A software business buyer checklist covers whether the intellectual property chain is clean — signed assignments from every founder, employee and contractor who touched the code — plus a source code review, verified churn and recurring-revenue figures, customer and data-processing contract terms, open-source licence compliance, and cybersecurity history, since a software business’s value is almost entirely.
Reviewed
This checklist covers what to verify before buying a Canadian software or SaaS business. Unlike a business built around physical assets, almost everything of value here is intangible — code, data, customer contracts and recurring revenue — which makes the intellectual property chain and the revenue numbers the two places diligence needs to go deepest.
Confirm the intellectual property chain is actually clean
Confirm every founder, employee and contractor who ever wrote code for the product signed a written assignment of IP to the companyA missing assignment from even one early contractor can mean that person, not the company, legally owns part of the codebase — a gap that is expensive and sometimes impossible to fix after the fact.
Confirm ownership of trademarks, the product domain name and any registered patents sits with the corporation, not an individualIt is common for a domain name or trademark to be registered personally to a founder rather than to the company, meaning it will not transfer automatically with a straightforward sale.
Request a full list of open-source components used in the product and confirm none carry a licence that restricts commercial use or resaleAn open-source dependency under a restrictive licence can create an obligation to release proprietary code, or a compliance issue, that the new owner discovers only after closing.
Verify the revenue and customer metrics
Reconcile reported monthly or annual recurring revenue against actual payment processor and bank deposits over several periodsA red flag is recurring revenue reported as a run-rate figure that does not match what is actually landing in the bank, or that quietly includes one-time or non-recurring charges.
Independently calculate customer churn and net revenue retention rather than accepting the seller’s summary figureChurn calculated inconsistently, or excluding customers who downgraded rather than fully cancelled, can make retention look meaningfully better than the underlying customer behaviour actually is.
Review the largest customer contracts for auto-renewal terms, termination rights and any change-of-control clausesA change-of-control clause can let a customer walk away specifically because the business changed hands, which matters a great deal if that customer represents a meaningful share of revenue.
Check code quality, infrastructure and technical risk
Have a qualified technical reviewer assess code quality, test coverage and outstanding technical debt, not just take a product demo at face valueA product that looks polished from the outside can sit on a codebase that is expensive to maintain or extend, and that cost only becomes visible once ownership has already changed.
Confirm whether source code is held in escrow or would otherwise be accessible if the current technical team left immediately after closingA business with no code escrow and a small technical team walking out the door on closing day can leave a buyer holding a product nobody left can actually maintain.
Review cloud infrastructure costs, vendor dependencies and any single points of failure in the hosting or data setupHeavy reliance on one cloud provider or a single unreplicated database is an operational risk that does not show up in the financial statements but can become very expensive to fix.
Check data privacy and security history
Confirm how the product handles personal information and whether its data practices comply with applicable Canadian privacy lawA product that processes customer or user personal data without clear privacy practices in place becomes the buyer’s compliance problem the moment the deal closes.
Ask directly about any past data breach, security incident or vulnerability disclosure and request supporting documentationA seller who is vague or defensive about past security incidents, rather than able to show what was found and fixed, is a pattern worth taking seriously before relying on the product’s security posture.
Confirm key technical staff — particularly anyone with irreplaceable knowledge of the codebase — intend to remain through and after the transitionA software business can depend as heavily on one or two engineers as a trades business depends on its licensed tradesperson, and losing that knowledge right after closing is a real operational risk.
Deavo is an advertising and listings platform, not a brokerage, law firm or valuation firm. This page is general information, not legal, tax, accounting or valuation advice, and rules differ by province. Confirm anything you rely on with a qualified professional before you act on it.