, measured technical debt against published thresholds, scaling readiness.

Model-dependence assessment

Measured, not asserted: dependency-catalog analysis, portability, and a calibrated prompt-replaceability assessment. Will the next model release eliminate the need for this product?

Remediation anchored to measured pace

Fix sizes in engineer-week bands, timed against the incumbent team's demonstrated velocity, measured from repository history. Effort bands are committed by a named person.

IC-ready and lender-ready summaries, and the 100-day plan

Shaped for your committee and your lender. What to address at close, with scope and a documented timeline.

Escrow-Window Verification

$7,500 flat add-on for deals where we ran the initial AITR.

Before your indemnity window closes, we re-run the instrument on the current codebase and deliver a delta report: what held, what changed, and where the represented technical state diverged — scored on the same rubric as your original AITR, formatted for your counsel, in hand while your claim rights are live.


Discipline

An opinion is one thing. An instrument is another.

Anyone can produce an opinion about a codebase. What a committee, a lender, and an underwriter can put to work is different: a fixed rubric applied the same way on every deal, findings reproduced by an independent method before they are called confirmed, confirmations bound to the named person who made them, and every gap we could not measure disclosed as a gap rather than passed over.

Here is what it looks like in practice.

01

Confirmed means reproduced.

A finding is confirmed only when an independent method reproduces it in a sandboxed environment. Everything else is visibly labeled unconfirmed. Nothing renders quietly.

02

Every measurement is sourced.

Each finding is labeled measured by us or subject-attested, verified by us. Where the best available tool is license-restricted, the target runs it on their own code and we verify provenance — commit SHA, tool version, query pack — and stand behind the output.

03

Coverage is layered, and gaps are named.

No single pass reads everything. We run static analysis and supply-chain depth, repository history, provenance, and reproduction as separate evidence bases, and anything we could not measure is disclosed on the coverage strip rather than omitted.

04

Findings are weighted to your thesis.

Relevance is drafted from your intake posture and confirmed by a named senior reviewer, so every finding lands at the weight it carries for your deal — and only that weight.

05

Findings state facts, not verdicts.

Every finding is a neutral statement of fact with evidence attached and a pointer to reproduce it. May be, never is. License facts are stated; the determination is counsel's.

06

Scope is set before we start.

Every engagement opens with a tiered artifact request and a deal-context questionnaire: what you're buying, how the product is used and distributed, and what your value case depends on. If the target won't provide something, we exclude it or caveat it explicitly. We don't reprice for missing artifacts — and what the seller declines to produce is itself recorded as a finding.

07

The seller's code stays sealed.

Analysis runs in the seller's GitHub or a controlled mirror. Code in, findings out. No client code is retained; what carries forward between engagements is a code-free pattern signature. Nothing trains a model. We sign the data-handling terms the seller's counsel requires.

08

You get it inside your exclusivity window.

Traditional technical diligence runs two to three weeks. We hold ten business days, fixed scope, parallel to QoE. Deal clocks are real; we run on them, without lowering the bar the report has to clear. We take a limited number of engagements each month so every one ships on time.


Who it's for

Built for buyers who do this more than once.

We work for buyers. Never sellers.

The pledge is permanent and structural: we do not enter seller data rooms, and we do not take sell-side work at any price.

For acquirers running a pipeline — platform builds, roll-ups, corporate development at $5 million and up — that permanence compounds: fixed price on every deal, the same instrument every time, findings you can compare across your pipeline.


Who we are

Operators who've sat in your chair.

Big Lever AI is a product of Big Lever Ventures, a venture studio building in software for two decades. The studio's record runs through $100M+ raised and six portfolio exits. Engagements are signed by Big Lever Ventures and run point under senior operators — people who have run diligence, commissioned diligence, and prepared companies to survive it.

Our own AI-native products are live in production today, built with the same models and tools as the codebases we review. We know where AI cuts corners because we stop it from cutting ours every day.

Every engagement sharpens the instrument. Findings that hold up at the table become calibration for the next deal's rubric — which is why the same $15,000 buys a better AITR each quarter than it did the last.


“Give me a lever long enough and a fulcrum on which to place it, and I shall move the world.”
— Archimedes

Ready to move the price?