Overview
Black Belt is Tiger Dojo's managed software security due diligence for M&A. It gives acquirers, investors, and founders an independent read on a software asset's security posture before the deal closes. Whether you are running technical diligence on a target or getting your own codebase ready for an acquirer, you get an objective application security assessment run by senior security engineers.
How It Works
We audit the target's Git repositories directly. No agents, no runtime instrumentation, no production access. Our team runs the Aikido Security platform and layers manual review on top, covering source code, dependency usage, and DevOps pipelines across the risk categories that move a valuation:
-
Vulnerabilities in open-source components and third-party packages
-
Insecure code patterns such as SSRF, SQL injection, and path traversal
-
Hardcoded credentials and secrets
-
License risk, including restrictive or incompatible open-source licenses
-
CI/CD pipeline misconfigurations and privilege-escalation paths
A senior security engineer validates every scan finding by hand to clear false positives and rank what actually matters. The results go into an executive-level report built to inform the investment decision, guide remediation, and back up compliance and risk work.
Prerequisites and Scope
To begin an engagement, the target or buyer grants read-only access to the relevant Git repositories (GitHub, GitLab, Bitbucket, or Azure DevOps). Scope can range from a single repository to a full codebase or an entire organization. A brief scoping call determines the engagement size, supported languages and frameworks, and expected timeline. Typical turnaround is days, not weeks, scaled to the number of repositories under review.
What You Get
-
Findings by severity and category written up in a detailed report
-
A valuation-and-integration risk summary covering the issues that affect price, compliance, and post-close integration
-
Remediation guidance with an optional follow-up session with the security team
Why Buyers Choose It
-
Fast enough for a deal cycle. Decision-ready findings in days, so diligence does not hold up the transaction.
-
Independent. Delivered by senior security engineers with no stake in the outcome.
-
Built for two audiences. High-level summaries for the deal team, technical detail for the engineers.
-
Zero operational disruption. No runtime access, deployment, or code changes, which fits pre-deal and stealth-mode targets.
-
Scoped to the deal. A single repository, a full codebase, or an entire organization.
Who It Is For
-
Private equity and venture firms that need fast, independent AppSec analysis during diligence
-
Corporate development teams that want technical risk clarity before an acquisition
-
Founders and CTOs preparing for an exit or a funding round
-
GRC and AppSec leaders validating software supply-chain and license risk
Getting Started
Engagements begin with a 15-minute scoping call to confirm repository access, languages in scope, and timeline requirements. From kickoff, expect preliminary findings within the first few days and a final executive-ready report shortly after. Because Tiger Dojo is an Aikido Security reseller partner, the same engagement can supply the Aikido license your team keeps after the deal, along with post-close support, ongoing monitoring, and remediation advisory.
Whether you are buying, evaluating, or preparing to be acquired, you find out what is in the code before it becomes your responsibility.
Highlights
- Independent software security due diligence for M&A. An objective, expert-led review of application-security and open-source license risk for mergers, acquisitions, and investment diligence.
- Fully managed and expert-validated. Every finding is reviewed by hand by senior security engineers, so the report focuses on the risks that affect valuation, not scanner noise.
- No runtime access or installation. The audit works directly from your Git repositories. No agents, no production access, no deployment, which suits stealth-mode and pre-deal environments.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Tiger Dojo provides support throughout the lifecycle of your Black Belt engagement. For initial inquiries, scoping questions, and engagement kickoff, contact the team at hello@tigerdojo.io .
What Is Covered
-
Pre-engagement scoping and access setup guidance
-
Questions about report findings, severity ratings, and remediation recommendations
-
Optional follow-up session with the security team to walk through results
-
Post-engagement support for teams transitioning to ongoing Aikido Security monitoring
Engagement Process
Engagements begin with a scoping call to confirm repository access requirements, languages and frameworks in scope, and timeline expectations. Once read-only Git access is granted, the audit proceeds with preliminary findings shared during the review period and a final executive-ready report delivered at completion.
Requesting Assistance
For all support inquiries, including questions about your report, remediation follow-up, or refund requests, email hello@tigerdojo.io . Please include your engagement reference or organization name for faster routing.
Please contact hello@tigerdojo.io for further information.