This is a sample. Sample report. Fernmoor is a fictional company. The structure and the kinds of findings follow a real Metamindz engagement, but every name, location, industry, technology and figure has been changed, and the report is much shorter than a real one.

Sample report: Fernmoor

Technical Due Diligence

An independent review of Fernmoor’s technology, delivery and security, commissioned by a UK family office considering a growth investment. Written so the investment committee can read the first two sections and stop there.

Prepared for
The investment committee of a UK family office (the Investor)
Prepared by
Metamindz: a fractional CTO and a senior engineer with experience in the stack under review
Company
Fernmoor Ltd (fictional): clinic management software for veterinary practice groups
Status
Initial assessment, one day on site plus a document review

Sample. Fictional company, anonymised from a real engagement.

Section 01

Scope and method

One day on site, a live walkthrough of the systems, interviews, and a review of the documents Fernmoor shared under NDA.

What we did

  • A screen-shared walkthrough of every system with Fernmoor’s technical lead
  • An account-by-account check of who holds access to what
  • Live performance measurements on the production dashboards
  • Interviews with the founders, the technical lead, support and a clinic customer
  • A review of the agency contract, the API documentation, the database structure and an external security scan

Section 02

Summary for the investment committee

Fernmoor has a product customers rely on, and a technology setup the company does not fully control. Overall technical risk: medium to high, most of it fixable within 100 days if the right conditions are agreed before completion.

Section 10 lists what to require before completion and what to do in the first 100 days. This report is a technical assessment. It is not financial, legal or investment advice.

Section 03

What is working

As observed during the visit.

Customers stay

The product is clearly valued by clinics. Staff we spoke to use it all day, and the support queue is dominated by feature requests rather than complaints.

Payments are handled properly

Card payments go through a regulated payment provider. Fernmoor never stores card numbers, which removes the largest category of compliance risk.

The API refuses strangers

An external security scan tested every API endpoint it found. All of them refused requests without a valid login. No owner or patient records were reachable without authentication.

A capable in-house lead

Fernmoor’s one technical employee understands the platform well and is the main reason it runs as smoothly as it does. That is a strength, and also a key-person risk (Section 04).

Section 04

Control of systems

Reviewed live, account by account.

17Systems reviewed
Seventeen systems reviewed. Hover or focus a row to see which systems sit in each category.

What that means in practice

  • Fernmoor cannot read its own source code
  • Fernmoor cannot release a fix without the agency
  • Fernmoor cannot publish or withdraw its own Android app
  • Nobody at Fernmoor can confirm where backups are kept, or that one has ever been restored

To establish

Whether backups are held in storage Fernmoor controls, and when a restore was last tested.

Section 05

Cost of the current arrangement

£38,500

Monthly agency charge

Excluding VAT, rising with inflation each April

~5

People on the account

Three developers, one of them senior, plus an account manager

~£230k

Cost of leaving

Six months’ notice at the current rate

Annual cost: agency against an in-house team

Current agency arrangement£460k – £475k

About five people. No QA, product manager or infrastructure engineer.

Equivalent in-house team£430k – £475k

Two senior developers, one mid-level developer, a part-time QA engineer, a part-time infrastructure engineer and a product manager, at 2026 UK employer cost.

Both figures are annual and exclude VAT. On headline cost the two are close; the difference is in what the money buys.

The agency contract assigns the code to Fernmoor as it is written, and obliges the agency to hand it over on request. That is good news. The contract has simply never been enforced.

Section 06

Delivery practice

  • No QA function. Fernmoor’s technical lead tests every release by hand, usually the evening before it ships.
  • The staging environment holds a copy of live data, including pet owners’ names, addresses and phone numbers.
  • Database changes are applied straight to production, with no rehearsal on a copy first.
  • No time is set aside for maintenance. Work on old code happens only when something breaks.
  • Releases now happen about once every four weeks, down from weekly a year ago.

Section 07

Performance

Measured on the day, on production.

~40s

Daily dashboard, largest customer

A group of about 60 clinics

3s

Typical appointment search

Measured on the day, mid-morning

Weekly

Manual server restarts

Reported by staff, not logged anywhere

Section 08

The AI claims

The investor deck describes “AI-powered triage”. This is what we saw.

  • Symptom triage is a set of hand-written rules maintained by a vet on contract. It works and is clinically reviewed, which is to its credit.
  • A third-party language model service rewrites the rules engine’s output into a friendly summary for pet owners. Fernmoor does not train or own a model.
  • Owner names and pet details are sent to that service. The privacy notice does not mention it, and there is no data processing agreement on file.
  • Nobody has tested how the summaries behave when given unusual or misleading input.

Section 09

Security

From an external vulnerability scan run four weeks before our visit, plus our own observations.

Findings by severity

Sixteen findings in total. One high, no critical.

Main findings

  • H1

    Severity

    High
    Live customer data in the staging environment, reachable by agency staff whose access has never been reviewed
    Personal data is in more places, and with more people, than Fernmoor knows about. Under UK GDPR that is Fernmoor’s problem, not the agency’s.
  • M1

    Severity

    Medium
    Outdated front-end library on the booking widget, with published cross-site scripting issues
    A known weakness that attackers scan for. A small, well understood fix.
  • M2

    Severity

    Medium
    API documentation published openly, listing every endpoint
    Not a breach in itself, but it gives an attacker a map.
  • M3

    Severity

    Medium
    Server admin login pages exposed to the internet on the marketing site host
    A door that should not face the street. Usually a configuration change.
  • M4

    Severity

    Medium
    Missing security headers on the owner app’s web version
    Basic browser protections switched off. Quick to fix.
  • L1

    Severity

    Low
    Expired certificate on a forgotten subdomain
    A sign nobody keeps an inventory of what is live.

Section 10

Before and after completion

  • When

    Before completion
    Source code deposited in a repository Fernmoor owns, with full historyWithout it, the asset being invested in is not fully in the company’s hands.
  • When

    Before completion
    Evidence of a successful backup restoreThe single most important unknown in this report.
  • When

    Before completion
    Live customer data removed from stagingCloses the one high-severity finding.
  • When

    First 30 days
    Fernmoor-only admin accounts on the cloud subscription, domains and app storesRemoves sole dependence on credentials the agency holds.
  • When

    First 30 days
    Data processing agreement for the language model service, and an updated privacy noticeBrings the AI feature inside UK GDPR.
  • When

    First 100 days
    Full code and database review, with the restart pattern and dashboard speed diagnosedDecides whether performance needs a defined fix or a rebuild.
  • When

    First 100 days
    A costed plan for the agency relationship: renegotiate, hybrid or move in-houseThe largest line in the cost base, currently set without data.

Items marked “before completion” are the technical conditions we would want satisfied. Whether and how to make them conditions of the investment is a decision for the Investor and its legal advisers.

Section 11

Open questions

Each needs access to the code, the cloud subscription or the delivery history.

  • Is the slow dashboard caused by missing database indexes, by how reports are built, or by the data model itself?
  • Why do the servers need restarting each week, and what fails just before they do?
  • How much of the platform does only one person understand?
  • Are the three white-label clinic apps one codebase or three?
  • Which open-source licences are in use, and do any restrict commercial use?

Want one of these before you invest?

A real report is much longer, with evidence and screenshots behind every finding. Most cost £5,000 to £25,000, fixed in advance after a free call.

Sample report. Fictional company. Not financial, legal or investment advice.