Technical due diligence · independent engineering review
Technical due diligence services
for crypto and fintech deals.
TrustChange is a technical due diligence consulting firm for EU-facing crypto and fintech. We give investors, acquirers and operators an independent read of the engineering — architecture, custody, payments, controls, security, delivery and team — as a written report with a ranked risk register, a control map and a remediation plan. Not a checklist scan, not a rebrand of legal advice.
- EU-based reviewers
- Crypto & fintech depth
- Written NDA per engagement
- Independence disclosed in report
What TDD means here
Technical due diligence consulting without a generic checklist
Most technical due diligence firms run a generic checklist and hand back a PDF. We work the other way. Our technical due diligence consultants read the system as engineers who have built exchange, custody, payment and compliance stacks themselves. That yields specific, source-linked findings a builder or a deal team can actually act on — and a report that names what we did not read as clearly as what we did.
Scoping a build after the diligence? See CTO advisory, fixed-scope product build, dedicated development teams or nearshore staff augmentation.
Scope areas
Four scope areas in every technical due diligence services engagement
We tailor scope to the deal or the launch, but every engagement covers these four reads — because a stack that looks clean in one and messy in another usually decides price, terms or launch date.
-
01
Architecture & code
Read the system as it actually runs: service topology, data model, event log, third-party dependencies and the health of the codebase and its tests.
- Topology & data model
- Dependency & licence scan
- Test coverage & CI health
-
02
Custody, keys & signing
For any crypto scope: key material, MPC or HSM setup, hot / warm / cold tiers, withdrawal policy, quorum and the evidence trail behind them.
- Key custody model
- Signing paths & policy
- Ceremony documentation
-
03
Compliance & controls
Read the controls in code: KYC/KYB, sanctions and wallet-risk screening, Travel Rule, PSD2 flow handling, GDPR data mapping and the audit log those controls write to.
- Control map to policy
- Audit log & evidence
- Regulator-shaped exports
-
04
Team, delivery & risk
Read the delivery signal: change frequency, on-call posture, incident and rollback record, roadmap dependencies, key-person risk and how the team actually ships.
- Change & incident record
- On-call and rollback posture
- Key-person risk
Review matrix
What technical due diligence consultants actually read
Eight layers, one review. Every layer names what we check and the artefact you receive — nothing is left implied under the "diligence" label.
Delivery patterns and evidence: how we deliver. Wider company view: about TrustChange. Company-level engineering: crypto software development company.
| Layer | What we check | What you receive |
|---|---|---|
| Architecture & scaling | Service boundaries, data flow, single points of failure, deterministic replay of key paths | Diagram + written findings, ranked by blast radius |
| Codebase health | Repo layout, static analysis, test coverage on money-moving paths, dependency and licence scan | Health scorecard with source-linked findings |
| Custody & keys | MPC / HSM setup, tier split, withdrawal policy, quorum, allow-lists, ceremony evidence | Custody model diagram + control gap list |
| Payment & ledger | Router, double-entry ledger, reconciliation, retries, idempotency, refund and chargeback paths | Money-flow diagram + risk register |
| Compliance controls | KYC/KYB, sanctions, Travel Rule, PSD2 fields, GDPR mapping, audit log integrity | Control-to-policy map + evidence sample |
| Security posture | Identity & access, secrets, egress, key rotation, third-party review history, pen-test posture | Security findings list, prioritised by exploitability |
| Delivery & operations | CI/CD, change frequency, on-call, incident record, rollback posture, runbook coverage | Delivery signal report + operational readiness view |
| Team & knowledge | Team shape, key-person concentration, documentation quality, cross-training, roadmap dependencies | Team & continuity risk list |
How it runs
How a TDD engagement runs, week by week
Five steps, in this order. A typical technical due diligence consulting services engagement runs three to five weeks; complex or multi-entity targets can extend by agreement.
For AML-specific reads see AML case management software development and compliance workflow software development. Rule mapping: compliance engineering.
- 01
Scoping
Week 1
We agree the target, the deal or launch timeline, the areas in and out of scope, and the access we need. Output: a written brief and a data-room checklist.
- 02
Access & sampling
Week 1–2
Read-only access to code, infrastructure and docs; interviews with lead engineers, ops and compliance; sampling plan agreed with your team.
- 03
Deep review
Weeks 2–3
Independent engineering review across the eight layers above. Findings are captured as we go, source-linked and ranked by blast radius.
- 04
Draft report
Week 3–4
A draft report with findings, a ranked risk register, a control map and remediation options. Draft is reviewed with the target team before final.
- 05
Final report & briefing
End of engagement
Final report delivered to the commissioning party, with an optional briefing session for investors, deal team or the operator's board.
After diligence
Four ways to act on the findings
Diligence is the read, not the fix. If you want TrustChange to help execute the remediation plan, four commercial shapes cover most cases — but there is no bundled remediation contract behind the diligence work.
-
CTO advisory
Architecture and hiring guidance around the plan. Best when direction is the question.
-
Fixed-scope build
A defined remediation scope at a fixed price and date. Best when the plan is settled.
-
Dedicated team
A standing squad executing the roadmap. Best for multi-quarter remediation.
-
Staff augmentation
Senior engineers inside your team. Best when your team leads and needs depth on gaps.
Questions
FAQ: technical due diligence services
Six answers up front on scope, differentiation, buyer vs operator, confidentiality & independence, area strengths and post-report support. Bring the rest to the call.
What do technical due diligence services from TrustChange cover?
We deliver independent engineering review across architecture and code, custody and keys, payment and ledger, compliance controls, security posture, delivery and operations, and team continuity. Output is a written report with a ranked risk register, a control map, an architecture view and a prioritised remediation plan — with source-linked findings a reviewer can trace. TrustChange is a technical due diligence consulting firm and an engineering partner; we are not a law firm, a QSA or a financial adviser.
How is your work different from other technical due diligence firms?
Most technical due diligence companies review a codebase against a generic checklist. TrustChange is a crypto and fintech engineering group that has built exchange, custody, payment and compliance systems ourselves. That means our technical due diligence consultants read a matching engine, an MPC signing path or an AML control the way an operator would — the review lands with more specific findings and a remediation plan a builder can actually work.
Do you serve investors and acquirers, or operators, or both?
Both. Investors and acquirers commission technical due diligence consulting services pre-deal to shape the price, the terms and the post-close plan. Operators commission TDD pre-launch, pre-audit or as a scheduled re-read of their own stack. The scope changes with the buyer, but the eight-layer review matrix on this page is the same. We are transparent about which party commissioned the work in the report itself.
How do you handle confidentiality, data access and independence?
Every engagement runs under a written NDA with the commissioning party and, where relevant, a separate NDA with the target. Access is read-only by default — code, dashboards and interview time — with any live-environment access limited to what the target explicitly agrees. TrustChange has no equity or reseller relationship with the vendors or products it reviews, and any prior work with either party is disclosed in the report so the reader can weigh independence.
What areas of crypto and fintech TDD are your technical due diligence specialists strongest in?
Crypto: exchange (matching, order-flow, market surveillance), wallet and custody (MPC, HSM, ceremony evidence), on- and off-ramp integration, Travel Rule and screening. Fintech: payment gateways, double-entry ledger and reconciliation, PSD2 flows, KYC/KYB and monitoring, banking-side controls. We say up front which areas we are strongest in and which we would bring a named partner for, rather than pretending to cover everything at the same depth.
Can you also help with remediation after the report?
Yes, if you want it. Some clients hand the report to their own team and take the remediation in-house — we support that with clarification calls at no extra cost during a defined window. Others engage TrustChange separately as a dedicated development team, on staff augmentation or on a fixed-scope build to execute the plan. The choice is yours, and we say so in the report; there is no bundled remediation contract behind the diligence work.
Book a discovery call with our technical due diligence specialists
Bring the target, the deal or launch timeline, the areas that worry you most and what access the target will grant. We come back with a scoping brief, a data-room checklist and a costed plan. No demo theatre.