Illustrative Sample
Grounded Work · Ground Truth
PE Due Diligence Brief
Acme Commerce Inc.
Engagement: GT-2026-047
Delivered: April 2026
Codebase: ~420K lines
Confidential — Deal Team Only

Technology Risk Assessment

Overall Risk Rating
6.4
Moderate–High
Security
8.1
High Risk
Architecture
6.8
Moderate
Cloud Cost
5.5
Moderate
Scalability
3.2
Low Risk
01

Executive Summary

Acme Commerce's technology foundation supports the business case in two of four dimensions, but carries material pre-close risk in security and moderate risk in cloud cost structure.

The security finding requires immediate attention: 17 API keys and database credentials are committed directly into production code, including a Stripe live secret key and an AWS IAM user with S3 full-access.

Cloud infrastructure is running at approximately 137% of what it should cost for the workload profile. $280K–$340K in annualized savings are identifiable with no functional changes to the product.

02

Key Findings

CriticalSecurity · Compliance
17 live credentials committed to source code

Includes a Stripe live API secret key, AWS IAM user credentials with full S3 access, and a production PostgreSQL password across multiple repositories.

Deal Implication: PCI-DSS scope violation and potential GDPR / CCPA exposure. Recommend credential rotation as a closing condition.
CriticalArchitecture · Business Continuity
Checkout service is a single point of failure for all revenue

Payment processing, inventory decrement, email dispatch, and fraud checks live in one synchronous call chain with no retry logic.

Deal Implication: Direct revenue reliability risk. Estimated 6–8 weeks to remediate with async queueing and dead-letter handling.
HighCloud Cost · EBITDA
$280K–$340K in annualized cloud waste identified

Underutilized EC2, oversized RDS, cold data sitting in Standard S3, and oversized ElasticSearch relative to workload.

Deal Implication: Material direct EBITDA improvement available in the first 100 days with limited implementation effort.
HighEngineering Velocity · Tech Debt
28% of codebase is dead code; test coverage at 14%

Deprecated endpoints, stale feature flags, and low test coverage materially increase change risk and slow new-hire ramp time.

Deal Implication: Constrains post-acquisition feature velocity and makes refactoring a longer-term modernization program.
03

Cloud Cost Analysis

ServiceCurrentOptimizedSavingsAssessment
EC2 Compute (12 instances)$312,000$148,000$164,0003 instances running at <3% CPU. Right-size + Reserved Instances.
RDS (PostgreSQL, db.r6g.4xlarge)$228,000$112,000$116,000Provisioned 4x actual workload. Downsize + read replica strategy.
S3 Storage (14 buckets)$96,000$48,000$48,000No lifecycle policies. Move year-old raw data to Glacier.
ElasticSearch (9-node cluster)$84,000$62,000$22,000Sized for 10x current document volume. Minor savings available.
Total$780,000/yr$428,000/yr$352,000/yr45% cloud cost reduction opportunity
04

Architecture Map (Generated from Code)

Service Dependency Map — Generated from actual codebase analysis
Client
Web App (React)
Mobile API
Admin Panel
API Gateway
API Gateway (Kong)
Services
Product Catalog
Checkout SPF
Search / Rec
User Mgmt
Data
PostgreSQL (RDS)
ElasticSearch
Redis (no HA)
External
Stripe (sync, no retry)
SendGrid (sync)
Twilio
AWS S3
05

Prioritized Action List

PriorityActionTimeframeImpact
1Rotate all 17 committed credentials; implement secrets management with Vault or AWS Secrets ManagerPre-CloseEliminates PCI-DSS breach liability and compliance exposure
2Right-size EC2 instances and purchase Reserved Instances for baseline workloadDay 1–30$164K/yr savings; 1-day implementation
3Decouple checkout service with async queueing, retry logic, and dead-letter handling30–90 DaysEliminates revenue-impacting outages; ROI in under 6 months
4Implement S3 lifecycle policies; downsize RDS to match workload30–60 Days$164K/yr additional savings
5Begin systematic dead code removal and test coverage program90–180 DaysUnlocks engineering velocity and supports post-acquisition scale
This is an illustrative sample. All company names, figures, findings, and data in this document are fictional and generated for demonstration purposes only.
Ground Truth by Grounded Work · ConfidentialBack to PE landinghello@grounded-work.com