Arrio

Measuring software development

Know what the deal is worth before you sign

In most M&A deals today, software is a large part of it, but stays invisible in the data room. Traditional technical due diligence takes weeks and only focuses on the software. Ours reads the target’s codebase itself and translates to business outcomes, so you can sign off on what is really there, and start day one with a baseline.

The cost of getting it wrong

Of deal value is what failed technical due diligence costs acquirers, on average. (Deloitte and Patsnap, 2026)
25%
Of deal value is what failed technical due diligence costs acquirers, on average. · Deloitte and Patsnap, 2026
The estimated cost of poor software quality in the US. (CISQ, 2022)
$2.41tn
The estimated cost of poor software quality in the US. · CISQ, 2022
Increase in duplicated code blocks, the kind of debt most often hidden at deal time. (GitClear, 2026)
+81%
Increase in duplicated code blocks, the kind of debt most often hidden at deal time. · GitClear, 2026

The value of a software business is locked in its code and its ability to keep producing. When diligence misses what the code is really carrying, the acquirer pays for it later, and the bill is a quarter of the deal.


What code-level diligence reveals

The things a data room is not built to show.

01

The real state of the code

Quality, complexity and technical-debt load read from the codebase itself, not from the target's own presentation of it. Duplicated code blocks are up 81% and cross-file reuse is down 35% (GitClear, 2026), and none of it shows in a data room.

02

How much was built by AI

42% of committed code is now AI-generated or assisted, and 45% of AI-generated code has shipped with a security vulnerability (SonarSource, 2026; Veracode, 2025). A target that moved fast may have moved fragile.

03

Concentration and key-person risk

Where the knowledge and the load actually sit across the engineering organisation, and what walks out of the door if the wrong people leave after close.

04

What the team actually produces

Output and delivery measured against cost across teams and vendors, so the run-rate you are underwriting reflects what is really being produced, not the headcount on a slide.

Before the deal, and the day after

The reading that informs the decision becomes the baseline for the asset.

Pre-deal, it tells you what you are buying. Post-close, the same independent measure becomes a day-one baseline: integration and oversight start from evidence, not from the story that sold the deal. For a private-equity owner it is one consistent measure across every company in the portfolio, so the whole book can be read on the same terms.

Failed technical due diligence costs acquirers around 25% of deal value.

Deloitte and PatsnapTechnical diligence research, 2026

Who it is for

For everyone underwriting a software business.

Private equity

Pre-deal diligence and a portfolio-wide baseline, so software health is read on the same independent terms across every holding.

Corporate development

Code-level diligence on a target and a day-one baseline for post-merger integration, without depending on the target’s own account.

Acquirers and their advisers

An independent technical read to sit alongside financial and legal diligence, fast enough to fit inside the deal timeline.


Questions

The questions worth asking

Related reading: the independent software audit, and for investors, Arrio for investors. Defined plainly:technical due diligence.

What is technical due diligence?

Technical due diligence is the assessment of a target company's software, engineering and technology before a transaction: what state the code is in, what the team actually produces, and what risks and liabilities are carried in the codebase. For software-intensive businesses it sits alongside financial and legal diligence, because the code is a large part of what is being bought.

Why does it matter so much in software-heavy deals?

Because getting it wrong is expensive. Failed technical due diligence costs acquirers around 25% of deal value on average (Deloitte and Patsnap, 2026). The value of a software business is largely locked in its code and its ability to keep producing, and both are hard to see from the outside without reading the code itself.

What does code-level diligence reveal that a data room does not?

The things the target has no incentive to surface: hidden technical debt, with duplicated code blocks up 81% since AI (GitClear, 2026); the AI-generated share of the code and the security risk that comes with it; complexity that will slow every future release; and where key-person risk really sits. A data room shows what the seller chose to show. Reading the code shows what is there.

Do you need the target to install anything or take the site offline?

No. Diligence runs from read-only access to the repositories in scope, with the deployment model chosen to suit the process, including inside a controlled cloud environment. It is sandboxed and audit-trailed, and the source code is not stored. That keeps the process fast and low-friction during a live deal.

Can you provide a baseline for after the deal closes?

Yes, and it is one of the most valuable outputs. The same reading that informs the decision becomes a day-one baseline for the asset you now own, so post-merger integration and ongoing oversight start from evidence rather than from the acquisition narrative. For private-equity owners it gives a consistent, independent measure across the portfolio.

How fast can it be done inside a deal timeline?

The first reading lands within days and includes history, so it fits a diligence window rather than extending it. It does not depend on interviews or workshops with the target's team, which keeps it discreet and quick.

Sources

  1. Deloitte and Patsnap, 2026 Failed technical due diligence costs acquirers around 25% of deal value.
  2. CISQ, 2022 Cost of poor software quality in the US at least $2.41 trillion, of which ~$1.52 trillion is accumulated technical debt.
  3. GitClear, 2026 Maintainability Gap study, 211M lines of code: the share of new code rewritten within two weeks rose from 3.3% to 7.1%; duplicated code blocks up 81%; cross-file reuse down 35%; refactoring moves down 70%.
  4. SonarSource State of Code, 2026 42% of committed code is AI-generated or assisted.
  5. Veracode, 2025 45% of AI-generated code introduced a security vulnerability.

Read the code before you sign, and own the baseline after.