Fractional CTO

Due diligence

Technical Assessment & Health Check

Get an honest, independent evaluation of your technology—before your next funding round, acquisition, or major initiative. No surprises.

3 WeeksDelivery
$4KStarting
25+ yrsExperience
Schedule a Discovery Call

Diagnosis

Sound Familiar?

Investors are asking about your tech stack and you're not sure how it will hold up to scrutiny. You need an honest answer before they find problems you didn't know existed.

You acquired a company or your founding CTO left. Now you're running on code nobody fully understands—and things keep breaking.

Growth is coming. Your team says "we'll need to rewrite everything" but can't explain why—or when. You need a second opinion before committing resources.

Your tech team says everything is fine. Your gut says otherwise. You need someone technical enough to dig in but independent enough to tell you the truth.

An agency built your product and handed it over. Now you own code you didn't write, can't evaluate, and the people who wrote it have stopped answering.

Scope

What I Assess

Architecture

System design, service boundaries, data flow, dependencies. Can this architecture support 10x growth? Where are the bottlenecks?

Code Quality

Cyclomatic complexity, duplication, cohesion, and coupling. I run a cognitive load index over the codebase (0-1000, eight dimensions) alongside test coverage and documentation. How expensive is it to change things? What's the bus factor?

Security Posture

Authentication, data protection, dependency vulnerabilities, compliance readiness. What would a security-focused investor find?

Performance

Response times, resource utilization, scalability limits. Where will things break under load? What's the cost curve?

Infrastructure

Cloud setup, deployment pipelines, monitoring, disaster recovery. How quickly can you recover from failures? What's your blast radius?

Technical Debt

Shortcuts, outdated dependencies, deferred maintenance. What did those decisions cost?

Business & Defensibility

For an acquisition or a round: how defensible the thing actually is, what it would cost to rebuild, where the switching costs sit, and what locks you to a vendor. Buy, build, or walk?

Deliverables

What You Get

1

Executive Summary

A one-page overview you can share with your board or investors. Overall health score, top risks, and key recommendations, no jargon.

2

Detailed Findings Report

Comprehensive documentation of what I found in each area. Evidence-based, with specific examples from your codebase and infrastructure.

3

Risk Register

Every issue categorized by severity and likelihood. What could hurt you tomorrow vs. what's a slow burn. No surprises during due diligence.

4

Prioritized Roadmap

What to fix first, what can wait, and what's actually fine. Effort estimates, dependencies, and suggested sequencing your team can execute.

5

Presentation & Q&A

A live walkthrough of findings with your leadership team. Ask questions, challenge conclusions, and align on next steps.

Formats

Pricing

Focused Assessment

$4,000

Deep dive into one area

  • Choose: Architecture, Security, or Performance
  • Detailed findings report
  • Recommendations
  • 60-min review call

1-2 weeks from access

MOST POPULAR

Full Health Check

$8,000

Complete picture

  • All seven assessment areas
  • Executive summary
  • Risk register
  • Prioritized roadmap
  • Team presentation + Q&A

3 weeks from access

The clock starts when I have read-only access, not at signature. Want ongoing support after the assessment? Continue with a monthly retainer.

The process

How It Works

1 Discovery

  • Kickoff call to understand your context and concerns
  • Access to repositories, infrastructure, and documentation
  • Brief conversations with key technical stakeholders

2 Analysis

  • Code review and architecture analysis
  • Security and dependency scanning
  • Infrastructure and deployment review
  • Performance and scalability assessment

3 Synthesis

  • Compile findings into actionable reports
  • Build risk register and roadmap
  • Prepare executive summary and presentation

4 Delivery

  • Present findings to your team
  • Answer questions, provide context
  • Discuss priorities and next steps

Fit

Who This Is For

Founders Raising Capital

Know your technical strengths and weaknesses before investors do their own due diligence.

CEOs Planning Major Initiatives

Validate that your technology can support the next phase before committing resources.

Acquirers & Investors

Independent technical due diligence before closing. I've led the technical assessment of a digital bank in an M&A deal. Understand what you're buying.

New CTOs & Tech Leaders

Get an objective baseline of what you've inherited. Make informed decisions about where to invest.

Founders Who Outsourced Development

An agency or dev shop built it and left you the code. Know what you actually own before you put more money into it, or replace it.

Writing the check

Technical Due Diligence for a Startup Investment

When you are the one investing, the question is narrower than the one most due diligence reports answer: can this team keep making good decisions after the round closes? The code and the repository history are how I get at that.

In an acquisition you are buying the system, so every defect in it becomes yours. A seed or Series A check is a different bet: most of that code gets rewritten before the next round, and a list of code-quality findings says little about whether the money works. The history says more. It shows which files get rewritten every month, how much of the product only one person understands, and whether the module the business runs on is the one nobody wants to touch.

Repository forensics

Bus factor, change hotspots, churn against complexity. Where the history says the risk sits, with the files attached so your partners can check the work.

Severity you can price

Every finding classified by severity and likelihood, with the evidence. The judgment you are paying for is the split between what has to be closed before the money lands and what is normal for a codebase at this stage.

A readout you can question

An executive readout, then the live walkthrough of findings, where you push back on the conclusions. If I cannot defend a finding in front of the founder's engineers, it does not belong in the report.

An outside consultant is worth paying for because I am independent of whoever built the system and of whoever wants the round to close. Formats and prices are the ones above. The clock starts when I have read-only access to the repository, and on a live deal getting that access is usually the slowest step. If the founder will not grant it, there is no assessment worth buying, and I will say so. The engagements below are the closest thing I have to a reference.

In practice

Assessments I have run

Every one of these ended in a decision: buy, walk, restructure, or ship.

Digital bank · buy-side due diligence 2021

Led the technical due diligence of a digital bank owned by one of Argentina's largest insurance groups, inside the M&A process in which the group acquired part of the fintech where I was VP of Engineering. Architecture, security, infrastructure, regulatory context and engineering team, reported straight to the decision-makers. The deal closed.

Embedded insurance · adopt-or-walk 2026

A founder had to decide whether to build a new business on an insurance-broker platform already in production — 600+ active producers, 6 carriers integrated. Seven dimensions assessed, 105 findings, including critical security issues. The cognitive load index came back at 450 out of 1000 on the legacy platform against 220 on the newer one, measured across 870 files and 195K lines. Deliverables: a findings register classified by severity with evidence, a consolidated risk matrix, a phased remediation roadmap, and an executive readout that informed the adopt-or-walk decision.

Health-insurance platform · technical audit 2024–2025

Full audit of a brokerage platform (PHP/React): technical debt, architectural risk, code quality, delivery practices and vendor performance. The findings drove a team restructuring and the replacement of an underperforming consulting firm.

Credit risk & collections · fintech 2025–2026

Assessments of credit-risk and collections platforms for a lending group: security and compliance review (OWASP Top 10, banking regulatory mapping), technical debt with repository forensics — bus factor, change hotspots, churn × complexity — and a prioritized remediation roadmap.

Next step

Ready for an Honest Assessment?

Let's talk about your technology and what you need to know. 30 minutes, no pitch—just an honest conversation about whether this makes sense for your situation.

Schedule a Discovery Call

FAQ

Questions

Can you run technical due diligence for an investment I am considering?

Yes, and it is a different read from the founder-side version. On an investment I am working out whether the team can keep making good decisions after the round closes, so the weight goes on repository history (bus factor, change hotspots, churn against complexity) and on security and compliance exposure that becomes yours once the money is in. Same formats and prices, same read-only access, and I need the founder's cooperation to get it. Portfolio companies you already hold work the same way.

What access do you need?

Read-only access to source code repositories, cloud console (AWS/GCP/Azure), and any existing documentation. I can work with whatever access level you're comfortable with—more access means deeper analysis.

Will this disrupt my team?

Some disruption, but bounded. Plan on 4-6 hours from your technical leads for a Focused Assessment, and closer to a full day—spread across three weeks—for the Full Health Check. A kickoff call, a few conversations with the people who actually know the system, and questions that land in Slack as I work. Everything else happens in the code and the infrastructure.

What if you find something really bad?

I'll tell you. Better to know now than during due diligence or after a production incident. The report includes not just problems but practical paths to fix them.

Can you help implement the fixes?

Yes—a fractional CTO engagement (monthly retainer) is the natural follow-up when remediation needs ongoing leadership. We can scope it together after you see the report.

How is this different from automated scanning tools?

Tools find symptoms. I find causes. Automated scanners can tell you about known vulnerabilities or code smells. I can tell you why your architecture will break at 10x scale and what to do about it.

Is everything confidential?

Absolutely. I sign NDAs before accessing anything. Your code, architecture, and findings never leave the engagement.