TrustMRR proves the MRR is real, straight from Stripe. Nobody proves the codebase is. Ascertify reads the code you're about to buy and tells you, in plain English with file-and-line proof, what you'd actually own the morning after the wire clears.
Read-only repo invite or a zip from the data room. We read the code. We never run it.
A working database password sits in the project's history. The file looks deleted, but anyone who ever had the repo can recover it. Unless it's rotated at closing, the seller keeps a key to the customer data you just bought.
Ascertify is an independent static code audit for SaaS acquisitions. It scans the codebase of a business you're buying, on TrustMRR or any marketplace, without ever executing it, and reports what it finds in plain English with the exact file and line as evidence. It answers the three questions a P&L can't: is the code exposed, is the product real, and can anyone but the seller actually run it.
One scan, one payment, $49. The free preview shows the critical-finding count before you pay. Not a penetration test, and not affiliated with TrustMRR.
the liabilities transfer with the repo, not the contract
Live credentials in git history, admin keys shipped to every visitor's browser, database rules open to the internet. Day-one exposure, now yours.
verified revenue can sit on top of an unverified asset
Dependencies that don't exist in any registry, a database schema with nothing but template scaffolding, code committed in one dump before listing.
the seller leaves. what leaves with them?
No setup instructions, no record of the database structure, no tests. If only the seller can operate it, you bought a job application, not a business.
You already ask for financials, churn data, and traffic. Add one ask to the list.
The seller grants a read-only GitHub invite they can revoke after the scan, or drops a zip in the data room. Serious sellers say yes. A refusal is a finding in itself.
Deterministic checks, no guesswork, results the same day. Every finding is pinned to a real file and line with the exact snippet shown.
Clean report: close with confidence. Findings: make fixes or rotation a condition of closing, adjust the price, or walk away before the wire, not after.
No vague grades. Every finding is pinned to a line of real code: specific enough that “that's not an issue” doesn't survive contact with it, clear enough that you don't need a CTO to understand it.
One scan, one payment. Run it during diligence, use it at the negotiating table, done.
You're about to wire $40,000 for a codebase you've never opened. Knowing what's in it costs $49.
Free preview
A count of the critical findings in the code. Enough to know whether there's a problem worth raising, before you pay for the detail.
Get the free previewEvery finding with file-and-line proof, the exact code, a plain-English explanation of what it means for the deal, and a PDF you can put in front of the seller.
Get full report ($49)This is one layer of due diligence: the technical asset. It doesn't check churn, customer concentration, traffic quality, or the seller's claims about anything but the code. It's a static review, not a penetration test, and a clean result is not a certification. We report what we can prove: the file, the line, and the exact code. Ascertify is independent and not affiliated with TrustMRR or any marketplace.
TrustMRR verifies revenue: the MRR you see is pulled live from the seller's payment processor, which kills the biggest lie in small SaaS deals. But it says nothing about the asset itself. The code can be leaking credentials, built on packages that don't exist, or runnable only by the seller, and the revenue badge looks identical. We cover the layer revenue verification can't.
The same way you get the financials: ask during diligence. The seller grants a read-only GitHub invite they can revoke right after the scan, or shares a zip through the data room. A serious seller agrees, because a clean report helps them close. A seller who refuses any code access before you wire five figures has just handed you a finding for free.
No. A real acquisition checklist covers financials, churn, customer concentration, traffic, liabilities, and transfer mechanics. We cover exactly one layer: the code you're buying. It's the layer no spreadsheet shows and the one most buyers skip because they can't read it themselves.
Three things. Inherited exposure: live credentials in git history the seller can still use after transfer, admin keys in the browser bundle, database rules open to the internet. Whether the product is real: dependencies that don't exist in any registry, a schema that's all template scaffolding. Transfer risk: no setup instructions, no migrations, nothing that lets anyone but the seller run it.
JavaScript and TypeScript apps: Next.js, React, Node, with deep checks for Supabase, Firebase, and Prisma. That covers most modern indie SaaS, and nearly everything built with AI tools. The free preview tells you whether the codebase is a fit before you pay.
No. We're independent. We think verified revenue plus verified code is how small SaaS deals should work, which is why this page exists, but the report is ours alone and TrustMRR has no involvement in it.
The free preview takes minutes and tells you whether there's anything in the code worth negotiating over. Start there.
Scan the code, free to startRead-only access. The code is sandboxed, never executed, and deleted after the scan.