The SEC and DOJ are now prosecuting AI-washing. Diligence caught up in 2025 — did your process? →

Opinion is cheap.
Evidence is the product.

The documented complaint about tech diligence is that it's "opinion with a logo on it." Assay's answer is a set of rules enforced in code, not in a style guide. These are the five invariants every memo is generated under.

1 · Every asserted finding carries evidence — by allow-list

The engine refuses to construct a finding whose evidence isn't a verifiable artifact: matched lines, file paths, commit statistics, manifest entries. This isn't reviewer discipline that erodes on a busy week — the code throws rather than assert an unsourced risk. An empty citation is a build failure, not a judgment call.

2 · Absence is a gap, never a clean bill

A check that didn't run appears in the memo as not assessed — UNKNOWN, not clean. Most diligence reports quietly imply safety for everything they didn't look at; the gaps section exists so ours can't. What we didn't examine is disclosed with the same prominence as what we found.

3 · Typed confidence on every finding

Each finding carries an explicit confidence between 0 and 1. Authorship statistics are strong evidence of knowledge concentration but not proof of current employment — so that finding ships at 80%, and says so. Your team can weigh a strong signal differently from a suggestive one, because the memo distinguishes them.

4 · The grade is deterministic

The deal recommendation maps mechanically from the worst asserted severity: critical → RED-FLAG, high → DILIGENCE-REQUIRED, medium → PROCEED-WITH-CONDITIONS. No asserted findings at all → INSUFFICIENT-DATA, never "proceed." Nobody's mood is in the loop, and the same repository grades the same way twice.

5 · The engine is pure — and runs where the code lives

Zero dependencies to install, zero network calls, no clock, no randomness. Reading the git history is the only external touch. That makes every memo reproducible under scrutiny — and it means the screen can run on the seller's own machine. Sellers hate shipping source to a stranger's cloud; with Assay they don't have to, which is why consent comes in days instead of weeks.

Fixture honesty, as an example of the discipline: a dummy AWS key in a target's test suite is reported — a "fixture" can still be a real leaked secret — but it's annotated as test-path and stops driving severity. Findings are never suppressed and never inflated. The same rule stops a mocked SDK in a test file from counting as "the AI is real."

Advisory, not a verdict

The recommendation is framing for a human decision-maker. Assay informs a buyer; it does not decide an acquisition. The automated pass extracts what's checkable; a senior reviewer reads it against your deal thesis and tells you what it means — including when the honest answer is "this instrument can't see that."

What we deliberately don't claim

Put the discipline to work on your deal.

Tell us about the target. If a screen isn't the right instrument, we'll say so.

Book a screen