
15 June 2026
Swarmer and Molfar Partner to Integrate Verified Intelligence Data for Autonomous Systems
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.
A software company may present strong growth and an ambitious product roadmap. Its value, however, often depends on assets outside the scope of financial due diligence: source code, architecture, data, infrastructure, intellectual property and the engineering team.
Software due diligence tests whether those assets support the investment thesis. Licence conflicts, fragile infrastructure, unsupported dependencies or technical debt may change the valuation, deal terms or integration plan.
Software due diligence is a transaction-focused assessment of the technology behind a company’s value. Buyers commission it before an acquisition or major investment, while a company may use it for IPO or sell-side readiness.
The review centres on revenue-generating products and the systems needed to build, operate and secure them. Internal tools still matter if their failure could interrupt delivery, expose data or create key-person dependence.
Software due diligence is typically narrower than a full technology review, yet broader than a code audit or penetration test. It cannot prove that software has no defects. It tests management’s claims and explains what the evidence gaps mean for the transaction.
The scope depends on the product, business model, jurisdictions and deal thesis. Most reviews examine the following areas.
The reviewer maps the product, hosting, databases, integrations and critical data flows. For a SaaS company, this includes cloud configuration, availability, recovery, capacity and infrastructure costs. Can the design support projected growth without disproportionate spending or a high-risk rebuild?
Code should be assessed with repository history, documentation, automated tests, release processes and defect records. Poor documentation, limited testing or knowledge concentrated in one engineer can increase integration risk and future development costs.
The target should show that it owns, or has valid rights to use, the technology in its product. Reviewers examine employee and contractor assignments, third-party agreements and open-source components. Technical evidence can help trace code provenance; legal counsel should confirm title and licence obligations.
Open-source software can be used commercially, but licences impose different conditions. Depending on how a component is used, modified, combined and distributed, obligations may include notices, attribution or disclosure of corresponding source code. Component inventories must therefore be matched to the actual licence terms.
Modern products rely on libraries, APIs, cloud services and external vendors. Reviewers should identify unsupported components, known vulnerabilities, restrictive licences, poor dependency pinning, weak patch management and single points of failure. A current software bill of materials helps, but does not replace analysis.
Cybersecurity due diligence should consider access controls, vulnerability management, encryption, logging, incidents, secure development and recovery. The NIST Cybersecurity Framework and Secure Software Development Framework provide useful reference points; claimed alignment does not prove that controls operate effectively.
Legal requirements depend on the target’s data, customers and jurisdictions. GDPR security duties apply where processing falls within the Regulation’s scope; the HIPAA Security Rule covers electronic protected health information handled by regulated US entities. ISO/IEC 27001 certification is evidence of an information security management system within its stated scope, not a guarantee that every product is secure.
Technical debt is future cost or risk created by earlier design and implementation choices. Reviewers should separate manageable backlog items from structural issues that threaten reliability, security or the roadmap. They should also assess backup restoration, incident response, monitoring, rollback and key-person dependence.
Start with the decision, not a standard checklist. A growth investor may test scalability; a strategic acquirer may focus on integration and IP ownership. The scope should identify the products, repositories, environments, entities and periods under review.
Evidence may include architecture diagrams, repositories, roadmaps, cloud costs, test results, incident logs, security policies, licence inventories, vendor contracts and staff interviews. The report should separate verified findings, management statements and unresolved questions.
No single metric establishes software quality. Repository activity, deployments, incidents and interviews should be compared with the stated development process. Automated scans can flag possible issues, but judgement is needed to assess materiality and false positives.
A useful report ranks issues by severity, evidence and business impact. Where possible, it estimates remediation cost, timing and ownership. Findings may support a valuation adjustment, warranties or indemnities, pre-closing remediation, retention measures or a post-acquisition plan.
A sound product does not remove risks surrounding the company that owns it. Buyers may still need corporate due diligence to verify beneficial ownership, founders and key executives, related parties, litigation, sanctions exposure, major vendors and public claims.
Molfar Intelligence complements technical review through due diligence services that investigate the corporate, reputational and cyber-risk context around a target. Combining those findings with software, financial and legal due diligence gives decision-makers a clearer basis for proceeding, renegotiating or pausing before capital is committed.
Author

15 June 2026
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.

2 March 2026
A €900M EU real estate deal under investigation shows why institutional reputation cannot replace structured due diligence.
Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.
Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.
Investment
Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.
Space
Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.
Finance
Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.
Cybersecurity
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.