Technical due diligence · independent engineering review

Technical due diligence services
for crypto and fintech deals.

TrustChange is a technical due diligence consulting firm for EU-facing crypto and fintech. We give investors, acquirers and operators an independent read of the engineering — architecture, custody, payments, controls, security, delivery and team — as a written report with a ranked risk register, a control map and a remediation plan. Not a checklist scan, not a rebrand of legal advice.

  • EU-based reviewers
  • Crypto & fintech depth
  • Written NDA per engagement
  • Independence disclosed in report

What TDD means here

Technical due diligence consulting without a generic checklist

Most technical due diligence firms run a generic checklist and hand back a PDF. We work the other way. Our technical due diligence consultants read the system as engineers who have built exchange, custody, payment and compliance stacks themselves. That yields specific, source-linked findings a builder or a deal team can actually act on — and a report that names what we did not read as clearly as what we did.

Scoping a build after the diligence? See CTO advisory, fixed-scope product build, dedicated development teams or nearshore staff augmentation.

Scope areas

Four scope areas in every technical due diligence services engagement

We tailor scope to the deal or the launch, but every engagement covers these four reads — because a stack that looks clean in one and messy in another usually decides price, terms or launch date.

  • 01

    Architecture & code

    Read the system as it actually runs: service topology, data model, event log, third-party dependencies and the health of the codebase and its tests.

    • Topology & data model
    • Dependency & licence scan
    • Test coverage & CI health
  • 02

    Custody, keys & signing

    For any crypto scope: key material, MPC or HSM setup, hot / warm / cold tiers, withdrawal policy, quorum and the evidence trail behind them.

    • Key custody model
    • Signing paths & policy
    • Ceremony documentation
  • 03

    Compliance & controls

    Read the controls in code: KYC/KYB, sanctions and wallet-risk screening, Travel Rule, PSD2 flow handling, GDPR data mapping and the audit log those controls write to.

    • Control map to policy
    • Audit log & evidence
    • Regulator-shaped exports
  • 04

    Team, delivery & risk

    Read the delivery signal: change frequency, on-call posture, incident and rollback record, roadmap dependencies, key-person risk and how the team actually ships.

    • Change & incident record
    • On-call and rollback posture
    • Key-person risk

Review matrix

What technical due diligence consultants actually read

Eight layers, one review. Every layer names what we check and the artefact you receive — nothing is left implied under the "diligence" label.

Delivery patterns and evidence: how we deliver. Wider company view: about TrustChange. Company-level engineering: crypto software development company.

Reference review matrix used by our technical due diligence specialists
LayerWhat we checkWhat you receive
Architecture & scaling Service boundaries, data flow, single points of failure, deterministic replay of key paths Diagram + written findings, ranked by blast radius
Codebase health Repo layout, static analysis, test coverage on money-moving paths, dependency and licence scan Health scorecard with source-linked findings
Custody & keys MPC / HSM setup, tier split, withdrawal policy, quorum, allow-lists, ceremony evidence Custody model diagram + control gap list
Payment & ledger Router, double-entry ledger, reconciliation, retries, idempotency, refund and chargeback paths Money-flow diagram + risk register
Compliance controls KYC/KYB, sanctions, Travel Rule, PSD2 fields, GDPR mapping, audit log integrity Control-to-policy map + evidence sample
Security posture Identity & access, secrets, egress, key rotation, third-party review history, pen-test posture Security findings list, prioritised by exploitability
Delivery & operations CI/CD, change frequency, on-call, incident record, rollback posture, runbook coverage Delivery signal report + operational readiness view
Team & knowledge Team shape, key-person concentration, documentation quality, cross-training, roadmap dependencies Team & continuity risk list

How it runs

How a TDD engagement runs, week by week

Five steps, in this order. A typical technical due diligence consulting services engagement runs three to five weeks; complex or multi-entity targets can extend by agreement.

For AML-specific reads see AML case management software development and compliance workflow software development. Rule mapping: compliance engineering.

  1. 01

    Scoping

    Week 1

    We agree the target, the deal or launch timeline, the areas in and out of scope, and the access we need. Output: a written brief and a data-room checklist.

  2. 02

    Access & sampling

    Week 1–2

    Read-only access to code, infrastructure and docs; interviews with lead engineers, ops and compliance; sampling plan agreed with your team.

  3. 03

    Deep review

    Weeks 2–3

    Independent engineering review across the eight layers above. Findings are captured as we go, source-linked and ranked by blast radius.

  4. 04

    Draft report

    Week 3–4

    A draft report with findings, a ranked risk register, a control map and remediation options. Draft is reviewed with the target team before final.

  5. 05

    Final report & briefing

    End of engagement

    Final report delivered to the commissioning party, with an optional briefing session for investors, deal team or the operator's board.

After diligence

Four ways to act on the findings

Diligence is the read, not the fix. If you want TrustChange to help execute the remediation plan, four commercial shapes cover most cases — but there is no bundled remediation contract behind the diligence work.

  • CTO advisory

    Architecture and hiring guidance around the plan. Best when direction is the question.

  • Fixed-scope build

    A defined remediation scope at a fixed price and date. Best when the plan is settled.

  • Dedicated team

    A standing squad executing the roadmap. Best for multi-quarter remediation.

  • Staff augmentation

    Senior engineers inside your team. Best when your team leads and needs depth on gaps.

Questions

FAQ: technical due diligence services

Six answers up front on scope, differentiation, buyer vs operator, confidentiality & independence, area strengths and post-report support. Bring the rest to the call.

What do technical due diligence services from TrustChange cover?

We deliver independent engineering review across architecture and code, custody and keys, payment and ledger, compliance controls, security posture, delivery and operations, and team continuity. Output is a written report with a ranked risk register, a control map, an architecture view and a prioritised remediation plan — with source-linked findings a reviewer can trace. TrustChange is a technical due diligence consulting firm and an engineering partner; we are not a law firm, a QSA or a financial adviser.

How is your work different from other technical due diligence firms?

Most technical due diligence companies review a codebase against a generic checklist. TrustChange is a crypto and fintech engineering group that has built exchange, custody, payment and compliance systems ourselves. That means our technical due diligence consultants read a matching engine, an MPC signing path or an AML control the way an operator would — the review lands with more specific findings and a remediation plan a builder can actually work.

Do you serve investors and acquirers, or operators, or both?

Both. Investors and acquirers commission technical due diligence consulting services pre-deal to shape the price, the terms and the post-close plan. Operators commission TDD pre-launch, pre-audit or as a scheduled re-read of their own stack. The scope changes with the buyer, but the eight-layer review matrix on this page is the same. We are transparent about which party commissioned the work in the report itself.

How do you handle confidentiality, data access and independence?

Every engagement runs under a written NDA with the commissioning party and, where relevant, a separate NDA with the target. Access is read-only by default — code, dashboards and interview time — with any live-environment access limited to what the target explicitly agrees. TrustChange has no equity or reseller relationship with the vendors or products it reviews, and any prior work with either party is disclosed in the report so the reader can weigh independence.

What areas of crypto and fintech TDD are your technical due diligence specialists strongest in?

Crypto: exchange (matching, order-flow, market surveillance), wallet and custody (MPC, HSM, ceremony evidence), on- and off-ramp integration, Travel Rule and screening. Fintech: payment gateways, double-entry ledger and reconciliation, PSD2 flows, KYC/KYB and monitoring, banking-side controls. We say up front which areas we are strongest in and which we would bring a named partner for, rather than pretending to cover everything at the same depth.

Can you also help with remediation after the report?

Yes, if you want it. Some clients hand the report to their own team and take the remediation in-house — we support that with clarification calls at no extra cost during a defined window. Others engage TrustChange separately as a dedicated development team, on staff augmentation or on a fixed-scope build to execute the plan. The choice is yours, and we say so in the report; there is no bundled remediation contract behind the diligence work.

Book a discovery call with our technical due diligence specialists

Bring the target, the deal or launch timeline, the areas that worry you most and what access the target will grant. We come back with a scoping brief, a data-room checklist and a costed plan. No demo theatre.