Technical Due Diligence Tools features explained
for Due Diligence
Every feature we track for Technical Due Diligence Tools products, with a description of what each one means.
Architecture Evaluation
Tools and features focused on reviewing software/system architecture, design patterns, and future readiness.
- API Surface Analysis
- Analyzes API surface size, versioning, and backward compatibility.
- Automated Architecture Diagramming
- Automatically generates diagrams of system/class/module dependencies.
- Change Impact Simulation
- Models potential impact of architectural changes.
- Cloud Native Compatibility
- Assesses if the architecture supports cloud-native principles.
- Data Flow Visualization
- Visualizes how data moves through the system.
- Documentation Coverage
- Measures the presence/quality of architecture documentation.
- Legacy Component Identification
- Detects outdated or obsolete technologies in use.
- Microservices Detection
- Detects presence and design of microservices in the stack.
- Modularity Assessment
- Evaluates modularity and separation of concerns in the architecture.
- Redundancy & High Availability Analysis
- Identifies points of failure and resiliency mechanisms.
- Service Dependency Mapping
- Maps out internal and external service dependencies.
Code Quality & Analysis
Capabilities for automated and manual assessment of codebases to detect issues, enforce standards, and measure maintainability.
- API for Data Export
- Availability of API for exporting scan data/results.
- Automated Code Scans
- Support for automated code quality analysis, identifying technical debt, code smells, and adherence to best practices.
- Automated Test Coverage Analysis
- Measures and reports on the percentage of code covered by tests.
- Code Review Collaboration
- Enables team-based code review, comment, and approval workflows.
- Continuous Integration Integration
- Ability to integrate with CI/CD pipelines to trigger scans automatically.
- Custom Rule Definitions
- Allows creation or editing of custom code analysis rules.
- Historical Analysis
- Ability to analyze code quality trends over time or across codebase versions.
- Issue Reporting
- Generates actionable issue and remediation reports.
- Language Support
- Number of programming languages that the tool can analyze.
- Metric Coverage
- Variety of code quality metrics tracked (e.g., cyclomatic complexity, code duplication, test coverage).
- Open Source Dependency Scanning
- Checks for open-source packages, their licenses, and known vulnerabilities.
- Refactoring Suggestions
- Offers automated suggestions or guidance for code improvements.
- Visualization
- Provides visual dashboards or charts for code quality trends and hotspots.
Collaboration & Workflow
Features to enable cross-functional teams to review, annotate, and act on due diligence findings efficiently.
- Audit Trail
- Maintains a secure record of all changes and actions for compliance/audit purposes.
- Collaboration History/Tracking
- Tracks changes, comments, and actions taken in collaborative reviews.
- Document/File Attachments
- Allows uploading and linking supporting documentation within reviews.
- In-Tool Commenting/Annotation
- Enables commenting directly on findings or code.
- Integration with Project Management Tools
- Pushes findings and tasks to external systems like Jira, Trello, Asana.
- Multi-User Access
- Allows multiple users to participate in analysis/review.
- Role-Based Permissions
- Supports granular roles and access rights.
- Task Assignment
- Assigns review tasks or remediation actions to team members.
- User Notifications
- Notifies users of mentions, assignments, or status changes.
- Workflow Customization
- Supports custom workflows tailored to specific due diligence processes.
Documentation & Maintainability
Assessment of technical documentation quality, onboarding processes, and knowledge transfer mechanisms.
- API Documentation Completeness
- Evaluates documentation for each public API endpoint.
- Automated Documentation Generation
- Supports auto-generation of code or API docs.
- Changelog Automation
- Automates changelog generation between software versions.
- Code Documentation Coverage
- Measures percentage of code adequately documented.
- Diagram Generation
- Creates diagrams for data flow, architecture, or infrastructure.
- Documentation Search Functionality
- Powerful search in all available documentation.
- Knowledge Base Integration
- Links to or includes wikis, FAQs, or internal documentation.
- Maintenance Guide Availability
- Availability of guides for system maintenance.
- Onboarding Analytics
- Tracks onboarding time and pain points for new engineers.
- ReadMe/Onboarding Quality
- Qualitative review of onboarding materials and process.
Integration & Interoperability
Features assessing the ease of integrating the technology stack with other systems and supporting interoperability.
- API Integration Support
- Assesses how many types of standardized APIs are supported.
- Authentication/SSO Integration
- Supports connection to SSO and IAM providers.
- Cross-Platform Compatibility
- Operates across multiple environments (e.g., Windows, Linux, macOS).
- Data Import/Export Tools
- Supports easy migration or syncing of data.
- Native Cloud Integrations
- Prebuilt integrations for AWS, GCP, Azure, etc.
- Plug-in Architecture
- Supports extension through plug-ins or modules.
- SDK Availability
- Availability of official client SDKs for integration.
- Standard Protocol Support
- Supports industry-standard protocols (e.g., OAuth, SAML, REST, gRPC).
- Third-Party Tool Compatibility
- Confirms compatibility with common development, monitoring, and management tools.
- Webhooks/Event Streaming
- Supports event streaming or webhook-based integrations.
Intellectual Property (IP) Analysis
Assessment capabilities targeting IP risk evaluation, software origin tracing, licensing compliance, and IP portfolio mapping.
- Code Origin Tracing
- Analyzes codebase to trace third-party, open-source, or internally developed code.
- Data Export/Reporting
- Exports data for external legal review.
- Export Control Compliance
- Assesses compliance with software export regulations.
- IP Ownership Mapping
- Maps and documents who owns or controls the codebase or platform IP.
- IP Portfolio Visualization
- Provides visual mapping of patents, copyrights, and trademarks.
- License Change Notification
- Notifies users on detected changes in license status.
- License Risk Assessment
- Identifies risky or incompatible open-source licenses in use.
- Open Source License Detection
- Detects open source usage and associated licenses.
- Patent Discovery
- Searches for pertinent patents held by the company.
- Potential Infringement Detection
- Flags possible IP infringements.
- SBOM (Software Bill of Materials) Generation
- Generates comprehensive inventories of third-party and open-source components.
Reporting & Visualization
Features supporting in-depth, accessible reporting and visual analytics for both technical and non-technical stakeholders.
- API Access for Reports
- Allows API queries to retrieve any report dataset.
- Automated Scheduling
- Enables scheduling regular reports delivery.
- Custom Alerts & Notifications
- Configurable notifications for key events/findings.
- Custom Report Builder
- Allows building custom reports from assessment data.
- Export Formats Supported
- Number of export formats supported (PDF, Excel, CSV, JSON, etc).
- Historical Data Comparison
- Supports side-by-side comparison of past and present assessment results.
- Interactive Dashboards
- Provides dynamic, filterable dashboards for different data views.
- Role-Based Views
- Customizes views/reports by user role (e.g., engineer, investor).
- Shareable Report Links
- Generates secure, shareable links for stakeholder access.
- Visualization Types
- Number of built-in chart/visualization types available.
Scalability & Performance Assessment
Tools and analysis for evaluating how the technology stack can scale to meet growth in users or data, and how it performs under load.
- Automated Load Testing
- Performs automated tests to simulate user traffic and stress on application components.
- Automated Reporting
- Generates reports on scalability and performance findings.
- Benchmark Comparisons
- Compares performance metrics against industry or historical benchmarks.
- Bottleneck Detection
- Identifies performance bottlenecks in code or infrastructure.
- Cloud Readiness Assessment
- Analyzes how applications and workloads can be migrated or operated in cloud environments.
- Concurrency Testing
- Tests how well the application handles concurrent operations.
- Latency Tracking
- Tracks response times and latencies for various system operations.
- Network Load Simulation
- Simulates network constraints (e.g. latency, packet loss) in testing scenarios.
- Peak Load Estimation
- Estimates the maximum load the system can handle before failure.
- Resource Utilization Metrics
- Monitors and reports on CPU, memory, and storage usage under various loads.
- Scalability Simulation
- Simulates and models scaling scenarios (e.g. horizontal, vertical scaling).
- Service Degradation Identification
- Detects and reports at which points the system functionality degrades under load.
- Throughput Measurement
- Measures the system's throughput under test loads.
Security Assessment
Verification and monitoring of security practices, vulnerabilities, and compliance standards within the technology stack.
- Access Control Review
- Analyzes role-based access and permission models.
- Audit Logging Analysis
- Validates logging of security-relevant events.
- Automated Patch Recommendations
- Suggests or applies patches for security vulnerabilities.
- Automated Vulnerability Scanning
- Performs security scans for known vulnerabilities in source and dependencies.
- Compliance Framework Mapping
- Assesses compliance against standards (e.g., SOC 2, ISO 27001, GDPR).
- Dependency Vulnerability Alerts
- Notifies when new vulnerabilities are discovered in dependencies.
- Encryption Verification
- Verifies use of encryption in transit and at rest.
- Incident Response Assessment
- Evaluates tools and protocols for incident detection and response.
- Penetration Testing
- Supports or integrates with penetration testing tools/workflows.
- Secrets Management
- Checks for secret/token exposure in code.
- Security Policy Auditing
- Checks for adherence to internal security policies.
Technical Debt Evaluation
Assessment tools focused on identifying, quantifying, and prioritizing technical debt across the codebase, architecture, and processes.
- Change Impact Tracking
- Monitors how software changes affect technical debt.
- Debt Categorization
- Classifies debt into types (e.g. design, code, architectural).
- Debt Identification Automation
- Automatically detects potential areas of technical debt.
- Debt Quantification
- Provides effort or cost estimates to address technical debt.
- Debt Tracking
- Tracks technical debt items over time for trend analysis.
- Impact Analysis
- Analyzes and reports the impact of technical debt on future development.
- Integration with Issue Trackers
- Links technical debt items to Jira, GitHub Issues, etc.
- Manual Annotation
- Allows manual input and tracking of technical debt not automatically detected.
- ROI Estimation
- Estimates potential ROI for technical debt remediation efforts.
- Remediation Prioritization
- Ranks or prioritizes technical debt based on severity and risk.
- Visualization of Debt Hotspots
- Visual maps highlighting parts of the codebase with high technical debt.