

Full git-history due diligence for PE and growth equity. Findings cited, confidence-scored, and signed off before your deal team ever sees them.
What a real finding looks like

Technical Due Diligence for PE & Growth Equity
Vestige reads a target's full git history and surfaces what actually happened: the shortcuts, the deferred fixes, the migrations that quietly stalled. Every finding comes with cited evidence and a named human sign-off before it reaches your deal team.
What the data room shows you
Surface
A hypothesis worth raising
Strata
Inferred from a pattern
Bedrock
Directly evidenced in the commit record
What Vestige shows you: everything underneath, scored by how deep the evidence goes.
Vestige reads the entire repository and sorts the information to give you the history of how this codebase became what it is today.
We narrate the history and display all the changes with preliminary findings, but the story isn't the risk assessment.
The story is a diagram that aids in finding and assessing the risks. Your report is what verifies where this code is fragile.
What we do, and what we don't
No tool can responsibly predict whether an acquisition will perform, and we're not going to claim Vestige is the exception. What we give you is complete coverage of the commit history, every commit reviewed and categorized, not a sample, not a highlight reel selected by the seller's engineering team. The picture is yours to interpret. We just make sure it's the whole one.
Archaeology: why is this code like this?
Risk Surface: where is this codebase fragile?
add null check
a3f9c2b · auth/parseToken.ts
update validation
b81e04a · auth/validateUser.ts
fix
c29f17d · middleware/auth.ts
A null check, a type guard, and an error catch. Three patches in sequence with no commit messages, no PR, no issue. The pattern is consistent with a production incident caused by an unexpected null return in parseToken().
⚠ Three patches that only make sense if something broke in production.
billing/charge.ts is the most-changed file in the repo and the most depended-on, 31 modules import it, yet the three engineers who shaped it have all left. Any change here ripples across billing with no one left who remembers why it works.
⚠ The three engineers who shaped it have all left. Whoever touches it next is on their own.
Data handling
Vestige connects through GitHub's read-only OAuth. We never request write access; revoke the grant and our access ends with it. We retain findings, citations, and sign-off records. We do not retain a copy of the repository after analysis completes. Analysis runs on Anthropic's Claude API; under their commercial terms, inputs and outputs are not used to train models.
Vestige is an early-stage product. We do not hold SOC 2 or ISO 27001 certification and we won't imply otherwise. What we offer instead is a short, accurate description of exactly where your data goes. If your diligence process requires certified vendors, we'd rather you know that in the first minute than the last.
Get a sample report
Send read access to a target's repository, or run it yourselves if your firm prefers to keep access in-house. We'll turn around a sample report with the same confidence tiers, citations, and sign-off layer your deal team would see in production. No slide deck. Just the report.