Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What do investors look for in technical due diligence?
Last verifiedInvestors look for scalable architecture, a team that is not a single point of failure, honest quality and security evidence, and a roadmap that matches the codebase. Red flags include fake certifications and missing denominators. This page is not investment advice and not legal advice.
Investor technical diligence, last verified 10 September 2026 against ISO/IEC 25010 quality dimensions, NIST CSF 2.0 for the security slice, and descriptive institutional-investor diligence outlines (not a ranking). Not investment advice. Not legal advice.
Investor lens, not a score
Audience: a founder raising capital. This page is not investment advice and not legal advice. Kind of text: ISO/IEC 25010 is a quality model. NIST CSF 2.0 is guidance. VC and growth-equity process notes are industry practice, cited descriptively — never a ranked list of firms. ShipReady Metrics recommendation: show measured posture (readiness score, Passport, DORA, per-committer metering) with denominators, not a highlight reel.
Green flags versus red flags
Last verified 10 September 2026. Not a buy/sell recommendation. Not investment advice.
| Theme | Green flag | Red flag |
|---|---|---|
| Scale story | Measured capacity and cost-to-serve with a test date. | Slide-only “infinitely scalable” with no load evidence. |
| Bus-factor | Named backups for every critical system; documented leave cover. | One person who “is the architecture.” |
| Quality | CI gates, known hotspots, and a debt list with owners. | No tests and a claim that “we move too fast for process.” |
| Security / compliance | Current evidence, scoped attestations, honest gaps. | Logo without a report; expired ISO; invented statistics. |
| Roadmap | Roadmap items that match the repo and staffing. | A roadmap that requires a team you have not hired. |
VC growth-equity versus strategic acquirer
Growth-equity and venture diligence usually optimize for whether the product can grow without collapsing under load or key-person risk. A strategic acquirer also asks how the stack will integrate, what must be rewritten, and what security debt they inherit on day one. Same checklist, different weight. Neither lens is a recommendation to take a particular check. Not investment advice.
Artifacts investors commonly request
Examples, not a mandatory list: architecture pack, access to a read-only metrics export, last incident review, SBOM, SOC 2 report or an honest “we do not have one,” engineering org chart, and a readiness report. Open the preparation and readiness-report pages on this site.
What to do now
Operational steps. Last verified 10 September 2026. Not investment advice. Not legal advice.
- Walk the green/red table with the CTO and strike any row you cannot evidence.
- Prepare the artifact list before the first data-room grant.
- If you already have a session: readiness score (A–E), Passport, DORA metrics, and per-committer metering are shareable facts — not a valuation.
Checklist
Question list. Not investment advice.
- Can every metric quote a denominator and a date?
- Is bus-factor documented without hero narratives?
- Have we separated VC growth questions from strategic-integration questions?
- Is anyone about to send a logo without the underlying report?
Where this shows up in ShipReady Metrics
Readiness score and A–E ratings, ShipReady Passport, DORA engineering metrics, and per-committer metering. The product does not give investment advice and does not predict a term sheet.
Primary sources (last verified 10 September 2026)
ISO/IEC 25010. NIST CSF 2.0. Institutional diligence outlines cited descriptively, not ranked. Not investment advice.