for buyers on trustmrr · pre-close code diligence

The revenue is verified. The code isn't.

TrustMRR proves the MRR is real, straight from Stripe. Nobody proves the codebase is. Ascertify reads the code you're about to buy and tells you, in plain English with file-and-line proof, what you'd actually own the morning after the wire clears.

Revenue: verified
Live from the payment processor. TrustMRR handles this.
Code: unverified
The asset itself. That's the gap this scan closes.

Read-only repo invite or a zip from the data room. We read the code. We never run it.

The one layer of diligence no spreadsheet shows.

Ascertify is an independent static code audit for SaaS acquisitions. It scans the codebase of a business you're buying, on TrustMRR or any marketplace, without ever executing it, and reports what it finds in plain English with the exact file and line as evidence. It answers the three questions a P&L can't: is the code exposed, is the product real, and can anyone but the seller actually run it.

One scan, one payment, $49. The free preview shows the critical-finding count before you pay. Not a penetration test, and not affiliated with TrustMRR.

What do you inherit?

the liabilities transfer with the repo, not the contract

Live credentials in git history, admin keys shipped to every visitor's browser, database rules open to the internet. Day-one exposure, now yours.

committed live credentialrow-level security disabled

Is the product real?

verified revenue can sit on top of an unverified asset

Dependencies that don't exist in any registry, a database schema with nothing but template scaffolding, code committed in one dump before listing.

hallucinated dependencyschema has no real tables

Can you run it without them?

the seller leaves. what leaves with them?

No setup instructions, no record of the database structure, no tests. If only the seller can operate it, you bought a job application, not a business.

no setup instructionsno database migrations

Fits inside your diligence window.

You already ask for financials, churn data, and traffic. Add one ask to the list.

01

Request code access

The seller grants a read-only GitHub invite they can revoke after the scan, or drops a zip in the data room. Serious sellers say yes. A refusal is a finding in itself.

02

We scan, without running it

Deterministic checks, no guesswork, results the same day. Every finding is pinned to a real file and line with the exact snippet shown.

03

Close, renegotiate, or walk

Clean report: close with confidence. Findings: make fixes or rotation a condition of closing, adjust the price, or walk away before the wire, not after.

Findings that survive a defensive seller.

No vague grades. Every finding is pinned to a line of real code: specific enough that “that's not an issue” doesn't survive contact with it, clear enough that you don't need a CTO to understand it.

Critical
Database password committed to git history
.env.backup:2 · recoverable by seller after transfer
Critical
Service-role key exposed in frontend code
src/lib/supabase.ts:14
Transfer risk
No database migrations: schema exists only in the live system
supabase/ · migrations directory absent
5 more findings in the full report
The free preview counts the criticals before you spend a cent. The full report shows you each one.Read a full sample reportUnlock the full report

The cheapest line item in the deal.

One scan, one payment. Run it during diligence, use it at the negotiating table, done.

You're about to wire $40,000 for a codebase you've never opened. Knowing what's in it costs $49.

$0

Free preview

A count of the critical findings in the code. Enough to know whether there's a problem worth raising, before you pay for the detail.

Get the free preview
full report
$49
$99one-time

Every finding with file-and-line proof, the exact code, a plain-English explanation of what it means for the deal, and a PDF you can put in front of the seller.

Get full report ($49)

What this covers, and what it doesn't.

This is one layer of due diligence: the technical asset. It doesn't check churn, customer concentration, traffic quality, or the seller's claims about anything but the code. It's a static review, not a penetration test, and a clean result is not a certification. We report what we can prove: the file, the line, and the exact code. Ascertify is independent and not affiliated with TrustMRR or any marketplace.

Fair questions.

TrustMRR already verifies listings. Why do I need this?

TrustMRR verifies revenue: the MRR you see is pulled live from the seller's payment processor, which kills the biggest lie in small SaaS deals. But it says nothing about the asset itself. The code can be leaking credentials, built on packages that don't exist, or runnable only by the seller, and the revenue badge looks identical. We cover the layer revenue verification can't.

How do I get the code before I've bought the business?

The same way you get the financials: ask during diligence. The seller grants a read-only GitHub invite they can revoke right after the scan, or shares a zip through the data room. A serious seller agrees, because a clean report helps them close. A seller who refuses any code access before you wire five figures has just handed you a finding for free.

Does this replace due diligence?

No. A real acquisition checklist covers financials, churn, customer concentration, traffic, liabilities, and transfer mechanics. We cover exactly one layer: the code you're buying. It's the layer no spreadsheet shows and the one most buyers skip because they can't read it themselves.

What does a scan catch that matters in an acquisition?

Three things. Inherited exposure: live credentials in git history the seller can still use after transfer, admin keys in the browser bundle, database rules open to the internet. Whether the product is real: dependencies that don't exist in any registry, a schema that's all template scaffolding. Transfer risk: no setup instructions, no migrations, nothing that lets anyone but the seller run it.

What stacks do you support?

JavaScript and TypeScript apps: Next.js, React, Node, with deep checks for Supabase, Firebase, and Prisma. That covers most modern indie SaaS, and nearly everything built with AI tools. The free preview tells you whether the codebase is a fit before you pay.

Is Ascertify affiliated with TrustMRR?

No. We're independent. We think verified revenue plus verified code is how small SaaS deals should work, which is why this page exists, but the report is ours alone and TrustMRR has no involvement in it.

Every finding is cheaper to know before the wire than after it.

The free preview takes minutes and tells you whether there's anything in the code worth negotiating over. Start there.

Scan the code, free to start

Read-only access. The code is sandboxed, never executed, and deleted after the scan.