PlumbexRequest access
Technical due diligence · Buy-side

Technical diligence,
grounded in evidence.

Plumbex sends read-only agents into a target’s code, cloud, and security posture, then delivers an investment-committee-ready report with a deterministic remediation-cost estimate mapped to your deal model. Every finding, score, and dollar cites the artifact that supports it.

9
assessment dimensions
100%
cited findings
0
write paths to your target
IC report · excerptHigh severity

Authentication tokens are logged in plaintext across three services.

Remediation estimate
$41,000–$58,000
Deal-model bucket
Must-fix pre-close
Dimension
Security posture
Citation lineage
  1. evd_7f21app/api/auth/session.py:142
  2. evd_7f0alogs/collector.yaml · redaction: off
Built for trustRead-only accessEvery finding citedEngagement-isolatedSecrets & PII redactedRight-to-erasureNever trained on client data
01The problem

Traditional technical diligence samples. It doesn't measure.

Deal teams inherit engineering risk they can't size and can't defend. In a compressed diligence window, the depth that a technical thesis actually needs is the first thing to get cut.

01

A few days, a few interviews

Classic tech DD is a handful of expert conversations and a shallow code skim under deal-clock pressure. It samples; it doesn't measure. The findings reflect who was in the room, not what is in the repository.

02

Risk you can't put a number on

“The architecture needs work” doesn't reach the deal model. Without a defensible remediation cost, technical risk is a footnote in the IC memo instead of a line item in the model.

03

Conclusions you can't audit

When a vendor hands you a rating, you can't trace it back to the evidence. If a finding is challenged in committee — or in a dispute later — there's no artifact to point to.

02How it works

From read-only access to a defensible number.

One pipeline, four stages. Provenance is captured at every step, so the final estimate traces cleanly back to the evidence it rests on.

  1. 01

    Connect, read-only

    Scoped, time-boxed, read-only connectors into the target's source control and — where credentials are provided — a live read-only AWS account. There is no write path into client infrastructure, by construction.

    GitHub · GitLab · live AWS · IaC · least-privilege

  2. 02

    Assess with agents

    A multi-agent system evaluates nine dimensions in parallel. Each agent has explicit tool and prompt boundaries and must ground every judgment in a stored artifact — no artifact, no finding.

    9 dimensions · evidence-bound · reproducible

  3. 03

    Price the remediation

    Findings roll up into a deterministic cost estimate — effort tier × blended rate — over an assumption ledger you can see and override. A model may size the work; it never sets the price.

    must-fix · first-100-days · roadmap

  4. 04

    Deliver the report

    An investment-committee-ready report: executive summary, a severity-ranked risk register, and the cost estimate — every number a click away from the source artifact that supports it, plus an exportable SBOM and a data-lifecycle attestation.

    IC-ready · cited · SBOM + attestation

03Capabilities

Nine dimensions. One consolidated view of engineering risk.

Each dimension produces evidence-backed findings that fold into a single severity-ranked risk register — and into the cost estimate below it.

01

Codebase health

Complexity, churn, and structural risk — the maintainability the deal thesis quietly assumes.

02

Code defects

An agent reads a bounded sample of the actual source and surfaces real bugs — logic errors, null-dereferences, unsafe handling — each pinned to the line that proves it.

03

Test coverage & quality

How much of the codebase the tests genuinely exercise, and whether they assert behavior or merely run — the safety net a post-close roadmap depends on.

04

Security & supply chain

Exposed secrets, injection and auth flaws, and unsafe data handling — plus known-vulnerable and abandoned dependencies via live advisory data, weighted by how deep they sit.

05

Cloud & infrastructure

Architecture read from infrastructure-as-code and a live read-only AWS connector. Anything the access can't reach is marked “not checked” — never assumed clean.

06

Architecture & scalability

How the system is structured and where it strains — coupling, boundaries, and the scaling limits that meet the growth the thesis prices in.

07

SDLC & DevOps maturity

Branching, review discipline, CI/CD, and release cadence — how reliably the team ships and recovers.

08

Documentation & maintainability

Onboarding surface, knowledge concentration, and the key-person risk that survives the transaction.

09

AI provenance

An AI Bill of Materials: the models, AI SDKs, and data dependencies a target ships — and the license, security, and concentration risk that rides along with them.

New · AI Bill of Materials

Targets now ship AI. Plumbex inventories the models, AI SDKs, and data dependencies inside the codebase — and the license, security, and concentration risk that comes with them — as a first-class diligence dimension, not a footnote.

The headline output

A remediation-cost estimate that reaches the deal model.

Plumbex prices what it finds — deterministically, as confidence-tagged ranges, not false-precision point numbers. Effort tiers meet a blended rate over an assumption ledger you control, rolled into the three buckets that matter to an operating plan: must-fix pre-close, first 100 days, and longer-term roadmap. Change an assumption and every downstream number moves with it.

Also exported · CycloneDX SBOM · data-lifecycle attestation

Remediation rollup
Must-fix pre-close
$150K–$210K
First 100 days
$200K–$280K
Roadmap
$260K–$360K

Illustrative. Every figure derives from cited findings.

04Trust & security

The trust model is the product.

You are pointing an autonomous system at a target's crown jewels during a live deal. Plumbex is built so that decision is defensible — to your IC, to the seller, and to a regulator.

Every claim is cited

Findings, scores, and dollars all reference the source artifact that supports them. Provenance is a first-class data model — unsourced claims are treated as defects, not opinions.

Read-only, least privilege

Connectors are scoped, time-boxed, and read-only. There is no write path into a target's systems, and access is the minimum that produces the finding.

Engagement isolation

Every record is scoped to a single deal. Storage, caches, and logs are partitioned per engagement — no cross-deal data leakage, ever, enforced with explicit tests.

Secrets & PII redacted

Credentials and personal data are redacted across all log output, including stack traces, and encrypted at rest and in transit. Contributor identity is never ingested.

A reconstructable audit trail

Every agent action and data access is logged — who, what, when, which engagement, which artifact — so any conclusion can be replayed and defended later.

Deletion on demand

Right-to-erasure purges a deal's evidence and findings and leaves a non-PII record proving the deletion happened. We never train models on client data.

05Pricing

Priced by engagement, not by seat.

Technical diligence is deal work, so Plumbex is priced like deal work — a defined fee for a defined scope, aligned to the size of the decision it informs. No per-user licensing.

Diligence engagement

Per deal

A full nine-dimension assessment on a single target, scoped to the deal timeline. Read-only access, IC-ready report, and the remediation-cost estimate mapped to your model.

  • Fixed price per engagement
  • Turnaround inside the diligence window
  • Report + evidence handed over, then erased on request
Request a scoped quote

Portfolio monitoring

On the roadmap

Ongoing, read-only assessment across held companies — so technical risk and remediation progress stay visible between board meetings, not just at entry. In development; early-access design partners welcome.

  • Priced by portfolio, not per seat
  • Re-runs on a cadence you set
  • Trend view across the portfolio
Join the early-access list
06FAQ

Questions a deal team asks first.

The short version of how Plumbex works, what it touches, and why its numbers hold up in committee.

What is Plumbex?
Plumbex is an AI-native technical due-diligence platform for private equity. Read-only agents assess a target company's codebase, cloud, and security posture across nine dimensions and produce an investment-committee-ready report with a deterministic remediation-cost estimate — where every finding, score, and dollar cites the evidence that supports it.
How is Plumbex different from traditional technical due diligence?
Traditional technical DD is a handful of expert interviews under deal-clock pressure — it samples rather than measures, and its conclusions can't be traced back to evidence. Plumbex measures the actual repository and cloud across nine dimensions in parallel, prices the remediation into your deal model, and links every judgment to the source artifact that proves it.
What does Plumbex assess?
Nine dimensions: codebase health, code defects (read from the actual source), test coverage and quality, security and supply chain, cloud and infrastructure, architecture and scalability, SDLC and DevOps maturity, documentation and maintainability, and AI provenance — an AI Bill of Materials of the models, AI SDKs, and data dependencies the target ships.
Is Plumbex safe to point at a target's systems?
Yes. Connectors are read-only, least-privilege, time-boxed, and scoped to a single engagement — there is no write path into client infrastructure, by construction. Secrets and PII are redacted across all output including stack traces, data is encrypted in transit and at rest, deletion is available on demand with an audit record, and models are never trained on client data.
How does Plumbex estimate remediation cost?
Deterministically. Findings map to effort tiers priced at a blended rate over an assumption ledger you can see and override, rolled into the buckets an operating plan needs — must-fix pre-close, first 100 days, and longer-term roadmap — and presented as confidence-tagged ranges rather than false-precision point numbers. A model may size the work; it never sets the price.
Which systems does Plumbex connect to?
GitHub and GitLab source control, a live read-only AWS account where credentials are provided, and infrastructure-as-code. Anything the access can't reach is marked “not checked” in the report — never assumed clean.
What does Plumbex deliver?
An investment-committee-ready report: an executive summary, a severity-ranked risk register, and the remediation-cost estimate — every number a click from its source artifact — plus a CycloneDX software bill of materials (SBOM) and a data-lifecycle attestation.
How is Plumbex priced?
Per engagement, not per seat. Technical diligence is deal work, so Plumbex is priced like deal work — a defined fee for a defined scope, aligned to the size of the decision it informs. Continuous portfolio monitoring is on the roadmap for held companies.
Request access

See Plumbex on a codebase you know.

We’re working with a small number of buy-side teams. Tell us a little about your firm and we’ll set up a walkthrough — including a retrospective run on a deal you’ve already closed, so you can check our findings against ground truth.

  • A working session, not a slide deck
  • Your data stays yours — erased on request
  • No obligation, no procurement gauntlet

We’ll only use your details to arrange a walkthrough. No list, no spam.