Technical due diligence for VC & corporates · Zurich

We separate the science from the science fiction.

Independent technical due diligence on deep tech deals, led by PhD-level industry experts in the exact technology you are looking at. A first read within 24 hours, a full report inside two weeks, and every finding tied to what it means for the investment.

100+ tech due diligences & reviews
Reply within one business day
Pitch deck · what they sayTechnical assessment · what we foundSee what it found →
Technical assessment · ConfidentialDTE-26-041 · Example

Photonic interconnect startup, Series A

Lead expert: applied quantum & photonics · 14 days · 3 dimensions
Proceed, with conditions
Technology readiness
TRL 6 · claimed 8
Key-person dependency on a single photonics PhD; no documented process knowledge
Bench results at 4 nodes; no evidence of scaling beyond lab conditions
Core patent claims overlap 2019 prior art; freedom to operate not assessed
No load test beyond the current user base; single-region deployment, no recovery plan
Technology · Business · PeopleRedacted
Scroll
100+Tech due diligences & reviews
combined experience
8Deep tech domains
2 wkSeed to A report
≤ 24 hFirst response
Expert backgrounds
ETH ZürichETH ZürichEPFLEPFLImperial CollegeImperial CollegeGoogleGoogleIBMIBMWorld Economic ForumWorld Economic ForumUnit 8200Unit 8200
Trusted by
High-Tech GründerfondsHigh-Tech GründerfondsEquityPitcherEquityPitcherPostFinancePostFinanceKodoriKodoriPwCPwCSwiss SECOSwiss SECOQBIT CapitalQBIT CapitalLightbirdLightbirdAcormaAcormaWorld Economic ForumWorld Economic Forum
What an assessment finds

Deep tech is a black box, until it isn't.

Groundbreaking science and sophisticated science fiction look identical from the outside. Here is one Series A deal, five claims from the deck, and what we found.

One Series A deal · five claims · composite of real engagements
The pitch deck saysWhat we found
“TRL 8, ready for pilot deployment.”
TRL 6. Bench demonstration at four nodes, no field data, coherence not measured at operating scale.
“Patented core architecture.”
Two patents granted. Independent claims overlap 2019 prior art; freedom to operate never assessed.
“A team of twelve engineers.”
Core photonics knowledge sits with one PhD. No documented process; her departure would halt the roadmap.
“Cloud-native, scales linearly.”
No load test beyond the current user base. Single-region deployment with no recovery plan.
“SOC 2 in progress.”
No penetration test on record. API keys committed to repository history, retrievable after deletion.
Two critical, three high · valuation renegotiated · deal closed with milestones  Verdict: proceed, with conditions
JW

Have a deal like this on the table?

Send the deck. Julien reads it personally and tells you within one business day whether a full assessment is worth it, and what it would cost.

Send the deck →
360° method

Technology, business, and people.

A technical due diligence that only looks at code misses the full picture. We evaluate all three dimensions that determine whether a deep tech startup will actually succeed, and the report places the deal inside the triangle so your committee sees at a glance where the risk sits.

Technology Business People Photonic interconnect · Series A Strong science · thin team
Dimension 01

Technology

What the methods, code, data, and results actually mean.

  • Is the approach defensible?
  • Is the architecture scalable?
  • Do the claims hold up under independent scrutiny?
Dimension 02

Business

How the technology can solve real problems and create commercial value.

  • Does it address the stated use case?
  • Could it be applied elsewhere or sold as separate products?
Dimension 03

People

Skillset, team cohesion, and transparency.

  • Have key people left?
  • Is the team capable of executing the roadmap?
  • Are they being straight with you?
We evaluate

Defensibility

How difficult is it to replicate? Is there a real moat, or is this an off-the-shelf approach with a good story?

We evaluate

Scalability

How well will the technology follow growth? Will the architecture hold under production load?

We evaluate

Claims

Do experiments reflect real-world performance? Does the code match what was presented? Are benchmarks rigorous?

We collaborate with

Legal & Financial

We work alongside your legal and financial due diligence teams for complete, integrated coverage.

Positioning orrery Technical rigour rises up the plate, commercial context runs to the right. Deep Tech Experts is fixed in the top-right quadrant. Research labs, IT consultants and Big 4 audit teams each orbit inside their own quadrant. Low commercial context High commercial context → Technical rigour → Feasibility, not viability Generalist reviews Checks the process Deep Tech Experts Applied deep tech

Positions are illustrative · Orbits show that each approach stays inside its quadrant

Why us

Rigour and context, in the same room.

A lab tells you whether the science is possible. An auditor tells you whether the process was followed. Neither tells you whether this company can turn the science into the product in the deck. We do both, because our experts have done both.

  • University and research labsFeasibility only
  • Generalist IT consultantsNo domain depth
  • Big 4 and in-house M&AProcess, not code
  • Deep Tech ExpertsBoth, in two weeks
Plate 01 · Every technology leaves a signatureDeep Tech Experts
Calibrated to your stage

The same method, at four depths.

Pre-seed to M&A. Approach, timeline and deliverables match where the deal is, so a same-day read is possible when that is all the round allows.

Not sure which depth you need? Send the deck; the answer comes back with the reply, at no cost.
Eight specialisms

A domain expert, not a generalist.

Every audit is led by someone who has published in, built in, or led teams within the exact technology.

Artificial intelligence
Deep LearningComputer VisionLLMs
Cybersecurity
PentestingCryptographyZero Trust
Quantum computing
AlgorithmsHardwarePhotonics
Encryption
CryptographyPost-Quantum
Aerospace
GNC
Robotics
PerceptionControlAutonomy
Systems architecture
Cloud NativeScalabilityDatabases
Semiconductors
Chip DesignPhotonics
The risk register · 36 findings

Thirty-six ways a deal goes wrong.

Every risk we have logged across a hundred diligences, mapped by domain and severity. The closer to the centre, the more often it kills a deal.

Composite of real engagements · anonymised
The full register · 36 findings · eight domainsRead every finding as text.Each risk with its regulatory anchor, plus how we turn findings into a recommendation.

AiArtificial intelligence

Regulatory exposure & technical safety gaps

  • EU AI Act classificationsystem misclassified as limited-risk when it meets high-risk criteria under Annex III; triggers full conformity assessment obligations
  • Explainability gapsArticle 13 transparency requirements not met; black-box models in regulated sectors (credit, hiring, healthcare) face immediate compliance blocks
  • Training data provenanceundisclosed use of scraped or licensed data; GDPR and copyright liability unquantified
  • Jailbreak surfaceLLM-based products with no adversarial testing; prompt injection, goal hijacking, and output manipulation not evaluated
  • Model driftno monitoring pipeline in production; accuracy degradation post-deployment undetected

Critical when present · Very high frequency in AI deals

CyCybersecurity

Vulnerabilities that invalidate the valuation

  • No penetration test on recordor last test >18 months ago; unvetted attack surface in a product handling customer data
  • Hardcoded credentialsAPI keys, passwords, and tokens committed to version control history; often retrievable even after deletion
  • CVE backlogknown critical vulnerabilities in production dependencies unpatched; CVSS ≥7.0 items unaddressed for >90 days
  • No incident response planGDPR Article 33 requires 72-hour breach notification; no documented procedure means regulatory penalty is near-certain post-incident
  • Single-factor admin accesscloud consoles, CI/CD pipelines, and production databases accessible without MFA

Critical · Unpatched vulnerabilities can void cyber insurance and trigger GDPR breach liability

QcQuantum computing

TRL inflation and roadmap dependencies

  • TRL inflationlab demonstration at 5–10 qubits marketed as a scalable product; coherence times and gate fidelities not disclosed at operating scale
  • Error correction overhead not modelledlogical qubit counts assume perfect hardware; fault-tolerant qubit cost (1000:1 physical-to-logical ratio) not in financial projections
  • Quantum advantage unprovenclaimed speedup not demonstrated against best classical algorithm on problem-relevant input sizes
  • Hardware supplier dependencyalgorithm layer dependent on specific hardware vendor (IBM, IonQ, etc.) with no commercial SLA for qubit access at scale

High frequency · TRL gap is the defining risk in quantum deals

EnEncryption

Deprecated standards and post-quantum exposure

  • Deprecated algorithms in productionMD5, SHA-1, RSA-1024, or 3DES still active in authentication or data-at-rest; known-broken and no migration plan
  • Key management gapssymmetric keys hardcoded or stored in environment variables; no HSM or secrets manager in use; rotation policy absent
  • Post-quantum migration not scopedNIST PQC standards (ML-KEM, ML-DSA) finalised 2024; no assessment of cryptographic asset inventory or migration timeline
  • FIPS 140-2/3 compliance gapUS government and financial sector customers require FIPS validation; non-compliant modules block enterprise sales

Medium frequency · Critical severity when present in regulated sectors

AeAerospace

Safety, certification, and supply chain exposure

  • DO-178C / DO-254 DAL mismatchsoftware or hardware design assurance level not aligned with actual failure consequence; re-certification cost can exceed development cost
  • Single point of failure in safety pathno redundancy architecture for critical functions; fails airworthiness standards for commercial operation
  • EMC / EMI not testedelectromagnetic compatibility testing not completed; product cannot legally operate in most jurisdictions
  • ITAR / EAR export controltechnology with defence application not classified under US export control regulations; international sales blocked, investor returns constrained
  • Fab concentration risksole-sourced from single foundry (commonly TSMC N5/N3); no second-source strategy; lead time >52 weeks with no mitigation

Critical · Certification gaps can halt commercialisation entirely

RoRobotics

Safety certification and real-world performance gaps

  • Sim-to-real gap undisclosedperformance benchmarks from simulation not replicated in uncontrolled real-world environments; deployment readiness overstated
  • Functional safety not certifiedISO 26262 (automotive), IEC 61508, or ISO 13849 compliance not achieved; product cannot operate in target sector
  • Edge case coverageperception and decision systems not stress-tested on distribution-shift inputs; long-tail failure modes uncharacterised
  • Liability framework absentno insurance, no product liability structure, no incident reporting procedure; one adverse event can terminate operations

Critical · Safety gaps are binary go/no-go blockers

SySystems architecture

Architecture debt and operational fragility

  • No load testing evidenceclaimed capacity figures not validated under simulated peak load; architecture untested beyond current user base
  • No disaster recovery planRTO and RPO not defined; backup strategy untested; single-region deployment for multi-tenant SaaS
  • Vendor lock-inproprietary database, single-cloud dependencies, or third-party APIs with no abstraction layer; switching cost not disclosed in financials
  • Technical debt ratioestimated remediation cost >20% of codebase undisclosed; post-acquisition refactor cost materially affects returns
  • Missing observabilityno structured logging, distributed tracing, or alerting in production; incidents discovered by customers, not engineering

High frequency · Scalability gaps amplify with growth

SeSemiconductors

Supply concentration and IP hygiene

  • Fab concentration risksole-sourced from single foundry (commonly TSMC N5/N3); no second-source strategy; lead time >52 weeks with no mitigation
  • Yield data not disclosedwafer yield and binning data withheld, or reported from engineering lots only; unit economics at volume unverifiable
  • Open-source IP contaminationcopyleft-licensed RTL, IP blocks or EDA scripts embedded in the proprietary design via transitive dependency; can force disclosure of design files
  • Untracked dependency treeno software composition analysis (SCA) tooling; licence obligations for hundreds of libraries unknown

High severity when present · Foundry lead times set the timeline

Our approach to findings

For each risk identified, we assess its severity in the context of the specific deal — distinguishing a hard red flag that warrants walking away from a manageable issue that can be mitigated with targeted fixes, contractual protections, or post-investment remediation. Every finding comes with a clear recommendation: block, negotiate, or remedy.

Identifying these risks is exactly our job. Tell us about your deal and we will tell you what to look for.

Brief us on a deal →
Who you work with

Led by the people who published the papers, then built the products.

One principal reads every deal and matches the expert. You always know who is doing the work, and you can attend every call.

In their words

Words from the people we have worked with.

Beyond due diligence

A full suite of deep tech services.

Technical due diligence is our core offering, but our experts cover a wider range of needs for investors, corporates and technology teams. Like an X-ray machine, we see the details that matter, whatever the decision in front of you.

Workshops & Masterclasses

Expert-led sessions that give investment teams, boards, and executives genuine working knowledge of deep tech — so they can ask sharper questions and make better decisions.

Workshop
Quantum Computing Landscape
What quantum actually is today, where the hype ends, which hardware approaches are viable, and how to evaluate quantum startups. For investors and corporate strategy teams.
Workshop
AI Landscape for Investors
Cutting through the noise: foundation models, applied AI, edge cases, and failure modes. How to distinguish real AI capability from engineering theatre in a pitch.
Workshop
Cybersecurity for Executives
From threat modelling to secure architecture. Designed for executives and boards who need to govern cyber risk — not just delegate it.

Specialised Audits

Targeted assessments for specific technical risks that go beyond a standard due diligence — for when you need depth in one dimension, not breadth across three.

AI Safety
AI Safety & Red Teaming
Jailbreaking assessments, adversarial prompt testing, bias audits, and EU AI Act compliance reviews for AI systems entering regulated or high-stakes environments.
EU AI Act
Cybersecurity
Penetration Testing
Black-box and grey-box penetration tests of web applications, APIs, infrastructure, and cryptographic implementations. Reports include prioritised remediation roadmaps.
Deep Tech
Patent Portfolio Assessment
Is the IP actually defensible? We assess whether patents cover what they claim, whether the claims hold up technically, and whether competitors can engineer around them.

Vertical Specialisms

Domain-specific assessments for sectors where regulatory complexity, clinical validity, and technical risk intersect in ways that general technology due diligence cannot fully address.

HealthTech · AI
HealthTech AI Review
Clinical AI validation, regulatory pathway assessment (CE mark, FDA SaMD), dataset quality, model interpretability, and bias audits for medical AI systems.
MDR · SaMD
Advisory
Advisory & Ongoing Insights
Retained advisory for VC funds and corporate innovation teams — ongoing access to domain experts for deal-by-deal questions, portfolio monitoring, and technology horizon scanning.
Technical Audit
Technical Audit for Startups
The same 360° assessment as a due diligence — but commissioned by the startup itself to strengthen defensibility, fix architecture risks, and prepare for investor scrutiny.
Common questions

Everything you need to know.

Still unsure? Reach out directly — we are happy to scope your engagement before you commit to anything.

Send an email →
What is technical due diligence and why does it matter for VC?

Technical due diligence is a structured expert assessment of a startup's technology — covering IP defensibility, architecture, scalability, team capability, and the validity of technical claims. For deep tech investments it is essential: groundbreaking science and sophisticated science fiction look deceptively similar, and a single oversight can wipe out an investment.

How long does a typical engagement take?

Pre-seed engagements can be completed same-day. Seed to Series A typically take two weeks. Growth-stage assessments run three weeks. M&A engagements are scoped individually. If you have a hard deadline, tell us — we accommodate urgent timelines.

What does the deliverable look like?

You receive a structured SWOT report covering defensibility, scalability, and claims verification, plus a competitive benchmark. For technical audits, the report adds a prioritised action roadmap. We also debrief you after each call. You are welcome to attend all calls with the startup team.

How do you match the right expert to our deal?

When you brief us, we review the technology and identify an expert with direct hands-on experience in that specific field — not adjacent knowledge. For deals spanning multiple domains, we deploy a multi-expert team.

Can you work with the startup itself, not just investors?

Yes. Our Technical Audit service is designed for startups and their investors who want a concrete roadmap to make the technology more defensible and scalable. It delivers the same SWOT analysis as a due diligence, plus specific action points.

Do you handle NDAs and confidentiality?

Absolutely. All engagements are governed by an NDA before any information is shared. Our domain experts are bound by the same confidentiality obligations. We have extensive experience operating within strict VC confidentiality requirements.

What are the Masterclasses?

We offer expert-led masterclasses on AI, Cybersecurity, and Quantum Computing to help investment teams, boards, and LP audiences build genuine working knowledge of deep tech. If you need your team to ask smarter questions of founders, a masterclass with one of our domain experts is the most efficient path.

Contact

Brief us on a deal.

Two paragraphs are enough. Julien replies within one business day with a view on whether an assessment is worth it, the expert he would match, a timeline and a price. No commitment.

01About youRequired
02The dealOptional
03TimingOptional
Two required fields: your name and work email.
Read by Julien personally. Reply within one business day, usually sooner. Confidential from the first line: you do not need an NDA to describe the deal to us.
Prefer email? julien [at] deeptechexperts [dot] com · Or take 15 minutes with Julien to decide whether you need an assessment at all.
Typical timeline
  • Initial responseWithin 24h
  • Expert matchedDay 1–2
  • Seed–A report~2 weeks
  • Growth report~3 weeks
References

Investors we have worked for will take your call. Ask, and we connect you within a day.

Have a deal on the table? Reply within 24 h

Brief us