£7,500. Five working days.
Red Flag Review
A fast technology screen before you take a deal to committee. We look for the things that kill a deal or reprice it, and we tell you which they are, in time for it to matter.
BOOK A DUE DILIGENCE CALL
What it is
The Red Flag Review is a short, senior technology screen run early in a deal, before you have committed real money or real time to it.
It is not a full assessment and it does not pretend to be.
It answers one question: is there anything in this target's technology that should stop you, change your price, or change your structure? If the answer is no, you proceed with confidence and a clear record of why. If the answer is yes, you have found it in week one rather than week five.
A CTO and, where security is material, a CISO spend five working days with the target's technology. They come back with the five risks that matter, ranked, and a view you can take into an investment committee.
When to use it
Take the Red Flag Review when the deal is early, competitive, or uncertain.
It fits a pre-IC screen where you need a technology view in the papers but a full diligence spend is not yet justified.
It fits a competitive process where timelines are compressed and you need to move before a fuller assessment could finish. It fits a pipeline where you are looking at several targets and cannot commission full diligence on all of them. And it fits any deal where your instinct says something is off and you want that instinct tested cheaply before you spend more.
If the deal is already live and heading to completion, you probably want the Standard Technology DD instead.
If you will own the technology outcome from day one, look at DD Plus 100-Day Plan.
What we look at
Five days is not long, so we spend it on the things most likely to change your decision rather than trying to cover everything shallowly.
- Architecture at headline level. Is the platform built on something that will take the growth in the deal thesis, or is there a rebuild hiding behind the projections? We are looking for structural problems, not a full architectural review.
- Security and compliance exposure. Is there anything that transfers to you as a liability? Unpatched or unsupported systems, obvious gaps in access control, personal data handled in ways that would not survive scrutiny, certifications claimed but not held.
- Key-person concentration. Does the engineering capability sit with the business, or with two people who may leave the moment the deal completes? This is one of the most common repricing findings and one of the fastest to establish.
- Delivery credibility. Has the team historically shipped what it said it would ship? A quick read on the gap between roadmap and track record tells you a great deal about the plan you are being sold.
- Anything the data room is quiet about. Often the most useful finding is an absence. No architecture documentation, no incident history, no test coverage, no disaster recovery evidence. We flag what is missing as well as what is there.
What you receive
A short written report, usually five to eight pages, containing:
- The top five technology risks, ranked by materiality to the deal
- A clear view: go, no go, or proceed with conditions
- For each risk, an indication of whether it is a price issue, a structure issue, or a walk-away issue
- What we could not establish in the time available, stated plainly
- A recommendation on whether fuller diligence is warranted, including where it should focus
Plus a thirty minute debrief with the deal team, where you can ask the questions the report will not have anticipated.
The report is written for investors. It assumes you are commercially fluent and technically not, and it does not hide behind jargon.
Three ways to buy it
Fixed prices, published, no hourly rates. You know what the work costs and what you get before you commission it, which is more than most of the deal process will offer you.
How the week runs
Day one. Scoping call and data room access. We agree what matters most for this deal so the five days are spent in the right places.
Days two and three. Assessment. Documentation review, and where access allows, a technical session with the target's senior engineer or CTO. We are candid with them about what we are doing, which usually produces better information than a guarded process.
Day four. Analysis and drafting. Findings ranked, risks characterised as price, structure, or walk away.
Day five. Report delivered, debrief held. You have it in hand for your committee.
Where a target is slow with access, we tell you on day two rather than day five, so you can chase it or accept a narrower scope with your eyes open.
Who it is for
- Private equity and venture capital teams screening ahead of investment committee.
- Corporate development teams triaging a pipeline.
- Corporate finance advisers who need a technology view to put in front of a client quickly.
- Any buyer in a competitive process where the timeline does not permit more.
What it does not cover
Being clear about this matters more than selling you the next tier up.
The Red Flag Review does not quantify technical debt, does not assess the engineering team's capability beyond key-person risk, does not review the codebase in any depth, does not establish run-rate technology cost, and does not give you a remediation plan. It gives you headline reads on architecture and security, not full assessments of either.
If you need those things, the Standard Technology DD covers all of them at £22,000 over two to three weeks.
Frequently asked questions
What is a red flag review in due diligence?
Is five days really enough?
What if you find something serious?
Can we upgrade to a full DD afterwards?
Do you work for the buyer or the seller?
What do you need from the target?
5-Minute Survey
Is Your Tech Ready To Scale?
Take our free survey, and get a personalised report & step-by-step action plan to optimize your tech.
TAKE THE SURVEY
Get actionable advice every Saturday
The CTO’s Playbook
Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.