pre-close code diligence · for saas buyers

Every marketplace verifies the business. None of them read the code.

Ascertify is an independent static code audit for SaaS acquisitions. Wherever you're buying, it reads the codebase before you close and tells you, in plain English with file-and-line proof, what you'd actually own: is the code exposed, is the product real, and can anyone but the seller run it.

Read-only repo invite or a zip from the data room. We read the code. We never run it.

Start with your marketplace.

Each guide covers what that marketplace verifies, what it doesn't, and how the scan fits into your diligence window.

Buying somewhere else, or direct from the founder? The scan works the same on any deal: a read-only repo invite or a zip, findings with file-and-line proof, results the same day. Start a scan.

The three questions no listing answers.

What do you inherit?

the liabilities transfer with the repo, not the contract

Live credentials in git history the seller can still use after transfer, admin keys shipped to every visitor's browser, database rules open to the internet.

committed live credentialrow-level security disabled

Is the product real?

a polished listing can sit on top of a template with a logo

Dependencies invented by an AI, a database schema with nothing but default scaffolding, most of the code committed in one dump right before listing.

hallucinated dependencyschema has no real tables

Can you run it without them?

the handover call ends. then it's just you and the repo

No setup instructions, no record of the database structure, no tests. If only the seller can operate it, you bought their job, not their business.

no setup instructionsno database migrations

Every finding is cheaper to know before the wire than after it.

The free preview takes minutes and tells you whether there's anything in the code worth negotiating over. Start there.

Scan the code, free to start

Read-only access. The code is sandboxed, never executed, and deleted after the scan.