Maine Street Partners

[ MSP.DD ] For founders · Updated

How should founders prepare for technical due diligence?

Short answer

Run the investor's checks on yourself first: scan dependencies and the full git history for secrets, write down which models you use and what they cost per customer, document how AI-written code is reviewed, and classify your product under the EU AI Act. Fixing these before the data room opens is cheaper than negotiating over them afterwards.

Why it matters

Every issue found in due diligence becomes a negotiation point: a warranty, a price adjustment or a condition. Issues you found and fixed first are a sign of a team in control.

Before the data room opens

  1. 01Scan the full git history for secrets and rotate anything you find.
  2. 02Run a dependency vulnerability scan and fix the critical findings.
  3. 03Generate a licence report and resolve copyleft and unlicensed components.
  4. 04Write one page on your models: providers, cost per customer, fallback plan.
  5. 05Write your policy on AI coding tools, and make sure the history backs it up.
  6. 06Classify your product under the EU AI Act and note the dates that apply.
  7. 07Make sure at least two people can explain every core part of the system.

Red flags

  • Discovering your own secrets leak during the investor's review.
  • Not knowing your model cost per customer.

Good signs

  • A short technical memo ready for the data room.
  • Scan results with fixes already applied.

The numbers

  • 35% of the private repositories in GitGuardian's customer research contained plaintext secrets. [1]
  • 56% of commercial codebases in Black Duck's 2025 analysis had licence conflicts. [2]

Sources

  1. GitGuardian, The State of Secrets Sprawl 2025
  2. Black Duck, 2025 Open Source Security and Risk Analysis (press release)