Know what you're buying, before the deal closes.
Tiger Dojo runs independent application-security due diligence on acquisition targets for investors, acquirers, and corporate-development teams. We assess the software you're about to own (vulnerabilities, dependency and supply-chain risk, license exposure, and security posture) and hand you a clear, expert-reviewed report you can act on.
Security expertise, applied to your deal
License + audit in one
As an Aikido reseller partner, we provision the platform and use it to run the diligence. You get deep, tool-backed evidence instead of a checklist opinion, and the platform can carry over to the buyer after close.
Expert-reviewed, not just automated
Automated reports flag findings. We interpret them for deal impact, what's material, what remediation will cost, and what's a walk-away.
Built for deal timelines
A pre-screen in days, a full assessment on your deal timeline.
Engagement tiers
Automated Pre-Screen
Fast, self-serve scan + scorecard + top risks + go/no-go summary. The low-cost first look.
Expert Assessment
Pre-screen plus manual review, dependency/supply-chain and license analysis, and an expert-reviewed executive report.
Full Technical Due Diligence
Deep engagement for larger or complex targets: architecture, CI/CD, cloud posture, remediation roadmap, transaction considerations.
What a software due diligence assessment covers
When you are about to buy a software company, the code is the asset. A security due diligence assessment tells you what is actually in that code before the deal closes, so a vulnerability or a license problem does not become your liability on day one. Here is what we look at and what you get back.
Application vulnerabilities.
We run static and dynamic analysis (SAST and DAST) across the target's codebase to find the exploitable issues: injection flaws, authentication gaps, insecure data handling. We separate the theoretical from the reachable, so you know which findings a real attacker could use.
Open-source and supply-chain risk.
Most modern software is mostly other people's code. We map the dependency tree, flag known-vulnerable packages (SCA with reachability), and check for abandoned or malicious components. Supply-chain exposure is one of the most common things a surface-level review misses.
Secrets and credentials.
Hardcoded API keys, tokens, and passwords in the codebase or git history are a fast route to a breach. We scan for exposed secrets across the repo and its history, not just the current HEAD.
License and compliance risk.
An open-source license can quietly obligate the acquirer to release proprietary code or pay for noncompliance. We inventory every license in the dependency tree and flag the ones that create legal or IP risk for the transaction.
Container and cloud posture.
We assess how the software is built and deployed: container image vulnerabilities, infrastructure-as-code misconfigurations, and cloud security posture (CSPM) on the target's environment. Deployment risk is as real as code risk.
Security maturity and process.
Beyond findings, we look at how the team works: is there a CI/CD pipeline with security gates, a patching cadence, an incident history. This tells you what you are inheriting operationally, not just technically.
What you get back.
An expert-reviewed report, not a raw scanner dump. Every finding is validated by a security engineer to remove false positives, rated for deal impact (what is material, what remediation will cost, what is a walk-away), and summarized for both the deal team and the engineers who will own the code. For larger targets we add an architecture and remediation roadmap.
The Tiger Dojo difference: license plus audit in one.
Because we are an Aikido reseller partner, we provision the platform and run the diligence on it, and that platform can carry over to the buyer after close. You get tool-backed evidence during the deal, and the same engagement can leave a security platform behind for the company you just bought.
How fast?
An automated pre-screen in days for an early go/no-go read. A full assessment scoped to your deal timeline. If you have a target under LOI, talk to us and we will scope it to your close date.
Common questions
Does Tiger Dojo do technical due diligence for acquisitions?
Yes. Independent application-security and software due diligence for acquirers, PE firms, and corporate development, from a fast automated pre-screen to a full expert assessment.
What does an AppSec due-diligence assessment cover?
Application vulnerabilities (SAST/DAST), open-source and supply-chain risk (SCA), secrets exposure, container and cloud posture, license and compliance risk, and overall security maturity, delivered as an expert-reviewed report.
How fast can you turn around a due-diligence report?
An automated pre-screen in days. A full assessment scoped to your deal timeline.
How is Tiger Dojo different from a due-diligence platform or a Big-4 consultancy?
We're a security firm and an Aikido reseller partner. We run the actual tooling on the target and interpret the findings for deal impact, and the platform can carry over to the buyer after close.
Contact Us
Whether you need a quick pre-screen or a full assessment, we scope the engagement to your timeline.