Skip to main content
Kompella Technologies

Technical Due Diligence · PE, VC & Family Offices · $8,000–$60,000

Technical due diligence that changes the price, or the decision

An independent read on whether the technology does what the company says, what it will cost to keep working through the hold period, and which findings should move the number. Every finding carries an engineer-weeks cost, because a finding without a cost is an opinion.

Technical due diligence is an independent assessment of a target company's technology, engineering organisation and technical risk, produced for an investor before capital is committed. It answers three questions: does the technology do what the company says it does, what will it cost to keep it working through the hold period, and which technical facts should change the price or the decision. Typical engagements run 5 to 15 working days and $8,000 to $60,000 depending on deal size.

Three Contexts

The same words, three different jobs.

Running one checklist across all three is the most common way diligence produces a thorough-looking document that does not help anyone decide anything.

Pre-close diligence for private equity

A buyout target has a running system, paying customers and a maintenance history, so the work is an audit with a valuation consequence. The output is a remediation plan with costs attached and a clear statement of which findings are pricing issues and which are walk-away issues.

  • Architecture and its actual scaling ceiling under the growth case in the model
  • Engineering cost base, and how much of it is servicing debt rather than building
  • Security and compliance posture against the sector's real regulatory floor
  • Key-person concentration and what the handover actually looks like
Private equity CTO

Venture-stage technical diligence

There is usually a prototype, a roadmap and a handful of engineers. You are underwriting a team's ability to build something that does not exist yet, not auditing an asset that does. Scoring the artifact here produces a report that reads well and predicts nothing.

  • Whether this specific team can produce the artifact on the capital being offered
  • The point at which the current design stops working, and whether the cost of passing it sits inside the round
  • Sector depth for crypto and AI infrastructure: token design, custody, inference economics, eval infrastructure
  • Data rights and provenance, which is where AI deals most often fail a customer's legal review
Venture capital CTO

Family-office direct investment diligence

A family investing directly rather than through a fund has no investment committee to absorb a technical mistake and usually no in-house technologist. The work is closer to venture diligence, but the reporting has to be legible to people who are not engineers and who will hold the position for a decade rather than a fund life.

  • Plain-language risk framing that a principal can act on without an interpreter
  • Concentration risk across the family's other holdings, which a fund would not consider
  • Realistic hold-period technology cost, not just the cost to close
  • Whether the family can monitor this position after the wire, and what that requires
Family office CTO

The Deliverable

What the report actually contains.

01

Investment-relevant summary

One page, written for the decision-maker rather than the engineer. States the recommendation, the two or three findings that drive it, and what would change the answer. If this page cannot be read on its own, the report has failed.

02

Architecture and scaling assessment

What the system is, where it stops working, and what it costs to get past that point. Includes the specific load at which the current design breaks rather than an adjective about scalability.

03

Code and delivery health

Test coverage where it matters, deployment frequency, rollback capability, and whether the team can ship on a Friday. Read the error paths before the happy paths, because that is where the unhandled cases are buried.

04

Security, data and compliance

Access control, secrets handling, dependency and supply-chain exposure, and the gap between the compliance posture claimed in the data room and the one visible in the repository.

05

Team and key-person analysis

Who the outcome actually depends on, what happens if each of them leaves, and whether the organisation could absorb it. Named by role, never by a claim about an individual's performance.

06

Remediation plan with costs

Every finding carries an estimated engineer-weeks figure and a recommended sequence. A finding without a cost is an opinion, and an opinion does not belong in a valuation conversation.

Timeline

A ten-day engagement, in order.

The binding constraint is access to the target's engineers, not analysis time. Booking those interviews on day zero compresses the calendar more than anything else you can do.

Day 0

Scope and access

Mandate check for conflicts, data-room and repository access, and agreement on which questions the report must answer.

Days 1–3

System and code review

Architecture, repository, delivery pipeline, dependency surface, and the infrastructure bill.

Days 3–6

Team interviews

Sessions with the technical leadership and, where the deal allows, two or three engineers who are not in leadership. The gap between those two accounts is usually the finding.

Days 6–9

Draft and challenge

Draft circulated to the deal team, with findings pressure-tested against the model's growth case before anything is finalised.

Day 10

Final report

Delivered with a live walkthrough. Follow-up questions for two weeks afterwards are included rather than billed.

Pricing

Priced by deal size, fixed at scope.

Fixed at scope rather than hourly, so a finding that takes longer to chase does not turn into an invoice conversation halfway through.

Under $5M

$8,000 – $15,000

Typically venture-stage or a small direct investment. 5 to 7 working days.

$5M – $25M

$15,000 – $30,000

The common band for growth deals and family-office direct investments. 7 to 10 working days.

$25M – $100M

$30,000 – $60,000

Buyout diligence with a remediation plan and valuation-relevant findings. 10 to 15 working days.

Above $100M

Scoped per deal

Usually multi-entity or multi-jurisdiction, and usually alongside a commercial diligence workstream.

Red Flags

What actually counts as a red flag.

Not messy code. Every company that has shipped anything has messy code somewhere. These are the findings that change a decision.

Nobody can explain a tradeoff they lost sleep over

A technical leader who describes only successes has either not made hard calls or is not telling you about them. Both are a problem. The strongest signal in any diligence interview is a specific decision the team regrets and can articulate precisely.

The compliance posture lives in the data room and nowhere else

A SOC 2 report with no corresponding access controls in the repository is a document, not a control. This gap is common and it is always more expensive to close after the deal than the seller implies.

A claimed capability that turns out to be a roadmap item

Rarely a lie, usually a demo shown often enough that everyone forgot it was a prototype. It reprices deals more often than it kills them, but only if diligence catches it before close.

No evaluation infrastructure on an AI product

A company shipping model changes without an eval set cannot tell when quality regresses and will learn about it from a customer. In an AI deal this is the single most predictive negative finding.

The infrastructure bill grows faster than revenue

Check unit economics at ten times current volume rather than at current volume. A material number of AI-era companies are gross-margin negative at scale, and the deck shows the margin at demo scale.

One person, no documentation, no successor

Key-person risk is normal in small companies and is not automatically a red flag. It becomes one when nobody has priced what happens if that person leaves during the hold period.

The longer checklist version of this lives in the technical due diligence checklist.

FAQ

What investors ask before engaging.

An independent assessment of a target company's technology, engineering organisation and technical risk, produced for an investor before capital is committed. It answers three questions: does the technology do what the company says it does, what will it cost to keep it working through the hold period, and which technical facts should change the price or the decision. It is distinct from a security audit, which examines controls, and from a code review, which examines quality without an investment consequence.
Typically 5 to 15 working days depending on deal size. A venture-stage review runs 5 to 7 days, a growth or family-office direct investment 7 to 10, and buyout diligence with a costed remediation plan 10 to 15. The binding constraint is almost always access to the target's engineers rather than analysis time, so booking those interviews early compresses the calendar more than anything else.
Priced by deal size and complexity: $8,000 to $15,000 under $5M, $15,000 to $30,000 for $5M to $25M, and $30,000 to $60,000 for $25M to $100M. Deals above $100M are scoped individually, since they are usually multi-entity or multi-jurisdiction. Pricing is fixed at scope rather than hourly, so a finding that takes longer to chase does not become an invoice conversation.
A one-page investment-relevant summary written for the decision-maker, then architecture and scaling assessment, code and delivery health, security and data posture, team and key-person analysis, and a remediation plan where every finding carries an estimated engineer-weeks cost and a recommended sequence. A finding without a cost attached is an opinion, and an opinion does not belong in a valuation conversation.
Yes to the NDA, and conflicts are checked before any material is shared. Tykhe Ventures deploys into blockchain and Web3 infrastructure globally and AI-first companies in India, so a diligence request inside either mandate is declined in writing up front. Where the mandates do not overlap, having deployed capital in these sectors is the reason to hire rather than a problem to manage.
Often, and the honest answer depends on the deal. The general engineering questions, delivery health, key-person risk, cost base, security posture, transfer across sectors well. The sector-specific questions do not, and in crypto and AI infrastructure those are usually the ones that decide the deal. If a target sits far outside that depth and the sector-specific risk is the crux, the useful answer is to say so rather than to produce a competent-looking report about the parts that are easy to assess.

Have a deal that needs a technical read?

Thirty minutes, no pitch. Conflicts are checked before anything is shared, and if the deal sits inside a Tykhe mandate I will say so and decline.