Source code due diligence: what buyers review in a software sale
Source code due diligence is a buyer's review of a target's codebase and engineering practices to confirm who owns the code, which open-source licenses apply, how secure and maintainable it is, and whether the team can keep shipping. The same Git history, pull requests and review threads can also be licensable records when the company's rights are clear.
What is source code due diligence?
Source code due diligence is the part of technical due diligence in which a buyer, or a specialist firm it hires, examines a software company's repositories, dependencies and development process before signing. It answers four questions: does the company own what it sells, may it legally ship it, is it secure, and can the team keep improving it? The findings feed the price, the IP representations in the purchase agreement and any special indemnities.
For sellers and their advisors, the review has a second use. The artifacts it examines (commit history, pull requests, review comments, linked tickets and incident write-ups) are records of real engineering work with outcomes, and AI developers pay to license that kind of history when they train and evaluate coding agents.
What do buyers review in code diligence?
| Area | What reviewers look at | What the seller should have ready |
|---|---|---|
| Ownership | Who wrote the code: employees, contractors, agencies, acquired teams | Invention assignment agreements, contractor agreements with IP assignment, acquisition documents |
| Open-source licenses | Components and their licenses, especially copyleft terms in distributed code | A software bill of materials and a recent license scan |
| Security | Vulnerable dependencies, secrets committed to history, access controls | Dependency and secret scan results, penetration test reports, remediation tickets |
| Quality and architecture | Test coverage, build reliability, technical debt, documentation | CI history, architecture documents, a debt register |
| Engineering process | Review discipline, branch protection, release cadence, incident handling | Pull request review data, release notes, postmortems |
| Key-person risk | Commit concentration and knowledge held by a few engineers | Team map, onboarding documents, retention plans |
| AI-assisted code | Policies on AI coding tools and how generated code is reviewed | A written policy and examples of review practice |
| Customer commitments | Source code escrow agreements, release triggers, customer-specific forks | Escrow agreements and a list of customer branches |
How does a code review run during a sale?
- Scope and clean team. The buyer names who will see code, frequently an outside firm, under the NDA and a clean-team protocol.
- Access model. The seller chooses how code is examined: guided screen-share sessions, read-only access in a controlled environment, or scans run by a third party that reports findings without keeping copies. Sellers can limit raw code access until signing.
- Automated scans. Software composition analysis, license detection and secret scanning across the full history, not just the main branch.
- Manual review and interviews. Reviewers sample critical modules and interview the CTO and lead engineers about architecture, debt and roadmap.
- Findings report. Issues are rated by severity, with remediation estimates.
- Deal terms. Findings shape IP and open-source representations, specific indemnities, escrow or holdback amounts and, where used, the exclusions in representations and warranties insurance.
Sellers who run their own pre-sale scan, sometimes called sell-side code diligence, find problems on their own schedule rather than the buyer's.
Who owns the code? The question behind most findings
Ownership gaps are the findings most likely to move price. Under US copyright law, a work prepared by an employee within the scope of employment is a work made for hire, and the employer is treated as its author (17 U.S.C. § 101). Commissioned work from an outside contractor counts as a work made for hire only if it falls within one of nine listed categories and both parties sign a written agreement saying so. Outside those categories, the company generally needs a written assignment from the contractor to own the work, as the Copyright Office's Circular 30 on works made for hire explains.
In practice, reviewers match the contributor list in Git against employee and contractor records and look for gaps: a founder's code written before incorporation, an offshore agency without an assignment clause, an acquired codebase with incomplete paperwork. Those gaps matter twice, once for the sale and again for any data license, because a company can only license what it owns.
This is general information, not legal, tax or financial advice. Ownership questions belong with deal counsel, who can confirm how the rules apply to the company's own contracts.
Why the same records can be licensed
What a diligence team skims for risk, an AI developer reads as training material. Coding agents learn from how engineers actually work: a ticket describing a bug, the pull request that fixes it, the reviewer's objections, the revised commit, the failed CI run and the eventual merge. That sequence, with its outcome, is scarce in public repositories for proprietary business software.
| Diligence artifact | What it tells a reviewer | How it helps a licensing inventory |
|---|---|---|
| Repository list with history depth | Scale and age of the codebase | Systems, years of history and volume for the data inventory |
| Contributor and assignment schedule | Ownership gaps | Which code the company has the right to license |
| SBOM and license scan | Third-party and open-source code | Components to exclude or treat under their own licenses |
| Secret scan results | Credentials in history | A redaction plan before anything is prepared |
| Pull request and review history | Engineering discipline | Linked problem, discussion and outcome records |
| Postmortems and incident tickets | Operational maturity | Decision records with documented results |
A seller who has just been through diligence, or is preparing for it, has already done much of the mapping a data inventory needs. Agencies that write code for clients face extra rights questions, covered in the guide to what a software development company owns.
How a software M&A advisor spots a candidate
You do not need to read code to spot a candidate. Ask the CTO three things: how many years of history live in Git and the issue tracker, whether pull requests are reviewed and linked to tickets, and whether every contributor signed an assignment. Clear answers to all three, at a company with 50+ full-time employees at peak (contractors excluded), justify a company fit check. The referral page for M&A advisors describes the partner program from a deal adviser's side.
Then settle timing with the client. A license before the sale is the seller's call and belongs in the disclosure schedules; once the deal closes, the buyer makes that call. Owners who fear that licensing code means handing over the product should read whether licensing company data gives away the crown jewels: the company keeps ownership, and scope, permitted use and redaction are set in the agreement it signs. For the wider picture of how AI is changing what software buyers ask, see software M&A trends in 2026.
Partners only make the introduction; they never receive, export or describe code. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, payable after the buyer pays and SourceX receives its fee, and no reward is guaranteed. The reward is funded from SourceX's fee, not from the seller's payment. Check your own engagement letter, firm policy and any professional or securities rules on referral fees and disclosure before registering.
Limits and open questions
- Not all code qualifies. Client-owned code, code under restrictive third-party licenses and repositories with unresolved ownership gaps are excluded or need consent.
- Security concerns are legitimate. Secrets, customer data in test fixtures and internal hostnames have to be stripped out under redaction rules the company approves up front.
- The policy debate on AI training continues. The US Copyright Office's Copyright and Artificial Intelligence report includes a Part 3 on generative AI training, released as a pre-publication version in May 2025, which examines where copying for training may implicate copyright and how practical licensing approaches are. It is analysis, not law.
- Diligence findings travel. If a buyer's review finds an ownership gap, fix it before any license is signed, not after.
Next step
Before your next software client opens its data room, ask the three CTO questions. Clean answers mean it is time to register as a partner and send the founder your referral link, which opens the company application at sourcex.si/apply. For subscription businesses, the guide to selling a SaaS company covers the records that matter beyond ARR.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Who usually performs source code due diligence?
Buyers either use their own engineering leaders or hire a specialist technical diligence firm, and the seller's CTO and senior engineers support the review through interviews and controlled access. Some sellers also commission their own pre-sale review, so that ownership, open-source or security issues can be fixed before a buyer finds them and uses them in negotiation.
Does the buyer get a copy of the source code during diligence?
Not necessarily. Sellers commonly limit access before signing, using guided sessions, read-only environments or a third party that runs scans and reports findings without keeping copies. The access model is negotiated under the NDA and clean-team arrangements. Full repository access normally follows closing, when the buyer owns the company.
What is source code escrow and why does it come up in M&A?
Source code escrow is an arrangement in which a software vendor deposits code with a neutral agent, to be released to a customer if defined events occur, such as the vendor ceasing to support the product. Buyers review escrow agreements because a sale or other trigger event can affect release rights. Sellers should list every escrow agreement and its release conditions in the data room.
Can a company license its Git history if it uses open-source components?
Generally yes, but the open-source parts are handled separately. Third-party and open-source code carries its own license terms, so a licensing inventory excludes it or treats it under those terms, while the company's own commits, reviews and discussions form the core of the dataset. A software bill of materials from diligence makes that separation much easier.
What should a seller fix before code diligence starts?
Start with missing IP assignments from founders, employees and contractors, then secrets committed to Git history, copyleft components in distributed code, undocumented customer forks and any escrow obligations. Fixing these before buyers arrive keeps them out of the price negotiation, and the same cleanup makes a later data license easier to scope.
Related pages
- How to sell a software development company, and what you actually own
- Check Company Fit for Data Licensing
- Referral opportunities for M&A advisors
- Is licensing your company's data giving away its most valuable asset?
- Software M&A trends in 2026: what sellers and their advisors should plan for
- How to sell a SaaS company, and what to do with the records beyond ARR
Free resources
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment