First, The Diagnosis
What a data room does not show you.
The documents are usually accurate. The gap is between what the documents describe and what is running on a Tuesday afternoon.
The platform in the pitch deck
Screenshots and a demo environment are cheap. Whether the system handles real load, holds real data, and can be maintained by anyone other than the person who built it is a different question, and it is answerable.
The team of forty
Headcount on a slide, contractors in practice. Commit history, access logs and system ownership tell you who actually builds and runs the thing.
The compliance position
"POPIA compliant" appears on most South African websites. Whether the business has an Information Officer registered with the Regulator, and whether its systems match its privacy policy, is checkable in an afternoon.
The technical debt nobody mentions
A platform built fast with AI assistance can look finished and be unmaintainable. We are called to clean these up often enough to know what the warning signs are before the money moves.
The security exposure you inherit
You buy the attack surface along with the company — including the forgotten staging server and the credentials already circulating from an old breach.
The address
Sometimes the simplest question is the useful one: is the registered address a premises, a serviced office, or a postbox? We can confirm what is at a given address and document it.
The Work
Four things, and we are specific about each.
1 · Technical due diligence
The target's systems assessed the way we would assess our own: architecture, code quality and maintainability, hosting and data residency, security posture, third-party dependencies, licence position, and what it would cost to keep running or to migrate. Delivered as a written register with findings ranked by what they would cost you.
2 · Digital and public-record verification
CIPC registration status and directorship as publicly recorded, domain and DNS ownership and age, certificate history, real digital footprint against claimed market presence, and whether the online estate is live or dressed. Public and open sources only, documented with the source for each finding.
3 · On-the-ground confirmation
Someone goes to the address. We confirm and photograph what is physically there — premises, signage, occupancy, apparent scale — and report it factually, with the date. This is observation of what is openly visible, not surveillance and not investigation.
4 · Implementation once you commit
The reason clients keep us after the deal: we build and run the technology. New entity infrastructure, secure email and identity, POPIA compliance programme, cybersecurity, the systems the business actually needs. See what we build.
You also get a local technical voice in the room. A South African counterparty's engineer will answer a local engineer differently to an overseas buyer's lawyer. We sit on the technical calls, ask the questions that get straight answers, and translate what comes back into something a board can act on.
Equally Important
What we are not, and who you need instead.
This is the section most firms leave out. Getting it wrong costs an investor far more than getting the technical work slightly wrong.
We are not registered auditors
"Audit" on this page means a technical assessment of systems. A statutory or financial audit in South Africa must be performed by an auditor registered with the Independent Regulatory Board for Auditors. We do not perform one and will not imply that we have.
We are not private investigators
Private investigation in South Africa is regulated under the Private Security Industry Regulation Act 56 of 2001 and requires PSIRA registration. We do not investigate individuals, conduct surveillance, or run background checks. Our verification is limited to public records, open sources, systems we are authorised to examine, and what is openly visible at an address.
We are not attorneys
Legal due diligence, contract review, structuring and regulatory opinion come from an admitted attorney. We work alongside your counsel or introduce a firm, and we stay in our lane.
We are not financial advisers
Valuation, financial modelling and investment advice sit with your own advisers. ASi Imperium is not an authorised financial services provider and gives no advice on the merits of any investment.
Authorisation governs everything technical. Any examination of a target's live systems — scanning, testing, access — happens only with that party's written authorisation. Doing it without is an offence under the Cybercrimes Act 19 of 2020, and no client instruction changes that. Where a seller will not authorise it, that refusal is itself a finding and we will report it as one.
Choose Your Level
Three levels, depending on how far along you are.
Reality Check
Before you spend money on advisers.
- Public-record and digital verification
- Digital footprint against claimed presence
- Address confirmation with photographs
- Short written report, sourced
Technical Due Diligence
You are serious and need the systems assessed.
- Everything in Level 01
- Architecture and code assessment
- Security and attack surface review
- Compliance position against POPIA
- Cost-to-own and migration estimate
- We attend the technical calls
Ground Team
You are committing, and need people here.
- Everything in Level 02
- Local technical representation
- Entity infrastructure and identity
- POPIA programme stood up
- Ongoing managed technology
Straight Answers
Common questions.
We already have advisers in South Africa. Why you?
Your attorneys read contracts and your accountants read numbers. Neither reads a codebase, a cloud bill or an access log. Technical reality is the part of a South African target that most commonly goes unexamined, and it is the part that determines what the thing costs to own after you buy it.
Can you do this if the target does not know we are looking?
Partly. Public records, domain and certificate history, and what is openly visible are available to anyone and need nobody's permission. Anything touching their live systems requires their written authorisation, without exception. We will tell you clearly which findings came from which side of that line.
How quickly can you turn a report around?
A Level 01 reality check is usually days. A full technical due diligence depends on how much the target gives us access to and how quickly — that is the variable, and we will tell you where it is stuck rather than letting a deadline pass quietly.
Will you work under our NDA?
Yes, and we expect to. We will also sign the target's, where the engagement requires it.
Do you find opportunities as well as check them?
We are not brokers and take no transaction fee — that keeps our findings worth something. What we can do is map a sector's digital and technical landscape so you can see who is actually operating, who is credible, and where the gaps are. That is research, and it is priced as research.
We are establishing rather than acquiring. Is this relevant?
Yes, and it is a large part of the work. Verifying prospective partners, suppliers and service providers before you are committed to them, then building the technology the new entity runs on. Starting a business in South Africa covers the foundation.
Start Here
Tell us what you are looking at.
A short call, in your timezone, to work out whether this is a reality check, a full technical due diligence, or something we should not be doing at all. We will say which — including when the honest answer is that you need an attorney or a registered auditor before you need us.