The documented complaint about tech diligence is that it's "opinion with a logo on it." Assay's answer is a set of rules enforced in code, not in a style guide. These are the five invariants every memo is generated under.
The engine refuses to construct a finding whose evidence isn't a verifiable artifact: matched lines, file paths, commit statistics, manifest entries. This isn't reviewer discipline that erodes on a busy week — the code throws rather than assert an unsourced risk. An empty citation is a build failure, not a judgment call.
A check that didn't run appears in the memo as not assessed — UNKNOWN, not clean. Most diligence reports quietly imply safety for everything they didn't look at; the gaps section exists so ours can't. What we didn't examine is disclosed with the same prominence as what we found.
Each finding carries an explicit confidence between 0 and 1. Authorship statistics are strong evidence of knowledge concentration but not proof of current employment — so that finding ships at 80%, and says so. Your team can weigh a strong signal differently from a suggestive one, because the memo distinguishes them.
The deal recommendation maps mechanically from the worst asserted severity: critical → RED-FLAG, high → DILIGENCE-REQUIRED, medium → PROCEED-WITH-CONDITIONS. No asserted findings at all → INSUFFICIENT-DATA, never "proceed." Nobody's mood is in the loop, and the same repository grades the same way twice.
Zero dependencies to install, zero network calls, no clock, no randomness. Reading the git history is the only external touch. That makes every memo reproducible under scrutiny — and it means the screen can run on the seller's own machine. Sellers hate shipping source to a stranger's cloud; with Assay they don't have to, which is why consent comes in days instead of weeks.
Fixture honesty, as an example of the discipline: a dummy AWS key in a target's test suite is reported — a "fixture" can still be a real leaked secret — but it's annotated as test-path and stops driving severity. Findings are never suppressed and never inflated. The same rule stops a mocked SDK in a test file from counting as "the AI is real."
The recommendation is framing for a human decision-maker. Assay informs a buyer; it does not decide an acquisition. The automated pass extracts what's checkable; a senior reviewer reads it against your deal thesis and tells you what it means — including when the honest answer is "this instrument can't see that."
Tell us about the target. If a screen isn't the right instrument, we'll say so.
Book a screen