# Small-SaaS Technical Evidence Memo

Use this compact template to turn technical diligence into a traceable decision record. Keep evidence in an approved, access-controlled data room. Do not put passwords, tokens, private keys, raw customer data, full proprietary source, privileged legal analysis or confidential contract text in this file.

## Scope

- Target:
- Transaction / review stage:
- Review dates:
- Buyer decision owner:
- Seller technical owner:
- Technical reviewer:
- Systems and environments in scope:
- Access mode: read-only / screen-shared / isolated / seller-operated
- Explicit exclusions:
- Evidence-room location and access owner:

## Page 1 — Decision layer

### Direct technical answer

- Overall state: SUFFICIENT EVIDENCE / CONDITIONAL / NOT ENOUGH EVIDENCE
- Deal-thesis promises tested:
- Confirmed P0 blockers:
- Material P1 risks or conditions:
- Bounded P2 post-close items:
- Unavailable evidence that limits the conclusion:
- Required legal, privacy, security, finance or transaction decisions:

### Material findings

| ID | Deal-thesis promise | State | Severity | Exact evidence | Business impact | One-time / recurring | Resolution path | Decision owner |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| F-01 |  | VERIFIED / NOT VERIFIED / UNAVAILABLE | P0 / P1 / P2 |  |  |  |  |  |
| F-02 |  | VERIFIED / NOT VERIFIED / UNAVAILABLE | P0 / P1 / P2 |  |  |  |  |  |
| F-03 |  | VERIFIED / NOT VERIFIED / UNAVAILABLE | P0 / P1 / P2 |  |  |  |  |  |

Severity is a technical/deal-thesis signal, not a transaction instruction. Counsel and the deal team decide price, escrow, conditions, remedies and whether to proceed.

## Page 2 — Evidence and transition layer

### Evidence coverage

| Area | State | Evidence checked | Material gap | Owner / next action |
| --- | --- | --- | --- | --- |
| System boundary and authoritative assets |  |  |  |  |
| Repository history and change control |  |  |  |  |
| Source → build → artifact → deploy → runtime → schema |  |  |  |  |
| People, support and key-person capability |  |  |  |  |
| Data model, integrity, backup and restore |  |  |  |  |
| Security, privileged access and incidents |  |  |  |  |
| Dependencies, SBOM and vulnerability response |  |  |  |  |
| Rights, licenses and contributor documents for counsel |  |  |  |  |
| Infrastructure, providers and operating cost |  |  |  |  |
| AI providers, data, evaluations and fallback |  |  |  |  |
| Release, rollback, alerts and operational rehearsal |  |  |  |  |
| Account transfer and post-close independence |  |  |  |  |

### Required actions by transaction stage

#### Before close

- Action / owner / evidence required / decision blocked:

#### Closing day or control transfer

- Account ownership and recovery continuity:
- Billing and renewal continuity:
- Privileged-access rotation/revocation sequence:
- Release freeze and stop authority:
- Incident communication owner:

#### First 30 days after close

- Isolated restore / owner / target date:
- First small reversible release / owner / target date:
- Provider and business-state reconciliation:
- Remaining transition and knowledge-transfer actions:
- Accepted residual risks and decision owner:

## Evidence appendix index

| Evidence ID | Controlled location | Exact revision / environment / date | Reviewer | Notes / limitation |
| --- | --- | --- | --- | --- |
| E-001 |  |  |  |  |
| E-002 |  |  |  |  |

## Sign-off

- Technical reviewer and date:
- Buyer decision owner and date:
- Legal/privacy/security/finance handoffs completed:
- Remaining assumptions and expiry/review date:

This template is engineering guidance, not legal, tax, accounting, valuation or transaction advice, and it does not certify the target or transaction.
