Skip to content
Yuri Subach

Independent AI and technical due diligence for software acquisitions.

Before you close, get an unsentimental read on whether the technology is real, whether it will scale, and what risk you're inheriting — fast enough to fit a live deal.

Engaged by private equity, growth investors, corporate development, and search-fund buyers — often on referral from a quality-of-earnings or financial-DD advisor.

By the time it matters, you're out of time to find out.

The "AI" may be a thin wrapper over someone else's API. The architecture may not survive the next order of magnitude of scale. The critical knowledge may live in one engineer's head. On a live deal timeline, you rarely have the runway to find out — so buyers borrow a portfolio-company CTO, stretch a generalist consultant, or take the founder's deck at face value.

None of those give you an independent answer. That's the gap I fill.

An outside read you can put in front of an investment committee.

Independent by design.
Fixed fee. No success fee, no contingency, no equity. Conflict-checked. My assessment doesn't change based on whether the deal gets done — which is the entire point of hiring it out.
AI-native depth.
I can tell real AI from an API wrapper, and I go where generalist tech-DD stops: training-data provenance and the legal right to use it, model performance and reproducibility, MLOps maturity, third-party API dependence, and regulatory and compliance exposure.
Fast enough for a live deal.
A working read in days, not weeks — sized to your timeline, not a firm's staffing model.
Right-sized.
Built for the deals the large firms overbuild for and a "friendly CTO" favor underserves — typically $2M to $50M in enterprise value.

Signature question

Real AI, or an API wrapper?

It's the first question I answer, and often the most expensive one to get wrong. Two companies can show the same demo; only one of them owns anything defensible.

Who I work with

Private equity & growth investors

A technical and AI go/no-go, pricing input, and risk-flagging on a live deal.

Corporate development / M&A teams

The same independent technical read, without pulling your own engineers off the roadmap.

Search funds & independent sponsors

You're buying a software or tech-enabled business and can't justify a six-figure firm. This is right-sized for you.

QoE & financial-DD firms

You sit in every deal but stop at the technical line. I become your technical arm on the engagements that need one, without touching your scope or your fees.

What I assess

Every engagement covers the technical foundation. Where AI is part of the thesis, it gets its own dedicated layer — the part most reviews miss.

The technical foundation

  • Architecture & scalability — will it survive the growth in your model, or does the roadmap depend on a rebuild?
  • Code quality & technical debt — what's real, what's fragile, and what it will cost to maintain.
  • Security — posture, exposure, and the gaps that become your liability at close.
  • Engineering team & key-person risk — where critical knowledge lives, and what happens if it walks.
  • Intellectual property — do they actually own what you think you’re buying?

The AI layer

  • Data provenance & rights — where the training data came from, and whether there's a legal right to use it.
  • Real AI vs. API wrapper — what's genuinely built versus rented from a third party.
  • Model performance & reproducibility — does it work outside the demo, and can it be rebuilt?
  • MLOps maturity — how models are versioned, deployed, monitored, and retrained.
  • Third-party API dependence — the concentration risk in the stack you’re acquiring.
  • Regulatory exposure — compliance obligations and legal risk in how the AI is built and used.

Three ways to engage

Every engagement is a fixed fee, agreed up front — no success fee, no contingency. Fees are scoped to the target and the timeline; I'll quote yours on our first call.

EngagementWhat it is
Red-flag screenA fast pre-LOI go/no-go. Surface-level architecture review, the obvious risks, and a short written summary. An intake filter, not a full report.
Confirmatory diligenceThe full technical and AI assessment: a risk-rated report and a debrief call. The read you base a decision on.
Deep / complexFor AI-core theses, complex stacks, or real regulatory exposure. Goes deep on provenance, reproducibility, MLOps, and data rights.

The red-flag screen is credited toward a confirmatory engagement if you upgrade within 30 days.

How I work

A short, predictable process built to fit a deal timeline.

The process

  1. 1Scope. A short call to understand the target, the thesis, and your timeline. I confirm fit, run a conflict check, and give you a fixed fee.
  2. 2Access & assessment. With data-room and repository access, I work through the technical and AI layers directly — code, architecture, documentation, and interviews with the target's team where useful.
  3. 3Risk-rated report. You get a written report that rates what I find by severity, in language a non-technical deal team can act on — not a jargon dump.
  4. 4Debrief. A call to walk the findings, answer questions, and pressure-test what they mean for your decision.

Independence, in writing

Independence isn't a claim here — it's how the engagement is structured. Fixed fee agreed before I start. No success fee, no contingency, no equity. Conflict checks before every engagement. Professional liability (E&O) coverage in place. Every engagement runs under a master services agreement, a mutual NDA, and a per-engagement statement of work with clear limitation-of-liability terms.

Terms

A deposit secures the engagement and the calendar slot; the balance is due on delivery or at agreed milestones. Fees are fixed. Standard terms are Net-15 or Net-30.

The deliverable

You're not paying for time. You're paying for a document you can put in front of an investment committee and a decision you can defend.

Every confirmatory and deep engagement ends with a risk-rated report and a debrief call. The report is written for the deal team, not for engineers: findings are rated by severity, tied to the impact on your thesis, and paired with the questions worth pushing on before you close.

A typical report covers:

  • An executive summary with an overall risk rating and the two or three things that actually matter.
  • Findings by area — architecture, code, security, team, IP, and the AI layer — each rated and explained in plain terms.
  • What each finding means for valuation, integration, or post-close risk.
  • Open questions and recommended conditions to raise before signing.

See a redacted sample report.

Twenty years building the systems I now evaluate.

I've architected AI document-processing pipelines, scaled a platform from one million to twenty million users, led engineering in regulated clinical environments, and been through an acquisition from the inside. I assess technology the way someone who has had to ship and scale it does — not from a checklist.

More about my background →

About

I'm Yuri Subach. I've spent twenty years as a software architect and engineering leader building and scaling the kinds of systems I now evaluate for buyers — and I assess technology the way someone who has had to ship it, secure it, and scale it does.

Yuri Subach
Interim photo — studio portrait pending.

Today I'm founder and CTO of Argentium, where I build AI-powered document-processing pipelines — LLMs, OCR, and data engineering in Python — deployed both in the cloud and on-premises. That work keeps me current on what real, production AI actually requires, which is exactly what makes the difference between a genuine capability and a demo.

Before that:

  • I was Director of Software Engineering for a decentralized clinical-trials SaaS platform — defining its architecture and technical stack and advising teams on compliance across HIPAA, SOC 2, and privacy law.
  • I was Senior Principal Software Engineer, architecting edge-and-cloud processing and hardening mobile security for decentralized clinical research. I went through acquisition from the inside — so I understand what diligence looks like from the target's side of the table.
  • I scaled backend systems to tens of millions of monthly users, using distributed data stores — so "will it scale" is not a theoretical question for me.

I hold a Master's in Computer Science Engineering (with honors, specialized in IT security).

Put together, that's AI infrastructure I've built myself, systems I've scaled by 20x, regulated environments I've shipped inside, and an acquisition I've lived through. It's why I can give buyers a read that holds up — on the technology, and on the AI.

AI technical due diligence

You're evaluating a company whose value rests on its AI, and you need to know if that value is real. AI technical due diligence answers the questions ordinary tech diligence isn't built for — before you commit capital.

Why AI needs its own diligence

Traditional technical due diligence assumes deterministic software: clear inputs, clear IP, measurable performance. AI breaks those assumptions. A model's value depends on where its training data came from and whether there's a right to use it, on whether results reproduce outside a demo, and on a data pipeline that has to keep working in production. Miss that, and it's easy to overpay for an impressive demo sitting on a fragile system.

What I look at

  • Whether the AI is genuinely built or rented from a third-party API
  • Training-data provenance and the legal right to use it
  • Model performance, reproducibility, and defensibility
  • MLOps maturity — how models are versioned, deployed, monitored, and retrained
  • Third-party API and vendor concentration risk
  • Regulatory and compliance exposure in how the AI is built and used

How it works

A fixed fee agreed up front, independent by design — no success fee, no contingency. A working read in days, delivered as a risk-rated report your deal team can act on, followed by a debrief call.

Written and delivered by Yuri Subach — a software architect with twenty years building and scaling production systems, including the AI infrastructure this kind of diligence is meant to test.

Have a deal in motion?

If you have a deal in motion, tell me the shape of it — the target, the thesis, and your timeline. I'll tell you whether and how I can help, usually the same day.

Engagements are confidential and run under a mutual NDA.