Every serious buyer checks the financials, the churn, the Stripe dashboard. Then wires five figures for a codebase nobody ever opened. Ascertify reads the code you're about to buy and tells you, in plain English with file-and-line proof, what you'd actually own after closing.
Read-only repo invite or a zip from the data room. We read the code. We never run it.
This package doesn't exist in any public registry. It's a hallmark of AI-generated code, which invents plausible-sounding dependencies. At best, the project can't be installed cleanly by the next developer. At worst, someone publishes a malicious package under that exact name and your app pulls it in.
Ascertify is an independent static code audit for SaaS acquisitions. It scans the codebase of a business you're buying, on Acquire.com or any marketplace, without ever executing it, and reports what it finds in plain English with the exact file and line as evidence. It answers the three questions the data room can't: is the code exposed, is the product real, and can anyone but the seller actually run it.
One scan, one payment, $49. The free preview shows the critical-finding count before you pay. Not a penetration test, and not affiliated with Acquire.com.
the liabilities transfer with the repo, not the contract
Live credentials in git history the seller can still use after transfer, admin keys shipped to every visitor's browser, database rules open to the internet.
real MRR can sit on top of a codebase that's mostly template
Dependencies invented by an AI, a database schema with nothing but default scaffolding, most of the code committed in one dump right before listing.
the handover call ends. then it's just you and the repo
No setup instructions, no record of the database structure, no tests. If only the seller can operate it, you bought their job, not their business.
You already request financials, metrics, and the customer list during diligence. Add one ask.
The seller grants a read-only GitHub invite they can revoke after the scan, or drops a zip in the data room. Serious sellers say yes. A refusal is a finding in itself.
Deterministic checks, no guesswork. Every finding is pinned to a real file and line with the exact snippet shown, translated into what it means for the deal.
Clean report: close with confidence. Findings: make fixes and credential rotation conditions of closing, adjust the price, or walk before the funds release, not after.
No vague grades. Every finding is pinned to a line of real code: specific enough that “that's not an issue” doesn't survive contact with it, clear enough that you don't need a CTO to understand it.
One scan, one payment. Run it during diligence, use it at the negotiating table, done.
You're about to wire $60,000 for a codebase you've never opened. Knowing what's in it costs $49.
Free preview
A count of the critical findings in the code. Enough to know whether there's a problem worth raising, before you pay for the detail.
Get the free previewEvery finding with file-and-line proof, the exact code, a plain-English explanation of what it means for the deal, and a PDF you can put in front of the seller.
Get full report ($49)This is one layer of due diligence: the technical asset. It doesn't check churn, customer concentration, traffic quality, or the seller's claims about anything but the code. It's a static review, not a penetration test, and a clean result is not a certification. We report what we can prove: the file, the line, and the exact code. Ascertify is independent and not affiliated with Acquire.com or any marketplace.
Marketplace vetting looks at the business: revenue claims, metrics, seller identity. Nobody opens the repository. The codebase, the thing you're actually buying, changes hands on faith. It can be leaking credentials, built on packages that don't exist, or runnable only by the seller, and the listing looks identical either way. We cover the one layer of the deal no marketplace checks.
During diligence: after your offer is accepted, before funds release from escrow. That's the window where you have both code access and leverage. Findings become closing conditions, price adjustments, or reasons to walk while walking is still free. Running it after close turns leverage into regret.
Ask, the same way you ask for the P&L. The seller grants a read-only GitHub invite they can revoke right after the scan, or shares a zip through the data room. A serious seller agrees, because a clean report helps them close. A seller who refuses any code access before you wire five or six figures has just handed you a finding for free.
AI-built isn't a defect; some of the best small SaaS right now was built with Cursor or Claude. But AI-built code fails in recognizable ways: invented dependencies, secrets where they ship to the browser, a schema that's all template and no product. The scan doesn't care who wrote the code. It tells you whether what was written is safe, real, and transferable.
No. A real checklist covers financials, churn, customer concentration, traffic, liabilities, and transfer mechanics. We cover exactly one layer: the code you're buying. It's the layer most buyers skip because they can't read it themselves, and the hardest one to fix after the wire clears.
JavaScript and TypeScript apps: Next.js, React, Node, with deep checks for Supabase, Firebase, and Prisma. That covers most modern bootstrapped SaaS and nearly everything built with AI tools. The free preview tells you whether the codebase is a fit before you pay.
The free preview takes minutes and tells you whether there's anything in the code worth negotiating over. Start there.
Scan the code, free to startRead-only access. The code is sandboxed, never executed, and deleted after the scan.