pineapples.dev
pineapples.dev
Technology Due Diligence#Vendor Due Diligence#Technology Due Diligence#Private Equity#M&A#Mid-Market#Family Office#SaaS

Vendor Due Diligence for PE and Mid-Market Buyers

Anthony Wentzel

Anthony Wentzel

Founder, Pineapples

September 8, 2026
9 min read
Vendor Due Diligence for PE and Mid-Market Buyers

Vendor Due Diligence for PE and Mid-Market Buyers

When I sit in a data room, vendor due diligence is the work of proving you can live with a software vendor after you buy the relationship. I look at whose tenant it is, whether the export loads, and who can cancel the bill after close. I am not counting logos.

Buyers who search this phrase get a procurement checklist or a third-party-risk brochure. I write this page for the operating partner who has to run the company if HubSpot still belongs to the founder.

Pineapples prices the hired version as Technology Diligence at $25K or $60K, 10 business days from data-room access.

What is vendor due diligence when a buyer types it?

Vendor due diligence is the phrase PE, mid-market, and family-office buyers type when they are about to pay for a counterparty. Sometimes that is a new SaaS contract. More often it is the stack they are about to inherit on an acquisition. They are not asking for a history of procurement. They are asking whether the vendor still works if the seller stops answering email.

I treat that as a live-file question. Can the buyer open the tenant. Can someone export the data in a form another system can load. Can anyone cancel, dispute, or renew without texting the founder. Can support open a ticket for a person whose name is not on the original order form.

A logo list answers a different question. It lists Salesforce, NetSuite, a warehouse WMS, and an AI copilot. All of that can be accurate. None of it tells you the CRM tenant is a personal workspace, the WMS export is a zip nobody can load, or the copilot is trained on customer data under a click-through the GC has never seen.

This page is that read. IT due diligence is the lockout, MFA and domains and bank admin. The mid-market technology due diligence guide is the longer stack explainer. Vendor concentration is the margin problem when one vendor owns too much of the business. Do not treat those as the same document.

Why does a SOC 2 pack miss the IC question?

Search "vendor due diligence" and you land on third-party-risk language. Request the SOC 2. Collect the subprocessors. Score the questionnaire. Fine work for a combined risk team. It is not the Monday counterparty.

A PE operating partner heading to IC still needs a shorter, uglier list:

  • Whose org is the tenant, company or personal
  • Whether anyone has actually loaded an export into something else
  • Who is the named commercial owner after the press release
  • What the invoice SKU is versus what runs in production
  • What happens if the vendor sunsets the plan, changes the API, or gets acquired

If your packet cannot answer those, you have a risk brochure. You do not have vendor due diligence for a live file.

I do not need the questionnaire to be wrong to say that. I need the ranking page to be honest about what it is. It is a control catalog. It is not a walkthrough of the workspace that still says the founder is the only admin.

An AI readiness assessment will fail the same way if you score tools and skip the owner. A vendor quiz with nobody on it is still a fail.

What do I open first on a vendor?

I do not start with the vendor spreadsheet the banker uploaded. I start with the objects that decide whether the buyer is a customer.

Tenant. Open the admin. Read the org name, the billing email, and the list of owners. If I see a personal Gmail, a founder's private workspace, or a consultant's agency org, I treat the vendor as a seller asset until it is moved. The company can look modern and still be renting someone else's Slack, HubSpot, or Notion.

Export. Ask for a real extract, then try to load it. A CSV that opens is not a pass. A pass is a file another system can use without the seller sitting next to you. If the only path is "we will get that from support after close," write it as a close condition.

Commercial owner. Who can cancel, dispute, or renew. Whose card or ACH is on the account. Who support will talk to after the announcement. A vendor that only knows the founder is a TSA you have not priced.

Invoice versus production. Read the SKU. Then sit in the workflow that supposedly uses it. I have opened bills for platforms the company stopped running two years ago, and I have found the real system living in a personal Airtable the invoice never mentions.

Kill switch. What happens if they deprecate the API, retire the cheap plan, or get bought. I am not asking for a legal essay. I am asking whether the buyer can keep operating for a defined window if the vendor changes the deal. If the honest answer is "we would stop shipping," write it down.

I write those as objects I can screenshot. I do not write them as a maturity score.

Gold-on-black counterparty diagram. Hook: YOU INHERITED THE BILL. NOT THE ACCOUNT. Tenant still personal, export nobody can load, support still requires the founder, and invoice SKU is not what runs lead to BUYER OWNS THE INVOICE, NOT THE COUNTERPARTY. Logo list and SOC 2 pack sit on the side path. Footer: Vendor due diligence is the counterparty test, not the logo list.

The diagram is the finding. Tenant still personal. Export nobody can load. Support that still requires the founder. Invoice SKU that is not what runs. That chain is a bill you cannot inherit. The logo list is the side path.

Where does day-one vendor risk actually live?

Day one is the first morning the buyer has to use the stack without the seller in the room.

Vendor risk lives in boring places:

  • The CRM tenant is a personal workspace, so the buyer cannot add admins or turn off the seller
  • The only export is a zip of PDFs, and the warehouse cannot rebuild orders from it
  • Support will not open a ticket because the contract contact left with the founder
  • The AI tool's click-through lets the vendor train on customer data, and nobody on the buyer's side has read it
  • The invoice is current. The production workflow runs in a different product the seller never put on the list

None of those show up as a row on a SOC 2 questionnaire. All of them show up if you sit down in the tenant and try to do one real admin task.

I also look for the vendor that is "free" because it sits on a personal card. Free is not cheap when the cardholder leaves. The renewal just becomes a lockout with a nicer logo.

The cheaper time to find that is before the announcement. After close it becomes a fight with a vendor who has no reason to help you. Same objects. Worse timing. If one vendor owns too much of revenue or compliance, that is the concentration problem sitting on top of the counterparty problem. Diversified logos do not save you if every tenant still fails the inherit test.

What belongs in the IC memo?

IC does not need another appendix of logos. IC needs the counterparties that change price, holdback, or timing.

I write findings as actions:

  • Move the tenant onto a company-owned org before close, or hold funds until two buyer-controlled admins are live
  • Produce an export the buyer has actually loaded, not a promise from support
  • Novate or re-paper the commercial contact so the buyer can cancel, dispute, and open a ticket on Monday
  • Reconcile the invoice SKU to the workflow that actually runs, and kill the bill that does not
  • Name the kill-switch window for any vendor that can stop shipping if they change the deal

If I cannot attach a screenshot, an export sample, or a contract clause, I am not done. "Documentation is light" is not a finding. "The only tenant owner is leaving" is a finding.

A logo list can sit in the appendix. The memo is the inherit list and the cost or delay to clear it. That is the difference between vendor commentary and something finance can use.

When the file is live and the model needs numbers, that is technology due diligence consulting. This page is the search phrase that seat sits on when the risk is the vendor, not the repo.

When do I hire the 10-day seat?

I hire the seat when the next decision is a price, a holdback, or a no, and a vendor relationship can change that decision.

Pineapples prices Technology Diligence at $25K or $60K, 10 business days from data-room access. Same operator from access to the readout. Findings written so they can sit next to legal and finance.

That is the deal-room buy. It is not a second vendor PDF. It is not a request to "send the SOC 2 and we will review it."

After close, if the company still needs a technology lead who owns those counterparties week to week, that is Fractional CTO at $15K or $35K a month, pause or cancel any month. Build work on systems you already control is AI-Native Build from $4,500 per 2-week sprint. One shipped proof workflow, later, is the Starter Workflow Pilot at $4,900, 7 business days. None of those replace the tenant check on a live file.

I do not invent fees. The PE menu lives on the engagements page.

What do I take into IC?

I take the counterparties you cannot inherit, and I stop.

The personal tenant. The export nobody can load. The support queue that still requires the founder. The invoice that does not match production. The vendor that can cancel you if they change the plan.

If those are clean, the logo list can wait. If they are not clean, the logo list does not matter yet.

I run this as owner-led work. Same person in the data room and in the readout. If you have a live file, scope the 10-day seat. Bring the target. I will sit in the tenant.

Related reading

Frequently asked questions

What is vendor due diligence?

Vendor due diligence is the work of proving you can live with a software vendor after you buy the relationship. I sit with the tenant, the export, the named commercial contact, and the kill switch. A logo list and a SOC 2 PDF can both be true and still leave you paying a bill you cannot operate.

What should I check before I inherit a SaaS vendor at close?

Open the objects that decide whether the buyer is a customer on Monday. Whose org owns the tenant. Whether an export loads into something else. Who can cancel, dispute, or renew without the seller. Whether the SKU on the invoice is what actually runs. Those are findings. The vendor spreadsheet is the cover page.

How is vendor due diligence different from IT due diligence?

IT due diligence asks whether you can operate the company if the seller's phone is off. Vendor due diligence asks whether you can inherit the counterparties that company already bought. One is lockout. The other is a bill you cannot take over. You need both on a live file.

How is this different from vendor concentration risk?

Concentration asks whether one vendor owns too much of the business and can reprice you after close. Vendor due diligence asks whether each material vendor is a counterparty you can actually take over. A company can have a diversified stack and still fail the tenant, export, and commercial-owner tests on every tool that matters.

When should I hire the 10-day Technology Diligence seat for vendors?

Hire it when a deal is heading to IC in the next 2-4 weeks and a vendor relationship can change the price, the holdback, or the no. After close, an empty technology seat that has to own those counterparties week to week is Fractional CTO at $15K or $35K a month. A later proof workflow is the $4,900 Starter Pilot. That is not the deal-room buy.

Working a live deal?

Book a 30-minute working session.

Same operator who runs the diligence engagements. No SDRs, no sales team. Bring the target, I'll bring the checklist.

Share this article

Anthony Wentzel

Anthony Wentzel

Founder, Pineapples

Anthony Wentzel has spent 26 years helping mid-market, PE, and family-office operators turn technology risk into decisions they can own. He is the founder of Pineapples.

Keep reading

Tech Strategy Assessment

5 minutes totech success

Running a tech business is challenging. Validate your tech strategy with the same AI-augmented assessment we use to drive client outcomes.

5 Minutes

Strategy Validation

Revenue Growth

Validate Your Tech Strategy

Total time investment: 5 minutes