AI due diligence
Before you pay for AI, check what’s in the code.
An AI story has two halves: the AI in the product, and the AI that writes the code. CodeDD tests both across the estate — every repository in scope — so the IC knows what is built, what is rented, and what no one reviewed.
Six pillars
Trusted by




Beyond the AI slide
Three questions every AI story has to answer.
Management can say the product is AI-powered and the team ships with Copilot. The code shows how much of that is true.
What kind of AI is in the product
Own models, agents, or a thin wrapper around someone else’s API. Two products with the same score can hold very different IP.
How much of the code AI wrote
Lines and commits that name a coding agent — a conservative floor you can defend, not a vendor dashboard number.
Whether a person reviewed it
AI-written code that merged with no human review on record. A quality and IP question before you sign.
AI in the product
Built, or rented?
Every repository ranked by IP depth — own models at the top, wrappers at the bottom — and scored across six weighted pillars from the code itself.
IP depth
Size = LOC
Score 0–100 →
AI in development
Written by agents. Reviewed by whom?
AI-authored code traced from commit to pull request, human review, and production. The figure that matters: what merged without a person looking.
98% of AI-authored commits matched a pull request — the funnel is well covered.
253,686
Lines written by AI
at least — provable from git
9,365
Human-reviewed
4% of merged
243,958
Merged with no human review
96% of merged
16,821
Reached production
7% of merged
AI-authored
Starting volume
Merged via pull request
of AI-authored
Reviewed by a human
of merged
Approved in review
of merged
Reached production
of merged
Ready for the management session
Risks and questions, grounded in evidence.
The findings come back as memo-ready text: a one-line verdict, the risks, and the open questions to put to management — each tied to the repository and evidence behind it. The score itself is rule-based; the write-up only summarises it.
Portfolio AI-Native narrative
Scores 41/100 (AI as Product): own models in train-svc carry real IP, but nothing feeds the product's own data to them, and AI work on the product has paused.
- train-svcModel training code and evaluation runs — the one Own models repository.e1
- chat-proxyCalls a third-party model API with no proprietary layer — API wrapper.e2
- PortfolioNo embeddings, vector store, or retrieval pipeline in any of the 7 repositories.e3
Risks
- Retrieval / Data Plane scores 0: the models never see the product's own data.
- No commits to the product's AI code in 90 days — Adoption Velocity is 0.
Open questions for diligence
- What is the plan to move chat-proxy beyond a wrapper?
- Is the AI roadmap for the product paused, or finished?
Across the investment cycle
Where it changes the valuation
Pre-deal tech DD
Separate AI that is built from AI that is rented before an AI premium goes into the price — and know how much of the product merged without review.
Hold period
Track the pillars as the AI roadmap lands, and require review on AI-written code while the unreviewed share comes down.
Pre-sale preparation
Back the AI story in the information memorandum with evidence a buyer’s technical DD will confirm.
Over 1,800 AI technologies detected
OpenAI
AnthropicGemini
Hugging Face
LangChainPyTorch
TensorFlow
Pinecone
Qdrant
MLflow
Ollama
FAQ
Questions deal teams ask us.
What does an AI due diligence with CodeDD cover?
Two measurements from the same audit. AI Native scores the AI inside the product — how much there is and what kind, from own models to thin API wrappers. AI in Development measures AI in how the code is written — how much coding agents wrote, and whether a person reviewed it before it merged. A company can score low on one and high on the other, so an AI equity story needs both.
How is the AI-Native score calculated?
It is a weighted sum of six pillars, each scored 0 to 100: Product Embedding (30%), Model Integration (20%), Retrieval / Data Plane (15%), Platform Readiness (15%), MLOps & Evaluation (10%), and Adoption Velocity (10%). The scoring is rule-based and versioned, so the same codebase always produces the same result. It is not generated by an AI model.
If a company uses OpenAI, does that make it AI-native?
Not on its own. An AI package in the dependency list has only a small effect. What counts is how much of the shipped code is machine learning, measured file by file, and where each AI package is actually used — usage only in tests, documentation, or authentication code does not count toward Model Integration.
What is IP depth, and why does it matter for valuation?
IP depth describes what kind of AI a repository holds: own models, data pipeline, agentic system, AI integrator, API wrapper, or no AI. Classes are checked from deepest to shallowest, and the first one the evidence supports is assigned. Two repositories can share a score and hold very different IP — the difference between an AI premium and an integration project.
What does “AI-authored” mean, and why is it a floor?
It is the share of committed work that names a coding agent. Only commits with evidence an agent wrote them are counted, so the team may use AI more than git can prove. Where a repository does not disclose agent authorship, the share is shown as unknown — not as 0%.
What does “merged unreviewed” mean?
AI-written code that reached the default branch with no human review on record. It is only shown when the Git host exposes review data, because “no review found” and “reviews are not visible” are different facts. Missing data is reported as unknown, never as drop-off.
Is the written narrative the same as the score?
No. The optional AI-generated narrative turns the findings into memo-ready text, but the score, pillars, IP depth, and evidence are calculated independently and stay available without it. Decisions should rest on the underlying findings.
What data do you store?
Only structured results: ML code share, detected technologies, pillar scores, usage class, IP depth, AI-authored line and commit counts, and review linkage. Not source code — for cloud audits, source is removed once the analysis is complete.
See what AI is really in an estate you care about — and who reviewed it
We will walk the six pillars, IP depth, and the AI delivery funnel on a repository set you choose — and separate what is built from what is only a wrapper.