TrustMRR verifies revenue by syncing read-only with the seller's payment provider, Stripe, Paddle, LemonSqueezy and five others, refreshed about hourly. It's the best revenue proof any marketplace offers, and it stops at the payment processor. Nobody at TrustMRR opens the code. Ascertify reads it before you wire and tells you, in plain English with file-and-line proof, what you'd actually own.
Read-only repo invite or a zip from the data room. We read the code. We never run it.
A working database password sits in the project's history. The file looks deleted, but anyone who ever had the repo can recover it. Unless it's rotated at closing, the seller keeps a key to the customer data you just bought.
TrustMRR reads aggregate metrics through a read-only API key: total revenue, MRR, last-30-days revenue, customer and subscription counts. Its own FAQ says the reconstructed figures can differ from the provider's by up to 30% depending on refunds, trials, prorations and currency conversion. The code is never part of it.
Ascertify is an independent static code audit for SaaS acquisitions on TrustMRR. It scans the codebase of the business you're buying, without ever executing it, and reports what it finds in plain English with the exact file and line as evidence. One scan, one payment: $49 for the first 50 scans, then $99. The free preview shows the critical-finding count before you pay. Not a penetration test, and not affiliated with TrustMRR.
the liabilities transfer with the repo, not the contract
Live credentials in git history, admin keys shipped to every visitor's browser, database rules open to the internet. Day-one exposure, now yours.
verified revenue can sit on top of an unverified asset
Dependencies that don't exist in any registry, a database schema with nothing but template scaffolding, code committed in one dump before listing.
the seller leaves. what leaves with them?
No setup instructions, no record of the database structure, no tests. If only the seller can operate it, you bought a job application, not a business.
TrustMRR publishes no due-diligence guide. What it publishes is the transfer checklist both parties follow after escrow is funded: domain, code repository, database, payment provider account, hosting, brand assets, social accounts. The scan reads the first three of those before you fund anything.
| on trustmrr's transfer checklist | what the scan shows before escrow |
|---|---|
| Code repository | The whole subject of the scan. Read read-only before you fund escrow, never executed, deleted after. |
| Database | Covered: whether the schema is product tables or template scaffolding, and whether migrations exist so the next developer can rebuild it. |
| Payment provider account | Covered in part: live Stripe or other payment keys hardcoded in the codebase, which keep working for the seller after the account transfers. |
| Hosting | Covered in part: setup instructions and environment documentation, the difference between redeploying in an afternoon and never. |
| Domain, brand assets, social accounts | Not covered. Those are accounts, not code. |
TrustMRR's own numbers explain why nobody hires an agency here: 162 acquisitions in the last 365 days totalling $922K, an average of 23 days from listing to acquisition, at an average 1.8× multiple. That works out to under $6,000 per deal. A four-figure technical review makes no sense at that size. A scan at $49 while the first 50 last, $99 after, does. The rest of the checklist, the accounts and the paperwork, is on our SaaS technical due diligence checklist, marked by what the scan covers and what stays yours to ask.
our own data, not a vendor study
In September 2026 we scanned 70 public Lovable apps with the same checks a paid report runs. 28 of them, 40%, had a critical or high problem in code their own team wrote, and 19 of the 33 with edge functions had an endpoint anyone could call. The raw numbers are published. Read the Lovable security report →
TrustMRR's path is offer, optional NDA, LOI, APA, escrow on Escrow.com, transfer. Due diligence sits between the LOI and the APA. The scan takes minutes, so it fits even at TrustMRR's pace. You already ask for churn and traffic there. Add one ask.
The repository is already on TrustMRR's transfer checklist; ask to see it read-only before escrow instead of after. A GitHub invite the seller can revoke after the scan, or a zip. Serious sellers say yes. A refusal is a finding in itself.
Deterministic checks, no guesswork, results the same day. Every finding is pinned to a real file and line with the exact snippet shown.
Clean report: close with confidence. Findings: make fixes or rotation a condition of closing, adjust the price, or walk away before the wire, not after.
No vague grades. Every finding is pinned to a line of real code: specific enough that “that's not an issue” doesn't survive contact with it, clear enough that you don't need a CTO to understand it.
TrustMRR reports $922K of acquisition volume across 162 deals in the last 365 days, at an average 1.8× multiple. That's under $6,000 per deal on average, and $49 (first 50 scans, then $99) is under 2% of it. One scan, one payment. The pricing page sets it against the $500 to $5,000 alternatives.
The average TrustMRR acquisition changes hands for under $6,000 with the codebase unopened. Knowing what's in it costs $49 while the first 50 last, $99 after.
Free preview
A count of the critical findings in the code. Enough to know whether there's a problem worth raising, before you pay for the detail.
Get the free previewEvery finding with file-and-line proof, the exact code, a plain-English explanation of what it means for the deal, and a PDF you can put in front of the seller.
Get full report ($49)This is one layer of SaaS due diligence: the technical asset. It doesn't check churn, customer concentration, traffic quality, or the seller's claims about anything but the code. It's a static review, not a penetration test, and a clean result is not a certification. We report what we can prove: the file, the line, and the exact code. Ascertify is independent and not affiliated with TrustMRR or any marketplace.
the message to send the seller
Before funds release, I'd like to run an independent static code audit on the repository. It reads the code without running it, installs nothing, and the code is deleted after the scan. Could you add me as a read-only collaborator on the repo for 48 hours? Revoke it as soon as the scan completes. If a zip in the data room is easier, that works too.
A serious seller says yes, because a clean report helps them close. A seller who refuses read-only access before you wire has handed you a finding for free. Once you have access, use GitHub's Download ZIP on the repository and upload that zip. The GitHub connect option needs admin rights on the repo, which a collaborator invite does not give you.
Sources, as published by TrustMRR on 5 Sep 2026; acquisition counts and volume are live figures on TrustMRR and change daily: TrustMRR, FAQ; TrustMRR, Why sell on TrustMRR; TrustMRR, Buy and Sell SaaS and Mobile Apps.
Every marketplace verifies the business and none of them read the code. The scan is the same wherever the listing lives; the SaaS due diligence overview explains what it covers.
The free preview takes minutes and tells you whether there's anything in the code worth negotiating over. Start there.
Scan the code, free to startRead-only access. The code is sandboxed, never executed, and deleted after the scan.