This is a sample. Sample report. Fernmoor is a fictional company. The structure and the kinds of findings follow a real Metamindz engagement, but every name, location, industry, technology and figure has been changed, and the report is much shorter than a real one.
Sample report: Fernmoor
Technical Due Diligence
An independent review of Fernmoor’s technology, delivery and security, commissioned by a UK family office considering a growth investment. Written so the investment committee can read the first two sections and stop there.
- Prepared for
- The investment committee of a UK family office (the Investor)
- Prepared by
- Metamindz: a fractional CTO and a senior engineer with experience in the stack under review
- Company
- Fernmoor Ltd (fictional): clinic management software for veterinary practice groups
- Status
- Initial assessment, one day on site plus a document review
Sample. Fictional company, anonymised from a real engagement.
Section 01
Scope and method
One day on site, a live walkthrough of the systems, interviews, and a review of the documents Fernmoor shared under NDA.
What we did
- A screen-shared walkthrough of every system with Fernmoor’s technical lead
- An account-by-account check of who holds access to what
- Live performance measurements on the production dashboards
- Interviews with the founders, the technical lead, support and a clinic customer
- A review of the agency contract, the API documentation, the database structure and an external security scan
Section 02
Summary for the investment committee
Fernmoor has a product customers rely on, and a technology setup the company does not fully control. Overall technical risk: medium to high, most of it fixable within 100 days if the right conditions are agreed before completion.
Section 10 lists what to require before completion and what to do in the first 100 days. This report is a technical assessment. It is not financial, legal or investment advice.
Section 03
What is working
As observed during the visit.
Customers stay
Payments are handled properly
The API refuses strangers
A capable in-house lead
Section 04
Control of systems
Reviewed live, account by account.
What that means in practice
- Fernmoor cannot read its own source code
- Fernmoor cannot release a fix without the agency
- Fernmoor cannot publish or withdraw its own Android app
- Nobody at Fernmoor can confirm where backups are kept, or that one has ever been restored
To establish
Whether backups are held in storage Fernmoor controls, and when a restore was last tested.
Section 05
Cost of the current arrangement
£38,500
Monthly agency charge
Excluding VAT, rising with inflation each April
~5
People on the account
Three developers, one of them senior, plus an account manager
~£230k
Cost of leaving
Six months’ notice at the current rate
Annual cost: agency against an in-house team
About five people. No QA, product manager or infrastructure engineer.
Two senior developers, one mid-level developer, a part-time QA engineer, a part-time infrastructure engineer and a product manager, at 2026 UK employer cost.
The agency contract assigns the code to Fernmoor as it is written, and obliges the agency to hand it over on request. That is good news. The contract has simply never been enforced.
Section 06
Delivery practice
- No QA function. Fernmoor’s technical lead tests every release by hand, usually the evening before it ships.
- The staging environment holds a copy of live data, including pet owners’ names, addresses and phone numbers.
- Database changes are applied straight to production, with no rehearsal on a copy first.
- No time is set aside for maintenance. Work on old code happens only when something breaks.
- Releases now happen about once every four weeks, down from weekly a year ago.
Section 07
Performance
Measured on the day, on production.
~40s
Daily dashboard, largest customer
A group of about 60 clinics
3s
Typical appointment search
Measured on the day, mid-morning
Weekly
Manual server restarts
Reported by staff, not logged anywhere
Section 08
The AI claims
The investor deck describes “AI-powered triage”. This is what we saw.
- Symptom triage is a set of hand-written rules maintained by a vet on contract. It works and is clinically reviewed, which is to its credit.
- A third-party language model service rewrites the rules engine’s output into a friendly summary for pet owners. Fernmoor does not train or own a model.
- Owner names and pet details are sent to that service. The privacy notice does not mention it, and there is no data processing agreement on file.
- Nobody has tested how the summaries behave when given unusual or misleading input.
Section 09
Security
From an external vulnerability scan run four weeks before our visit, plus our own observations.
Findings by severity
Main findings
| Ref | Finding | In plain English | |
|---|---|---|---|
| H1 | High | Live customer data in the staging environment, reachable by agency staff whose access has never been reviewed | Personal data is in more places, and with more people, than Fernmoor knows about. Under UK GDPR that is Fernmoor’s problem, not the agency’s. |
| M1 | Medium | Outdated front-end library on the booking widget, with published cross-site scripting issues | A known weakness that attackers scan for. A small, well understood fix. |
| M2 | Medium | API documentation published openly, listing every endpoint | Not a breach in itself, but it gives an attacker a map. |
| M3 | Medium | Server admin login pages exposed to the internet on the marketing site host | A door that should not face the street. Usually a configuration change. |
| M4 | Medium | Missing security headers on the owner app’s web version | Basic browser protections switched off. Quick to fix. |
| L1 | Low | Expired certificate on a forgotten subdomain | A sign nobody keeps an inventory of what is live. |
H1
Severity
HighLive customer data in the staging environment, reachable by agency staff whose access has never been reviewedPersonal data is in more places, and with more people, than Fernmoor knows about. Under UK GDPR that is Fernmoor’s problem, not the agency’s.M1
Severity
MediumOutdated front-end library on the booking widget, with published cross-site scripting issuesA known weakness that attackers scan for. A small, well understood fix.M2
Severity
MediumAPI documentation published openly, listing every endpointNot a breach in itself, but it gives an attacker a map.M3
Severity
MediumServer admin login pages exposed to the internet on the marketing site hostA door that should not face the street. Usually a configuration change.M4
Severity
MediumMissing security headers on the owner app’s web versionBasic browser protections switched off. Quick to fix.L1
Severity
LowExpired certificate on a forgotten subdomainA sign nobody keeps an inventory of what is live.
Section 10
Before and after completion
| Action | |
|---|---|
| Before completion | Source code deposited in a repository Fernmoor owns, with full historyWithout it, the asset being invested in is not fully in the company’s hands. |
| Before completion | Evidence of a successful backup restoreThe single most important unknown in this report. |
| Before completion | Live customer data removed from stagingCloses the one high-severity finding. |
| First 30 days | Fernmoor-only admin accounts on the cloud subscription, domains and app storesRemoves sole dependence on credentials the agency holds. |
| First 30 days | Data processing agreement for the language model service, and an updated privacy noticeBrings the AI feature inside UK GDPR. |
| First 100 days | Full code and database review, with the restart pattern and dashboard speed diagnosedDecides whether performance needs a defined fix or a rebuild. |
| First 100 days | A costed plan for the agency relationship: renegotiate, hybrid or move in-houseThe largest line in the cost base, currently set without data. |
When
Before completionSource code deposited in a repository Fernmoor owns, with full historyWithout it, the asset being invested in is not fully in the company’s hands.When
Before completionEvidence of a successful backup restoreThe single most important unknown in this report.When
Before completionLive customer data removed from stagingCloses the one high-severity finding.When
First 30 daysFernmoor-only admin accounts on the cloud subscription, domains and app storesRemoves sole dependence on credentials the agency holds.When
First 30 daysData processing agreement for the language model service, and an updated privacy noticeBrings the AI feature inside UK GDPR.When
First 100 daysFull code and database review, with the restart pattern and dashboard speed diagnosedDecides whether performance needs a defined fix or a rebuild.When
First 100 daysA costed plan for the agency relationship: renegotiate, hybrid or move in-houseThe largest line in the cost base, currently set without data.
Items marked “before completion” are the technical conditions we would want satisfied. Whether and how to make them conditions of the investment is a decision for the Investor and its legal advisers.
Section 11
Open questions
Each needs access to the code, the cloud subscription or the delivery history.
- Is the slow dashboard caused by missing database indexes, by how reports are built, or by the data model itself?
- Why do the servers need restarting each week, and what fails just before they do?
- How much of the platform does only one person understand?
- Are the three white-label clinic apps one codebase or three?
- Which open-source licences are in use, and do any restrict commercial use?
Want one of these before you invest?
A real report is much longer, with evidence and screenshots behind every finding. Most cost £5,000 to £25,000, fixed in advance after a free call.
Sample report. Fictional company. Not financial, legal or investment advice.