Seven analyzers, pure and deterministic: same repository at the same revision, same findings, every run — sealed so you can prove it. What isn't built yet is listed here too, labeled rather than hidden. That's the same honesty discipline the memo runs on.
No other M&A diligence product asks the question this deal cycle turns on: is the claimed AI actually there? Assay reads the target's own prose — README, docs, marketing copy in the repo — extracts its AI claims, and then hunts the codebase for the substance that would make them true: model SDK imports, named model identifiers, inference calls, embedding and prompt pipelines.
"AI-powered", "machine learning", "our proprietary model" — each claim is captured with its file and line, so the memo quotes the target's own words back with a citation.
SDK imports, model IDs, inference and embedding calls across the source tree. Zero production substantiation against live claims is a critical finding.
Integration that exists only in test files is its own high-severity finding — the exact place a demo-ware "AI integration" hides. Test mocks never count as corroboration.
Honesty cap: a static scan proves the code talks to a model — not that the value path does. Findings carry capped confidence, and the $25–35k tier pairs the automated pass with a human demo-tracing session for exactly this reason.
The commit history knows who actually built the system. Assay computes the truck factor, dominant-author share, and the specific significant files owned by a single person — quantified from every commit, not from an org chart the seller drew last week.
How many people can leave before the codebase is unmaintainable? A truck factor of 1 on the core is a high-severity finding with the files named.
Author share per significant file. Thresholds are calibration knobs, tuned per deal — a 4-person startup is not a 400-developer monorepo.
Buyers already deduct for this: key-person risk drives a 0.5–1.5x multiple reduction in current buyer frameworks. Assay gives you the evidence to negotiate it.
Copyleft in a proprietary target changes what you're buying. Assay detects AGPL, GPL, and LGPL signals — license files, SPDX headers, manifest declarations — and grades by the worst family present. AGPL outranks GPL; a fixture string in a test file is annotated, downgraded, and never manufactures a red flag.
Cloud keys, private-key blocks, high-entropy tokens committed to the repository. Every hit is redacted in the memo — you learn what leaked without the memo re-leaking it — and classified by rule and by location, so a live production credential and a test fixture are never conflated.
Lint scores and coverage percentages are commoditized, and a buyer can get them free. So this analyzer measures only what a non-executing pass can honestly establish — and says so in the finding: Assay never runs a target's test suite, so this reports the presence of tests, not the coverage of them.
Whether a test suite and a CI configuration exist at all. Absent CI on a live codebase means changes are validated manually, if at all — an integration-cost signal, flagged as such.
The files that change constantly and are written almost entirely by one person. That intersection is where knowledge concentration actually bites post-close — and neither churn nor bus-factor alone can see it.
Severity is capped so a commoditized signal can never outrank a real liability in the deal recommendation. Missing tests should never outvote a leaked production credential.
A report that can't say which revision it examined can't be re-run, checked, or defended in an IC meeting a month later. Every Assay run carries the target's commit SHA and a cryptographic seal.
Each finding is hashed over its own content; the run seal covers the ordered findings plus the revision. Re-running at the same revision reproduces the seals byte-for-byte — an altered memo does not.
Diligence is a snapshot, but the target keeps committing between LOI and close. Re-screen and see exactly what changed — new findings, severity moves, metric drift. A signal that disappeared is reported as no longer detected, never as fixed.
Metrics are positioned against comparable prior screens in the same size class. Below 20 comparable screens the benchmark reports itself as not assessed — an un-benchmarked metric is unknown, not average.
Two-thirds of audited codebases now carry open-source license conflicts, up from 56% a year ago, and the average codebase carries 581 known vulnerabilities. Both arrive through the dependency tree, which is why a scan of the target's own files answers neither question.
package-lock, yarn.lock and pnpm-lock parsed offline — no install, no registry call. Copyleft arriving transitively is the majority case a direct-dependency review misses, and the obligation attaches to what ships, not to what the target chose deliberately.
The artifact counsel and reps-and-warranties underwriters ask for by name, generated deterministically — no timestamp, so the same revision always produces the same document. A dependency whose license we could not resolve is reported as unresolved, never assumed permissive.
The vulnerability database is a file, stamped with the date it was built, that runs on the seller's machine with everything else. The memo cites that date, so staleness is a disclosed fact rather than a hidden one — and with no snapshot supplied, vulnerabilities are reported as not assessed, never as none found.
A match means the vulnerable code is present — not that it is exploitable here. Reachability inside the target's product is a question for its engineers, and the finding says so rather than inflating a count into a crisis.
Assay has no cloud credentials and never will. What it can read is the target's own infrastructure-as-code, which is where no backups, open to the internet and one replica are written down in plain text.
Public databases, ingress from 0.0.0.0/0, public object ACLs, and managed databases with no declared backup retention. Egress to anywhere is deliberately not flagged — it's normal, and noise costs trust.
Single replicas, single-AZ databases, workloads with no resource limits, privileged containers, and base images pinned past their upstream support window — checked against a dated table the memo prints and asks you to confirm.
IaC declares intent, not deployment. The file may be stale or overridden in a console we cannot see, so every finding says so and none can reach CRITICAL. A target with no IaC in the repo is a gap — many provision by hand, and that is unknown, not clean.
Findings converted to engineer-days and priced at a blended rate you replace with your own — every output a range, the assumption table printed beside the number, and an unsubstantiated AI claim left deliberately unpriced, because that is a deal-terms matter and not a sprint.
Fan-in, module size, cross-directory coupling, and what the entry points don't reach — plus the questions that shape raises. Assay measures the shape and refuses to grade the architecture, because a synthesized "won't scale" is the confident unfalsifiable sentence this engine exists to avoid.
Every finding generates a question for management, carrying that finding's seal. Answers are recorded against it — who said it, when, what evidence they offered. Edit the finding afterwards and the answer visibly detaches instead of silently re-attaching. Assay records answers; it does not verify them.
Until an analyzer ships, its category appears in every memo as not assessed — UNKNOWN, not clean. What is honestly still missing:
Who contributed, under what agreement, and whether the chain of title behind the IP representation actually holds — over the same git graph the key-person analyzer already reads.
Value-path reachability and the architecture pack read JavaScript and TypeScript today. Python, Go and Java targets get the rest of the battery, and an explicit gap for this.
SOC 2, penetration tests, IAM and data handling live outside a codebase. We will not synthesize them from source — they belong to the reviewer and the management session, and the memo says so.
That's the trade we think buyers deserve.
Book a screen