Skip to main content
Transactions · Pre-signature exposure diligence

You cannot scan a company you do not own yet. You can still see what you are buying.

“We are acquiring. Tell me what we are inheriting, from outside, without touching their network.”

Outside-in discovery is the only assessment method available before a deal signs — no access, no credentials, no agents, and nobody with the standing to authorise a test. What it establishes is the target's live external estate, the credential exposure already sitting under its domains, and how far both diverge from the disclosure schedule. What it cannot establish is set out on this page at the same weight.

24 hours
First external read, from the apex domain alone
~41TB
Raw source material retained — including from before the deal
CERT-In
Empanelled auditor since 2008 — Security Brigade
Day one

When the exposure stops being theirs and starts being yours

Nothing about a target's exposure resets at completion. A credential taken from a machine at a business the target itself bought years ago still opens whatever it opened; the access paths it names sit inside your perimeter from the moment the entity does; the remediation moves onto your backlog rather than the seller's. The transaction changes the owner and nothing else. Which is why the question worth asking before signature is not whether the target has had an incident — that is a data-room question and it is answered by people who may not know — but what is already in circulation under its domains, and how far that diverges from the schedule.

The constraint

Before signature there is no scope, and without a scope there is no test

The instruments that dominate ordinary security work — a scoped assessment, an authenticated scan, an agent on the estate — all begin from a permission the buyer does not hold and cannot yet be given.

A security assessment normally begins with a scope, and a scope begins with a signature from whoever owns the estate. Before a transaction signs, the buyer holds neither. There is no access to grant, no agent to install, no credential to issue, and the only party who could authorise a test is the party on the other side of the negotiation — where asking sets a tone most deal teams would rather not set. So the methods that dominate ordinary security work are unavailable in precisely the window where the decision gets made. What remains is what the target publishes to the internet whether it means to or not, and what has already left it. That is a narrower instrument than a scoped assessment and a much wider one than a questionnaire: it needs no cooperation, it cannot be curated by the party being assessed, and it reads the same on the day before the term sheet as on the day after close. The discipline that makes it usable in diligence is the boundary around it. Discovery reads public records and observes what the target's own systems return to an ordinary request. Nothing is authenticated against, nothing is exploited, nothing is modified, and nobody at the target, its staff or its suppliers is contacted. Every use of the word established on this page means established that way — and the questions this method cannot reach are published beside the ones it can, because a diligence report is read by people whose job is to find the gap between them.

What is establishable

The diligence questions, answered in three parts

Each row is a question a deal team actually asks. The middle column is what an outside-in read establishes before signature. The column after it is the one that decides whether the report survives being challenged.

What the deal team asksWhat outside-in establishes pre-signatureWhat it cannot establishWhere this is covered
"What are they actually running on the internet?" Every hostname that answers across the apex domains named in the information memorandum — and the ones underneath them nobody named: dormant brands, regional sites, and estates the target itself acquired years ago and never migrated. Discovery starts at an apex domain and keeps whatever responds. Anything that does not answer from the public internet. Internal segmentation, the endpoint estate, backup design and the privileged-access model are out of reach from outside and stay out of reach until you have access. Attack Surface Management
The delta runs in both directions, and both directions matter in a negotiation. Assets answer that appear nowhere in the schedule — dormant brands, regional sites, estates the target itself acquired and never migrated — and scheduled entries turn out to have stopped answering long ago. A seller can overstate an estate as easily as understate it, and the two errors are priced differently: one is exposure nobody has costed, the other is an asset register that will not survive its first reconciliation after close.
"Whose credentials are already in criminal hands, and since when?" Credential and breach artefacts attributed to the target's domains, read out of source material already held — the identities, the services they reach, and the date each artefact entered the corpus. Where the material came from an infected machine rather than a combolist, the artefacts belonging to that one device are assembled into a single case. Whether any of it still opens anything. A credential attributed to a target is not probed before an authorised scope exists, so it reaches you with no working state asserted and none implied. Dark Web Monitoring
Retention is what makes this a diligence instrument rather than a lookup. Raw source material is kept permanently and re-read as extraction improves, so a machine compromised long before the term sheet can yield an artefact this month. Nothing new was stolen — we simply became able to read what we already held.
"Which of their suppliers are we inheriting?" The hosting, DNS, mail, certificate and authentication providers the target actually resolves to, plus the same outside-in read run against any named supplier you nominate — scored with the identical categories, maths and bands applied to your own estate. Contract terms, sub-processor disclosures and data-processing obligations. Those live in the data room. Outside-in observation cannot see a clause. Third-Party Risk Management
Concentration is the supplier finding that most often survives the deal. Where the target and your own group already depend on the same upstream provider, an acquisition raises your exposure to that provider without anybody adding a supplier — and it is a quarterly agenda item with a number behind it rather than an assumption inside a continuity plan nobody has tested.
"Are we buying a brand that is already being abused?" Look-alike and permutation domains registered against the target's marks, impersonating profiles on social platforms, and app-store listings carrying its name, including ones the target has never had cause to look for. Whether the target holds the trade mark registrations that would give you standing to act. That is a question about paperwork, and paperwork is a data-room artefact. Brand Protection
Worth pricing rather than noting. Abuse of a mark you are about to own becomes your remediation backlog on day one, and nothing gets removed until somebody owns the work.
"Is any of it exploitable today?" Reachability, software versions, exposed administrative interfaces, and whether the sign-in path in front of them presents a second factor. All of that is observation, and observation is where a pre-signature read stops. Exploitability itself. Establishing it means testing, testing means an authorised scope, and before signature that authorisation is not the buyer's to give. Nothing is exploited and nothing is modified. Continuous Automated Red-Teaming, once a scope exists
This is the row a diligence report gets challenged on. Anyone asserting that a target is exploitable before signature is describing either a test nobody authorised or an inference they have decided to call a finding.
"Is what we are seeing normal for this sector?" The target's external estate set against comparable estates of similar size in the same sector, using the same categories on both sides — so a first read is interpretable before you have a portfolio to compare it against. Whether normal is acceptable. A benchmark tells you if the target is unusual. It does not tell you whether this is exposure you are willing to own. Manufacturing and industrial groups
Acquisitive industrial groups are the hardest version of this job and the most common one: plants, joint ventures and entities absorbed over decades, each with its own IT, most of them still invisible from the centre long after the deal that brought them in.
"Have they already been breached?" That material attributable to the target is in circulation, dated to when it entered the corpus. That is a fact about exposure, not a conclusion about how the target was run or about what its controls did or did not do. Whether an incident occurred, was contained, was reported internally, or was disclosed to a regulator. Nothing observed from outside answers any of those, and a read that claims to is guessing in a document that will be relied on. Not establishable — a data-room question

"What are they actually running on the internet?"

What outside-in establishes pre-signature
Every hostname that answers across the apex domains named in the information memorandum — and the ones underneath them nobody named: dormant brands, regional sites, and estates the target itself acquired years ago and never migrated. Discovery starts at an apex domain and keeps whatever responds.
What it cannot establish
Anything that does not answer from the public internet. Internal segmentation, the endpoint estate, backup design and the privileged-access model are out of reach from outside and stay out of reach until you have access.
Where this is covered
Attack Surface Management

The delta runs in both directions, and both directions matter in a negotiation. Assets answer that appear nowhere in the schedule — dormant brands, regional sites, estates the target itself acquired and never migrated — and scheduled entries turn out to have stopped answering long ago. A seller can overstate an estate as easily as understate it, and the two errors are priced differently: one is exposure nobody has costed, the other is an asset register that will not survive its first reconciliation after close.

"Whose credentials are already in criminal hands, and since when?"

What outside-in establishes pre-signature
Credential and breach artefacts attributed to the target's domains, read out of source material already held — the identities, the services they reach, and the date each artefact entered the corpus. Where the material came from an infected machine rather than a combolist, the artefacts belonging to that one device are assembled into a single case.
What it cannot establish
Whether any of it still opens anything. A credential attributed to a target is not probed before an authorised scope exists, so it reaches you with no working state asserted and none implied.
Where this is covered
Dark Web Monitoring

Retention is what makes this a diligence instrument rather than a lookup. Raw source material is kept permanently and re-read as extraction improves, so a machine compromised long before the term sheet can yield an artefact this month. Nothing new was stolen — we simply became able to read what we already held.

"Which of their suppliers are we inheriting?"

What outside-in establishes pre-signature
The hosting, DNS, mail, certificate and authentication providers the target actually resolves to, plus the same outside-in read run against any named supplier you nominate — scored with the identical categories, maths and bands applied to your own estate.
What it cannot establish
Contract terms, sub-processor disclosures and data-processing obligations. Those live in the data room. Outside-in observation cannot see a clause.
Where this is covered
Third-Party Risk Management

Concentration is the supplier finding that most often survives the deal. Where the target and your own group already depend on the same upstream provider, an acquisition raises your exposure to that provider without anybody adding a supplier — and it is a quarterly agenda item with a number behind it rather than an assumption inside a continuity plan nobody has tested.

"Are we buying a brand that is already being abused?"

What outside-in establishes pre-signature
Look-alike and permutation domains registered against the target's marks, impersonating profiles on social platforms, and app-store listings carrying its name, including ones the target has never had cause to look for.
What it cannot establish
Whether the target holds the trade mark registrations that would give you standing to act. That is a question about paperwork, and paperwork is a data-room artefact.
Where this is covered
Brand Protection

Worth pricing rather than noting. Abuse of a mark you are about to own becomes your remediation backlog on day one, and nothing gets removed until somebody owns the work.

"Is any of it exploitable today?"

What outside-in establishes pre-signature
Reachability, software versions, exposed administrative interfaces, and whether the sign-in path in front of them presents a second factor. All of that is observation, and observation is where a pre-signature read stops.
What it cannot establish
Exploitability itself. Establishing it means testing, testing means an authorised scope, and before signature that authorisation is not the buyer's to give. Nothing is exploited and nothing is modified.

This is the row a diligence report gets challenged on. Anyone asserting that a target is exploitable before signature is describing either a test nobody authorised or an inference they have decided to call a finding.

"Is what we are seeing normal for this sector?"

What outside-in establishes pre-signature
The target's external estate set against comparable estates of similar size in the same sector, using the same categories on both sides — so a first read is interpretable before you have a portfolio to compare it against.
What it cannot establish
Whether normal is acceptable. A benchmark tells you if the target is unusual. It does not tell you whether this is exposure you are willing to own.

Acquisitive industrial groups are the hardest version of this job and the most common one: plants, joint ventures and entities absorbed over decades, each with its own IT, most of them still invisible from the centre long after the deal that brought them in.

"Have they already been breached?"

What outside-in establishes pre-signature
That material attributable to the target is in circulation, dated to when it entered the corpus. That is a fact about exposure, not a conclusion about how the target was run or about what its controls did or did not do.
What it cannot establish
Whether an incident occurred, was contained, was reported internally, or was disclosed to a regulator. Nothing observed from outside answers any of those, and a read that claims to is guessing in a document that will be relied on.
Where this is covered
Not establishable — a data-room question

Inherited liability

The estate arrives carrying its own history

A compromise that happened before the deal does not stay with the seller. It is the liability that transfers without appearing anywhere in the agreement — and the only way to price it is to be able to read source material that predates the transaction. The example below is a composite illustration rather than a customer, and it carries no figures for that reason.

Illustrative scenario — composite, not a customer

A laptop compromised long before the term sheet existed

What the disclosure schedule said
No reportable security incident in the lookback period the schedule specified. The answer was given in good faith by people with no way of knowing otherwise: the machine belonged to a subsidiary the target had itself acquired, it caused no outage, and nothing about it ever reached the target's own logs or anybody's incident register.
What the retained source material already held
Artefacts attributed to that subsidiary's domains and dated well before the term sheet — credentials, session cookies, autofill data carrying a corporate address, and browser history naming the internal tools the machine had reached. They had been sitting in the corpus, attributed to nobody who cared, since long before the transaction existed.
What close changed
Not the exposure. Only the owner. On day one those identities are yours, the access paths they name sit inside your perimeter, and the remediation is on your backlog rather than the seller's. The one thing that keeps getting better is the evidence: because the raw material is retained permanently and re-read as extraction improves, what is known about the target's pre-deal exposure improves after the deal instead of freezing at close.

Reading a finding

Every finding on a target declares how it was established

On your own estate a finding can be tested. On a target's it cannot, and a report that blurs the difference is one the other side will take apart. Five states, published, and the fourth is the one that matters most.

Every finding on a target declares how it was established
StateWhat it meansWhat follows
Observed responding The host answered an ordinary unauthenticated request from the public internet on the date recorded. Nothing was authenticated against, exploited or modified. A fact about reachability, never about exploitability. Assume anyone else can reach it too.
Attributed from the public record Registration, certificate and naming records associate the asset with the target or one of its brands. Ownership is inferred from what is published, not adjudicated. Confirm against the disclosure schedule before it enters a valuation. We surface it; we do not decide whose it is.
Historical, from retained material Credential or breach artefacts attributed to the target's domains, dated to when they entered the corpus rather than to when the underlying compromise happened. Price it. This is the exposure that transfers with the entity whether or not anyone declared it.
Not established — needs access A question no outside-in method answers: internal architecture, whether a control actually operates, incident history, contractual obligation. Put it in the data room. A read that answers this from outside is inferring and calling it a finding.
Reported as zero A capability ran across the target estate and found nothing attributable. Recorded explicitly as zero rather than quietly omitted from the report. Evidence that the surface was examined — which is the first thing a challenge to the report will ask for.
Key
  • Price it into the deal
  • Assume reachable
  • Ask it in the data room
  • Confirm ownership first
  • Recorded, not omitted

How the read is bounded

What a pre-signature read does — and what it deliberately does not do

The boundary is not a disclaimer attached to the method. It is the method. Counsel will ask for this list before the report is circulated, so it is published rather than produced on request.

Pre-signature scope discipline As of August 2026
  • The input is one apex domain per legal entity being assessed. No seed list, no scope file, no allowlist, and no contact with the target.
  • Discovery reads the public record — registrar and DNS data, certificate transparency, public scan data, app-store listings — and observes what the target's own systems return to an ordinary, unauthenticated request. Every response recorded is one any visitor would have received.
  • Credential and breach material is read out of source material we already hold and retain permanently. Nothing is bought for a transaction, and no new collection is commissioned against a named target.
  • Findings are dated to when they became observable to us, not to when the underlying event happened. That distinction matters in diligence: recency measures when the fact could have been known, not when the seller got round to describing it.
  • The automated read finishes inside 24 hours. The written summary a deal team can circulate follows within two business days and carries an as-of date on every figure in it.

Deliberately excluded

  • No authentication is attempted against the target with any credential, including one recovered from retained source material. A credential attributed to a target carries no working state before close, and none is inferred on its behalf.
  • Nothing is exploited and nothing is modified. Continuous Automated Red-Teaming is not run against a target until a scope exists and the party that owns that estate has authorised it in writing — which, before signature, is not the buyer.
  • No contact of any kind with the target, its employees or its suppliers. No pretexting, no outreach, no social engineering, and no attempt to obtain anything a public source does not already publish.
  • Nothing behind the perimeter. Segmentation, endpoint estate, backup design, privileged-access model and every control that requires a login sit outside what any outside-in method can reach. They are data-room questions, and this read does not pretend to answer them.

The sequence

Four moments, and what each one is permitted to do

Order carries information here. Authorisation expands at every step and the method follows it, never the other way round — which is why the third step is a published boundary rather than an assumption somebody makes under time pressure.

Questions buyers actually ask

Before you evaluate this

Can you assess a target without the target knowing?

Yes, and it is worth being precise about what that does and does not mean. The read uses public records — registration and DNS data, certificate transparency, public scan data, app-store listings — and observes what the target's own systems return to an ordinary, unauthenticated request. Nothing is authenticated against, nothing is exploited, nothing is modified, and nobody at the target, its staff or its suppliers is contacted in any form. There is no pretexting and no outreach. No notification is required because nothing is being done to the target that a search engine or a security researcher does not do daily. If your counsel would prefer the target were told, telling them changes neither the method nor the result.

Do you test the credentials you find under a target's domains?

No. Testing needs an authorised scope, and before signature that authorisation belongs to the party that owns the estate, which is not you. Credentials attributed to a target therefore arrive observed and untested, with no working state asserted and none implied — the value of them in diligence is the exposure and its date, not a claim about what still opens. After close the estate is yours, and where it is safe and authorised they are probed and carry the published states: Confirmed Working, Maybe Working, Not Working and Not Tested. What was and was not tested is legible on every row, which is the whole point of publishing the states.

The target gave us a recent penetration test report. Is this not the same thing?

It is the opposite instrument, and both are worth having. A penetration test is a deep read of a scope the target chose, on a date the target chose, by a firm the target instructed — and it is genuinely good evidence about the systems inside that scope. An outside-in read chooses no scope. It starts at an apex domain and keeps whatever answers, which is exactly how it finds the estate that was never in anybody's scope: the acquired brand still serving on its original certificate, the preview environment that outlived the pull request, the regional site nobody migrated. Read the report for depth and the observed estate for coverage. Where the two disagree about what exists, the disagreement is itself the diligence finding.

What happens if the deal does not proceed?

The target workspace is closed and the derived findings go with it. The underlying source material is our own corpus and was not acquired for your transaction — it was already held, which is the only reason a read this fast is possible at all. Where the deal does proceed, the acquired estate folds into your existing one rather than sitting beside it as a second programme: one more apex domain, the same categories, the same bands and the same queue your team already works.

Read a target the way an acquirer should — before the term sheet

One apex domain is the entire input. Nothing is asked of the target and nothing is authenticated against. A written read of what you would be inheriting, in two business days.