StackAttestTechnical Trust
Free tool

The technical due diligence checklist

61 items across 12 areas, in two modes. A founder preparing works the list as the questions they are about to be asked. An investor reviewing works it as what they would otherwise be taking on trust. Every item carries what would actually settle it, which is the part most checklists leave out. It runs in your browser and nothing is sent anywhere.

Working through this as

The same list an investor works from, phrased as the question you will be asked. An honest not sure here is worth more than a confident yes, because the not sure is the one you still have time to fix.

0 of 61 answered

Access and authorisation

Who can reach what, and whether the answer is enforced somewhere the caller cannot edit.

Can one customer reach another customer's records if they change an identifier in a request?
Independently testedSA-CORE-004passes at E2 or better
Is every permission check enforced on the server, rather than by hiding a button?
Independently testedSA-CORE-004, SA-CORE-005passes at E2 or better
Are sign-in and password reset rate limited?
Independently testedSA-CORE-003passes at E3 or better
Who on the team can reach production data, and how is that access recorded?
Human diligence
When somebody leaves, is there a list of what has to be revoked?
Human diligence
Is multi-factor authentication enforced on the accounts that could take the company down?
Human diligence

Data and privacy

What is stored, where it is, and what happens to it when somebody asks for it back.

Does the database itself scope rows to their owner, or does the application do it?
Independently testedSA-CORE-004passes at E2 or better
Is data access parameterised everywhere, including the query somebody assembled by hand?
Independently testedSA-CORE-006passes at E2 or better
Can you say what personal data you hold, where it is, and why?
Human diligence
What happens to a customer's data when they leave?
Human diligence
Do your terms actually let you use customer data the way the roadmap assumes?
Human diligence
Would somebody new understand the data model from the schema?
Human diligence

Secrets and configuration

What the deployment hands out to anybody who asks for it.

Are there any credentials in the repository, including in its history?
Independently testedSA-CORE-007passes at E3 or better
Is anything privileged reachable from the browser bundle?
Independently testedSA-CORE-007passes at E3 or better
Is the application HTTPS only, with plain HTTP redirected rather than served?
Independently testedSA-CORE-001passes at E2 or better
Do production errors return a generic message rather than a stack trace?
Independently testedSA-CORE-008passes at E3 or better
Are the security response headers set, including a content security policy?
Independently testedSA-CORE-002passes at E4 or better
Could you rotate your most important credential today, without an outage?
Independently testedSA-CORE-007passes at E3 or better

Dependencies and supply chain

What you ship that somebody else wrote.

Are there known-critical advisories against anything you deploy?
Independently testedSA-CORE-012passes at E3 or better
Does a lockfile pin what actually deployed?
Independently testedSA-CORE-012passes at E3 or better
Has anyone looked at the licences of what you depend on?
Human diligence
Is anything under GPL or AGPL linked into what you ship?
Human diligence
Do your third-party licences survive the company changing hands?
Human diligence

Reliability and recovery

What happens on the day something breaks.

Has a backup been restored, by somebody, recently?
Independently testedSA-CORE-010passes at E2 or better
Can you put yesterday's version back, and how long does it take?
Evidence collectedSA-CORE-013passes at E2 or better
Would you find out about an outage from monitoring or from a customer?
Independently testedSA-CORE-011passes at E2 or better
Is there an agreed answer to who does what when something serious happens?
Human diligence

Performance and cost

What happens when there is ten times as much of everything.

Are the queries behind your main screens index-backed?
Evidence collectedSA-CORE-009passes at E2 or better
Has the application been run under realistic concurrent load?
Human diligence
Do you know what serving ten times the traffic would cost?
Human diligence
Has anyone plotted twelve months of infrastructure spend against revenue?
Human diligence
Which single thing failing takes the product down?
Human diligence

Engineering practice

How changes get made, and what stops a bad one.

Are the flows that would cost you money covered by tests?
Human diligence
Does anything run automatically before code reaches production?
Human diligence
Is input validated on the server for anything that changes state?
Evidence collectedSA-CORE-005passes at E2 or better
Does anybody other than the author read a change before it ships?
Human diligence
Are production and development genuinely separate, including their data?
Human diligence
Could a new engineer run this locally and ship something small in their first week?
Human diligence
Do you know how often you deploy and how often a deploy breaks something?
Human diligence
Does anything read the code automatically before a human does?
Independently testedSA-CORE-006passes at E2 or better

Architecture and documentation

Whether somebody who was not there could work out how this fits together.

Is there a current description of how the system fits together?
Human diligence
Can you name the three places you would not want a new engineer to start?
Human diligence
Which external services would take the product down if they stopped?
Human diligence
Could somebody else deploy this if you were unavailable?
Human diligence
Did you write your own authentication, payments or cryptography?
Human diligence

Team and commercial

The part of technical diligence that is not about the software.

For each critical system, could a second person operate and extend it?
Human diligence
Is it clear who decides architecture and who owns production?
Human diligence
Is anyone critical near a vesting cliff or otherwise likely to leave after a raise?
Human diligence
Do your customers ask for a certification you do not have yet?
Human diligence

AI and model exposure

The questions that did not exist three years ago, and that now decide whether a roadmap is real.

Can you say which parts of the codebase were AI-generated?
Human diligence
Which features stop working if a model provider changes its pricing or its terms?
Human diligence
What customer data leaves your boundary to reach a model, and under what agreement?
Human diligence
Has anybody tried to make your AI feature do something it should not?
Human diligence
What does one active user cost you in inference at plan scale?
Human diligence
If you trained or fine-tuned anything, where did the data come from?
Human diligence

Ownership and IP

Whether the company actually owns what it is selling.

Does the company own the code, including anything written by contractors?
Human diligence
Are the domain, the app store accounts and the cloud account in the company's name?
Human diligence
Has anything proprietary been published by accident?
Independently testedSA-CORE-007passes at E3 or better

Roadmap credibility

Whether the plan and the engineering reality are the same document.

Has anyone costed the roadmap in engineering time?
Human diligence
Does your recent delivery history support the velocity the plan assumes?
Human diligence
Is the hiring plan realistic for your market, and can the team absorb it?
Human diligence

What this list is made of

Every item is labelled by what could settle it, read from the controls in the active pack rather than decided here. Which is how 41 of 61 come out as questions no control covers: a number worth seeing before you start, and one we would rather show than round.

Independently tested17 of 61
Evidence collected3 of 61
Founder attestation0 of 61
Human diligence41 of 61

Answer some of the list above and the open items will be gathered here, separated by what it would take to close each one.

How each item is labelled

A checklist that treats every item as equally answerable is comfortable and wrong. Whether your dependencies carry a known advisory is a question a machine settles in seconds. Whether one person leaving would stop the product is not a question a machine should be allowed near.

So each item names the controls in the active control pack that bear on it, and the label is read from those controls rather than decided here. An item whose control puts the system under test is labelled independently tested. One whose control reads the source, the configuration or a query plan is labelled evidence collected, because finding that a check exists is a narrower claim than watching it hold. An item with no control behind it is labelled human diligence.

41 of the 61 items fall in that last group. That is not a gap waiting to be closed by better software. Contracts, people and judgement are diligence, and they need a person.

What this checklist is not

It is not due diligence. Answering a list of questions about your own software produces a record of what you believe, and belief is where diligence starts rather than where it ends. The value is in finding your own gaps early, while there is still time to do something about them.

It is also not a scoring tool. There is no grade at the end, because a score built out of self-reported answers would be a number with nothing behind it, and reporting one would undercut the entire point of the labels.

Common questions

What should a technical due diligence checklist include?

At minimum: access and authorisation, data and privacy, secrets and configuration, dependencies and supply chain, reliability and recovery, performance and cost, engineering practice, architecture and documentation, and the team and commercial questions that are not about software at all. This checklist covers 61 items across those 12 areas, and labels each one with what would actually settle it.

What is the difference between founder mode and investor mode?

The list is the same. The phrasing is not. Founder mode asks whether you can answer the question when it arrives; investor mode asks what you would be taking on trust if you did not check. Working both is useful: the items where the two phrasings feel different are usually the ones where a founder's yes and an investor's verified are not the same claim.

Does completing this checklist mean the diligence is done?

No, and it is worth being blunt about it. A completed checklist records what you believe about your own system. It is a way to find your own gaps before somebody else does. Every answer in it is self-reported, which is the part any serious reviewer will discount, and reasonably so.

How do you decide what StackAttest can verify?

Each item names the controls in the active SA-CORE pack that bear on it, and the label comes from those controls' own verification methods. 20 of the 61 items have at least one control behind them. The other 41 have none and are labelled human diligence, because contracts, people and judgement do not have a control and a tool that pretended otherwise would be selling a number rather than an answer.

What does the evidence grade on an item mean?

It is the minimum grade the pack will accept as a pass for the controls behind that item, so it tells you how strong an answer has to be before it counts. It describes the Standard rather than any particular validation, and no grade appears on an item that no control covers.

Is this free, and does anything get sent anywhere?

It is free, needs no account, and runs entirely in your browser. Your answers stay on your machine, nothing is stored, and nothing is sent to StackAttest or anyone else. Closing the tab clears it.

When a checklist stops being enough

The moment somebody else has to believe the answers. A technical due diligence validation produces the same answers with evidence attached and a grade on each one, which is what makes them reviewable by somebody with no reason to take your word for anything.

If you want something back in the next minute instead, the free AI app security check tests a deployed application from outside with no account, and reports the controls a public URL cannot reach as uncovered rather than passing them.

Keep reading