Buyer evidence room
Build the evidence room around seven decisions
Request raw, scoped evidence and reconcile it across systems. A seller’s summary is useful context but should not be the only source for a material claim.
Ownership and authority
RequestEntity, contracts, contributors, source, domain, assets, licenses and account register
Red flagCritical rights or accounts remain personal, informal or non-transferable
VerifyMatch agreements and administrator access to the actual assets
Revenue and customer reality
RequestProcessor exports, invoices, refunds, concentration, churn and active-customer definitions
Red flagScreenshots replace source records or revenue depends on one related customer
VerifyReconcile representative transactions and definitions across systems
Product and data
RequestCritical journeys, data model, providers, retention, deletion and backup procedures
Red flagThe team cannot trace customer data or restore a representative backup
VerifyWalk one record through creation, use, export, deletion and recovery
Security and access
RequestRole model, incidents, vulnerability process, secrets, dependencies and recent assessment scope
Red flagAuthorization is described by hidden buttons or one shared administrator account
VerifyRun bounded negative role tests and review authoritative controls
Technology and maintainability
RequestArchitecture, dependency inventory, test evidence, deployment and known debt ledger
Red flagOnly the seller or a closed builder workspace can change production
VerifyHave an independent maintainer build and change a representative path
Operations and vendors
RequestMonitoring, incidents, support, quotas, costs, jobs, email and third-party terms
Red flagUsers report outages before the team detects them
VerifyTrace one alert and recovery; reconcile current vendor usage and ownership
Transfer and separation
RequestDetailed cutover plan, seller dependencies, credentials, support period and rollback
Red flagThe plan is ‘send the repository and change DNS’
VerifyRehearse account transfer, clean deployment and a reversible thin-slice migration
Treat public signals as triage
A high Vibe-Footprint is not an acquisition verdict
Public pattern similarity may suggest questions about distinctiveness or implementation conventions, while the separate security baseline may show visible header gaps. Neither establishes source ownership, revenue quality, authorization, maintainability or private data handling.
Use public observations to target diligence, then base the transaction decision on verified private evidence and qualified advice. A low score must not shorten the evidence room, and a high score must not substitute for it.
- Preserve evidence before accounts begin transferring
- Use read-only and least-privilege access during review
- Record unresolved facts separately from confirmed defects
- Tie every remediation promise to owner, date and closing condition
Decision matrix
Translate findings into transaction decisions
Severity alone does not determine the deal response. Consider consequence, uncertainty, remediation cost and whether the seller must act before transfer.
| Finding class | Possible response | Evidence before decision | Do not do |
|---|---|---|---|
| Ownership gap | Condition closing on transfer or remove the asset | Executed rights and tested access | Assume possession equals permission |
| Security boundary failure | Remediate before exposure or isolate affected scope | Reproducible test and verified control | Price a critical unknown without containment |
| Maintainability concentration | Secure transition support and reduce key-person paths | Independent build/change exercise | Rely on a generated architecture summary |
| Vendor or cost concentration | Renegotiate, migrate or adjust economics | Usage, terms and exit plan | Model current free allowances as permanent |
| Uncertain low-impact detail | Track post-close with a bounded owner | Clear uncertainty and maximum consequence | Treat every unknown as equally urgent |
Applied example
Diligence example: profitable site, non-transferable operations
A small subscription product shows consistent processor revenue. During technical review, the buyer learns that authentication, email and the production database are tied to the seller’s personal accounts and one builder workspace.
- Revenue evidence does not establish operational transferability.
- A repository export may omit identity configuration and live data ownership.
- The seller can transfer accounts where supported or help execute a staged migration before closing.
- The purchase agreement and cutover plan need to reflect unresolved dependencies.
Plain answers
Due-diligence questions
Can VibeFootprint tell me whether to buy a website?+
No. It provides bounded public observations. Purchase decisions need financial, legal, technical, security and operational evidence appropriate to the transaction.
Should the seller provide production credentials during diligence?+
Use controlled, least-privilege and auditable access designed by the parties and advisers. Do not broadly share secrets or customer data.
Does AI-assisted development reduce valuation?+
The production method alone does not determine value. Ownership, customer outcomes, economics, risk, maintainability and transferability are more decision-relevant.