SaaS due diligence checklist

Know your numbers the way a buyer would

Before anyone buys a software business, they check it against a long list: how money comes in, whether customers stay, what it costs to run, and who owns what. That check is called due diligence. Our Acquisition Standard is that list, written down, so you can run it on your own business.

And here is the part most people miss: you do not have to be selling for it to help. The same questions a buyer asks are the ones that tell you what is working today.

Your numbers stay private. The Acquisition audit runs on your own computer. Your code and your figures go only to your own AI, on your own key, and never to us.

If you want to sell one day

Walk into the conversation ready

Buyers pay more for a business that can prove its numbers, and walk away from one that cannot. Knowing your gaps early means fixing them on your own schedule, not the buyer’s.

If you never plan to sell

Run your business with real numbers

Most owners guess at the numbers that matter most: why customers leave, which marketing brings people who stay, and what each customer costs. The checklist puts those numbers in front of you, so you can improve conversions, keep more customers and cut what you do not need.

What the checklist looks at, in plain words

Each row is something a buyer checks, and what the same answer tells you about your business right now.

AreaA buyer asksIt helps you now by showing
Money coming inHow much comes in each month, and does it keep coming?Whether you are growing, and which months or offers actually paid off.
Customers who stayDo people keep paying, or do they leave after a few months?Why people leave, so you fix the reason instead of chasing new signups.
One big customerWould losing one customer sink the business?How risky your income is, before it becomes a problem.
Cost to win a customerWhat does it cost to get a customer, and what are they worth over time?Which marketing is worth the money and which is not.
Where customers come fromDoes the business depend on a single channel, like one ad platform?Whether search, referrals or ads bring the customers who stay.
Running costsDo hosting and tools eat the profit as you grow?Where your money quietly goes each month.
Your dataIs the data clean, recorded with consent, and allowed to move to a new owner?What your users actually do, and whether you can use it.
The code and hostingIs it built well enough to keep running and keep changing?How fragile the product is before a customer finds out.
Security and backupsIs customer data protected, and has a backup ever been restored?Whether a bad day would stay a bad day.
Who owns whatDoes the business own its code, domain, brand and accounts?Loose ends like a domain in a personal account or unlicensed images.
The services you rely onWhat happens if a key service shuts down or raises prices?Where you are exposed, and what a backup plan would cost.
Legal and paperworkIs the company set up, and are the terms and policies in place?What you need before customers or partners ask for it.

Some answers only you can give, like your revenue or your contracts. The Standard lists those as yours to fill in instead of guessing, so nothing on your report is made up.

Start with the data your app keeps

Many of these numbers can only be measured if your app saved the right information from the first day. Whether people came back last month cannot be worked out later if nobody recorded it. So we publish a free starting layout for your app’s database: the list of tables and columns it stores (developers call this a schema). It records the things a buyer and a business owner both need: who your users are, what they agreed to, how often they come back, and how to delete their data when they ask.

Free to download

The files, and what each one does

  • ↳01_core.sql: your users, what they agreed to, how often they use the app, delete requests, and a ready-made view of how many people come back.
  • ↳02_value_tables.sql: the things your users create, plus a view of how many of them go on to do the thing that matters, so your conversion rate is a number, not a guess.
  • ↳03_rls.sql: locks each user’s data to that user. If you use Supabase, you need this: without it, a signed-in user could read or delete everyone else’s data.
  • ↳data-asset.js: the code side: record consent, export one person’s data, delete a person, and count the data you are allowed to transfer.
Before you rely on it

What these files can and cannot do

They follow the rules of Postgres, the database they are written for, but they were not run against a live database when they were made. Try them on a practice database first.

They record that a user agreed to their data moving to a new owner. They cannot make that agreement legal. A lawyer has to confirm your terms say so where your users live. This is not legal advice.

Read the full setup guide for the order to run them in and how the code works.

Run the full check on your own business

The Acquisition Standard runs inside Vibe Coder Playground, which is free, and it unlocks during the beta. It uses your own Claude key, so you pay Anthropic for that usage directly and we add nothing on top. It reads your app and the numbers you connect, gives you a readiness rating, the findings behind it, and a step-by-step plan, plus a plain list of what only you can supply. See what the beta unlocks.

Get early access, free