for buyers on acquire.com · pre-close code diligence

You've read the P&L. Nobody's read the code.

Every serious buyer checks the financials, the churn, the Stripe dashboard. Then wires five figures for a codebase nobody ever opened. Ascertify reads the code you're about to buy and tells you, in plain English with file-and-line proof, what you'd actually own after closing.

The business: vetted
Revenue, metrics, seller identity. Marketplace territory.
The code: taken on faith
The asset itself. That's the gap this scan closes.

Read-only repo invite or a zip from the data room. We read the code. We never run it.

The one layer of diligence no data room covers.

Ascertify is an independent static code audit for SaaS acquisitions. It scans the codebase of a business you're buying, on Acquire.com or any marketplace, without ever executing it, and reports what it finds in plain English with the exact file and line as evidence. It answers the three questions the data room can't: is the code exposed, is the product real, and can anyone but the seller actually run it.

One scan, one payment, $49. The free preview shows the critical-finding count before you pay. Not a penetration test, and not affiliated with Acquire.com.

What do you inherit?

the liabilities transfer with the repo, not the contract

Live credentials in git history the seller can still use after transfer, admin keys shipped to every visitor's browser, database rules open to the internet.

committed live credentialrow-level security disabled

Is the product real?

real MRR can sit on top of a codebase that's mostly template

Dependencies invented by an AI, a database schema with nothing but default scaffolding, most of the code committed in one dump right before listing.

hallucinated dependencyschema has no real tables

Can you run it without them?

the handover call ends. then it's just you and the repo

No setup instructions, no record of the database structure, no tests. If only the seller can operate it, you bought their job, not their business.

no setup instructionsno database migrations

Fits between the LOI and the wire.

You already request financials, metrics, and the customer list during diligence. Add one ask.

01

Request code access

The seller grants a read-only GitHub invite they can revoke after the scan, or drops a zip in the data room. Serious sellers say yes. A refusal is a finding in itself.

02

We scan, without running it

Deterministic checks, no guesswork. Every finding is pinned to a real file and line with the exact snippet shown, translated into what it means for the deal.

03

Close, renegotiate, or walk

Clean report: close with confidence. Findings: make fixes and credential rotation conditions of closing, adjust the price, or walk before the funds release, not after.

Findings that survive a defensive seller.

No vague grades. Every finding is pinned to a line of real code: specific enough that “that's not an issue” doesn't survive contact with it, clear enough that you don't need a CTO to understand it.

Critical
Dependency that doesn't exist in any registry
package.json:28 · "react-auth-helper-pro"
Critical
Database password committed to git history
.env.backup:2 · recoverable by seller after transfer
Transfer risk
No database migrations: schema exists only in the live system
supabase/ · migrations directory absent
5 more findings in the full report
The free preview counts the criticals before you spend a cent. The full report shows you each one.Read a full sample reportUnlock the full report

The cheapest line item in the deal.

One scan, one payment. Run it during diligence, use it at the negotiating table, done.

You're about to wire $60,000 for a codebase you've never opened. Knowing what's in it costs $49.

$0

Free preview

A count of the critical findings in the code. Enough to know whether there's a problem worth raising, before you pay for the detail.

Get the free preview
full report
$49
$99one-time

Every finding with file-and-line proof, the exact code, a plain-English explanation of what it means for the deal, and a PDF you can put in front of the seller.

Get full report ($49)

What this covers, and what it doesn't.

This is one layer of due diligence: the technical asset. It doesn't check churn, customer concentration, traffic quality, or the seller's claims about anything but the code. It's a static review, not a penetration test, and a clean result is not a certification. We report what we can prove: the file, the line, and the exact code. Ascertify is independent and not affiliated with Acquire.com or any marketplace.

Fair questions.

Acquire.com vets listings. Why do I need a code audit?

Marketplace vetting looks at the business: revenue claims, metrics, seller identity. Nobody opens the repository. The codebase, the thing you're actually buying, changes hands on faith. It can be leaking credentials, built on packages that don't exist, or runnable only by the seller, and the listing looks identical either way. We cover the one layer of the deal no marketplace checks.

When in the process should I run the scan?

During diligence: after your offer is accepted, before funds release from escrow. That's the window where you have both code access and leverage. Findings become closing conditions, price adjustments, or reasons to walk while walking is still free. Running it after close turns leverage into regret.

How do I get the code before I own the business?

Ask, the same way you ask for the P&L. The seller grants a read-only GitHub invite they can revoke right after the scan, or shares a zip through the data room. A serious seller agrees, because a clean report helps them close. A seller who refuses any code access before you wire five or six figures has just handed you a finding for free.

A lot of listings are AI-built now. Does that matter?

AI-built isn't a defect; some of the best small SaaS right now was built with Cursor or Claude. But AI-built code fails in recognizable ways: invented dependencies, secrets where they ship to the browser, a schema that's all template and no product. The scan doesn't care who wrote the code. It tells you whether what was written is safe, real, and transferable.

Does this replace due diligence?

No. A real checklist covers financials, churn, customer concentration, traffic, liabilities, and transfer mechanics. We cover exactly one layer: the code you're buying. It's the layer most buyers skip because they can't read it themselves, and the hardest one to fix after the wire clears.

What stacks do you support?

JavaScript and TypeScript apps: Next.js, React, Node, with deep checks for Supabase, Firebase, and Prisma. That covers most modern bootstrapped SaaS and nearly everything built with AI tools. The free preview tells you whether the codebase is a fit before you pay.

Every finding is cheaper to know before the wire than after it.

The free preview takes minutes and tells you whether there's anything in the code worth negotiating over. Start there.

Scan the code, free to start

Read-only access. The code is sandboxed, never executed, and deleted after the scan.