Technology and code
Who really built this, and what comes with it?
Pactlab reads commit metadata and scan results, never keeps the source, and ties every technical finding to the exact commit and tool version that produced it.
What it does
Commit provenance
Every finding resolves to a full commit hash, the tool that produced it and that tool’s version.
Unattributed commits
Work by identities missing from the identity map, or committed after a recorded departure.
Key-person concentration
Subsystems that depend on one contributor, reported as aggregates and never as a ranking of people.
Licence exposure
Components and licences from a software bill of materials, checked against a licence policy.
Scanner findings
Security and quality signals from isolated, short-lived scans.
Source never kept
Scan workspaces are destroyed on success, failure, timeout or cancellation. Paths and hashes remain; code does not.
What the reviewer gets
Technology findings, each tied to a commit, a tool version and the evidence it cites.
Where it sits in the loop
01 · Evidence
Collect the evidence
Billing records, repositories, delivery data and documents — normalized, hashed and kept with their source.
02 · Finding
Draft the findings
Analysts, scanners and models draft issues that cite the evidence they rest on.
03 · Review
A person decides
A named reviewer accepts, rejects or asks for support. Nothing is accepted by a machine.
04 · Assumption
Price the risk
Accepted risks become explicit, versioned inputs with a price range and a basis.
05 · Valuation
Run the numbers
Deterministic scenarios and a purchase-price bridge, run from stored inputs.
06 · Deal terms
Set the terms
Price adjustments, escrows and indemnities, each tied to the risk that justified it.
Pilots with acquirers of software companies
We are working with a small number of design partners on live deals. If you buy or invest in software businesses, talk to us.