trustmrr due diligence · the code layer, before escrow

The revenue is verified. The code isn't.

TrustMRR verifies revenue by syncing read-only with the seller's payment provider, Stripe, Paddle, LemonSqueezy and five others, refreshed about hourly. It's the best revenue proof any marketplace offers, and it stops at the payment processor. Nobody at TrustMRR opens the code. Ascertify reads it before you wire and tells you, in plain English with file-and-line proof, what you'd actually own.

Revenue: verified
Live from the payment processor. TrustMRR handles this.
Code: unverified
The asset itself. That's the gap this scan closes.

Read-only repo invite or a zip from the data room. We read the code. We never run it.

What does TrustMRR verify, and what doesn't it?

TrustMRR reads aggregate metrics through a read-only API key: total revenue, MRR, last-30-days revenue, customer and subscription counts. Its own FAQ says the reconstructed figures can differ from the provider's by up to 30% depending on refunds, trials, prorations and currency conversion. The code is never part of it.

TrustMRR verifies
  • Revenue synced from Stripe, LemonSqueezy, Polar, Paddle, DodoPayment, RevenueCat, Superwall or Creem, refreshed about hourly
  • MRR, last-30-days revenue, total revenue, customers and active subscriptions
  • Churn, growth and margin, for logged-in buyers
  • The closing path: offer, LOI, APA, escrow on Escrow.com, transfer checklist
Nobody at TrustMRR verifies
  • Whether the dependencies in package.json exist
  • Whether live credentials sit in the codebase
  • Whether database rules are open to the internet
  • Whether anyone but the founder can run the thing
  • Whether the revenue figure is exact: TrustMRR itself allows for up to 30% discrepancy

Ascertify is an independent static code audit for SaaS acquisitions on TrustMRR. It scans the codebase of the business you're buying, without ever executing it, and reports what it finds in plain English with the exact file and line as evidence. One scan, one payment: $49 for the first 50 scans, then $99. The free preview shows the critical-finding count before you pay. Not a penetration test, and not affiliated with TrustMRR.

What can the code tell you that the revenue badge can't?

What do you inherit?

the liabilities transfer with the repo, not the contract

Live credentials in git history, admin keys shipped to every visitor's browser, database rules open to the internet. Day-one exposure, now yours.

committed live credentialrow-level security disabled

Is the product real?

verified revenue can sit on top of an unverified asset

Dependencies that don't exist in any registry, a database schema with nothing but template scaffolding, code committed in one dump before listing.

hallucinated dependencyschema has no real tables

Can you run it without them?

the seller leaves. what leaves with them?

No setup instructions, no record of the database structure, no tests. If only the seller can operate it, you bought a job application, not a business.

no setup instructionsno database migrations

What's on TrustMRR's transfer checklist, and what can the code tell you first?

TrustMRR publishes no due-diligence guide. What it publishes is the transfer checklist both parties follow after escrow is funded: domain, code repository, database, payment provider account, hosting, brand assets, social accounts. The scan reads the first three of those before you fund anything.

on trustmrr's transfer checklistwhat the scan shows before escrow
Code repositoryThe whole subject of the scan. Read read-only before you fund escrow, never executed, deleted after.
DatabaseCovered: whether the schema is product tables or template scaffolding, and whether migrations exist so the next developer can rebuild it.
Payment provider accountCovered in part: live Stripe or other payment keys hardcoded in the codebase, which keep working for the seller after the account transfers.
HostingCovered in part: setup instructions and environment documentation, the difference between redeploying in an afternoon and never.
Domain, brand assets, social accountsNot covered. Those are accounts, not code.

TrustMRR's own numbers explain why nobody hires an agency here: 162 acquisitions in the last 365 days totalling $922K, an average of 23 days from listing to acquisition, at an average 1.8× multiple. That works out to under $6,000 per deal. A four-figure technical review makes no sense at that size. A scan at $49 while the first 50 last, $99 after, does. The rest of the checklist, the accounts and the paperwork, is on our SaaS technical due diligence checklist, marked by what the scan covers and what stays yours to ask.

our own data, not a vendor study

In September 2026 we scanned 70 public Lovable apps with the same checks a paid report runs. 28 of them, 40%, had a critical or high problem in code their own team wrote, and 19 of the 33 with edge functions had an endpoint anyone could call. The raw numbers are published. Read the Lovable security report →

When in a 23-day TrustMRR acquisition should you run a code audit?

TrustMRR's path is offer, optional NDA, LOI, APA, escrow on Escrow.com, transfer. Due diligence sits between the LOI and the APA. The scan takes minutes, so it fits even at TrustMRR's pace. You already ask for churn and traffic there. Add one ask.

01

Request code access

The repository is already on TrustMRR's transfer checklist; ask to see it read-only before escrow instead of after. A GitHub invite the seller can revoke after the scan, or a zip. Serious sellers say yes. A refusal is a finding in itself.

02

We scan, without running it

Deterministic checks, no guesswork, results the same day. Every finding is pinned to a real file and line with the exact snippet shown.

03

Close, renegotiate, or walk

Clean report: close with confidence. Findings: make fixes or rotation a condition of closing, adjust the price, or walk away before the wire, not after.

What does the seller see when you send a finding?

No vague grades. Every finding is pinned to a line of real code: specific enough that “that's not an issue” doesn't survive contact with it, clear enough that you don't need a CTO to understand it.

Critical
Database password committed to git history
.env.backup:2 · recoverable by seller after transfer
Critical
Service-role key exposed in frontend code
src/lib/supabase.ts:14
Transfer risk
No database migrations: schema exists only in the live system
supabase/ · migrations directory absent
5 more findings in the full report
The free preview counts the criticals before you spend a cent. The full report shows you each one.Read a full sample reportUnlock the full report

What does a code audit cost against a TrustMRR deal?

TrustMRR reports $922K of acquisition volume across 162 deals in the last 365 days, at an average 1.8× multiple. That's under $6,000 per deal on average, and $49 (first 50 scans, then $99) is under 2% of it. One scan, one payment. The pricing page sets it against the $500 to $5,000 alternatives.

The average TrustMRR acquisition changes hands for under $6,000 with the codebase unopened. Knowing what's in it costs $49 while the first 50 last, $99 after.

$0

Free preview

A count of the critical findings in the code. Enough to know whether there's a problem worth raising, before you pay for the detail.

Get the free preview
full report
$49
$99one-time

Every finding with file-and-line proof, the exact code, a plain-English explanation of what it means for the deal, and a PDF you can put in front of the seller.

Get full report ($49)

What this covers, and what it doesn't.

This is one layer of SaaS due diligence: the technical asset. It doesn't check churn, customer concentration, traffic quality, or the seller's claims about anything but the code. It's a static review, not a penetration test, and a clean result is not a certification. We report what we can prove: the file, the line, and the exact code. Ascertify is independent and not affiliated with TrustMRR or any marketplace.

What do TrustMRR buyers ask before running a scan?

Does TrustMRR verify the code of a listing?
No. TrustMRR verifies revenue by syncing with the seller's payment provider through a read-only API key and reading aggregate metrics: total revenue, MRR, last-30-days revenue, customer and subscription counts. Its FAQ describes verification entirely in terms of payment-provider data. The code repository appears on its transfer checklist, which both parties follow after escrow is funded, not before.
How accurate is TrustMRR's verified revenue?
Good, and TrustMRR is honest about the limits: its FAQ says reconstructed metrics can differ from the provider's own figures by up to 30% depending on refunds, trials, prorations and currency conversion. Treat the badge as a range, not a decimal. The code doesn't have that problem: a live credential is in the file or it isn't, and a dependency exists in the registry or it doesn't.
How do I get the code before I've bought the business?
The same way buyers get financials: you ask during the diligence window, between the LOI and the APA. The repository is already on TrustMRR's transfer checklist, so ask to see it read-only before escrow instead of receiving it after. A GitHub invite the seller can revoke after the scan, or a zip. A seller who refuses any form of code access before you wire is telling you something worth knowing.

the message to send the seller

Before funds release, I'd like to run an independent static code audit on the repository. It reads the code without running it, installs nothing, and the code is deleted after the scan. Could you add me as a read-only collaborator on the repo for 48 hours? Revoke it as soon as the scan completes. If a zip in the data room is easier, that works too.

A serious seller says yes, because a clean report helps them close. A seller who refuses read-only access before you wire has handed you a finding for free. Once you have access, use GitHub's Download ZIP on the repository and upload that zip. The GitHub connect option needs admin rights on the repo, which a collaborator invite does not give you.

What does a scan catch that matters in an acquisition?
Three things specific to buying: exposure you inherit on day one, like live credentials left in the codebase that the seller can still use after transfer; whether the product is real, like dependencies that don't exist in any registry or a database schema containing nothing but template scaffolding; and transfer risk, like missing setup instructions or no database migrations, meaning nobody but the seller can actually run what you bought.
Does this replace due diligence?
No. Buying a SaaS means checking financials, churn, customer concentration, traffic quality, liabilities, and transfer risk. Ascertify covers exactly one layer of that: the technical asset. It's a static scan, not a penetration test, and it doesn't run the app. What it gives you is the part no revenue badge shows: whether the code is safe, real, and transferable, with proof you can point to.
What stacks are supported?
JavaScript and TypeScript apps: Next.js, React, Node, with deep checks for Supabase, Firebase, and Prisma. That covers most modern indie SaaS and nearly everything built with AI tools, which is most of what's listed on TrustMRR. The free preview tells you whether a codebase is a fit before you pay.
Is Ascertify affiliated with TrustMRR?
No. Ascertify is an independent service. We think verified revenue plus verified code is how small SaaS deals should work, which is why this page exists, but we have no relationship with TrustMRR and the report is ours alone.

Sources, as published by TrustMRR on 5 Sep 2026; acquisition counts and volume are live figures on TrustMRR and change daily: TrustMRR, FAQ; TrustMRR, Why sell on TrustMRR; TrustMRR, Buy and Sell SaaS and Mobile Apps.

buying somewhere else?

The same check, for every marketplace.

Every marketplace verifies the business and none of them read the code. The scan is the same wherever the listing lives; the SaaS due diligence overview explains what it covers.

Verified revenue deserves a verified codebase.

The free preview takes minutes and tells you whether there's anything in the code worth negotiating over. Start there.

Scan the code, free to start

Read-only access. The code is sandboxed, never executed, and deleted after the scan.