Guide

Due diligence on an AI search and retrieval platform

Due diligence on an AI search and retrieval platform verifies whether indexed documents can be retrieved outside their original access permissions, what the contract actually says about retaining or deleting customer data, how dependent the platform is on a single foundation-model provider for both embedding and generation, and whether every contractor who built the retrieval code assigned its IP.

Reviewed

A retrieval-augmented-generation platform can pass every financial diligence check and still be carrying a serious problem that only surfaces once someone tests how the system actually behaves with real, permissioned customer data. Technical diligence in this sub-sector exists specifically to find that kind of problem before closing, not after an enterprise customer finds it first.

The document list specific to this sub-sector

  • Data-processing agreements by customer, including retention and deletion terms for indexed content
  • The contract with the underlying foundation-model provider covering both embedding and generation, and whether it is assignable
  • IP assignment records for every contractor who built or contributed to the retrieval or ranking layer
  • Any prior security review, audit or incident history related to data access or permission enforcement
  • A list of enterprise customer contracts that include data-governance, security or data-residency commitments

Testing permission boundaries yourself

Ask for, or arrange, a real test of whether the system enforces each document’s original access permissions during retrieval — for example, whether a query from one user can ever surface content that user was never permitted to see in the source system. A seller’s assurance that “permissions are respected” is not the same as evidence of a tested enforcement mechanism, and this specific finding is one of the most serious a buyer can uncover, because it represents a live data-leakage risk for every enterprise customer on the platform, not just a documentation gap.

Sensitive-document exclusion, not just permission enforcement

Respecting a document’s existing access permissions is not the same as being able to exclude a category of sensitive content from the retrieval index altogether, and enterprise and regulated-sector customers increasingly expect both. Ask specifically whether the platform can exclude classes of documents — material under legal hold, executive or HR-only content, anything flagged confidential — from ever being retrieved or surfaced, regardless of a given user’s nominal permission level, since this defense-in-depth capability is one some platforms in this category have simply never built. Its absence does not automatically sink a deal, but it is a finding a buyer should weigh against how sensitive the target’s typical customer’s document base actually is, and it belongs in the same file as the permission-boundary test above rather than as a footnote to it.

What a data-retention gap in the contract actually means

If a customer’s data-processing agreement is silent or vague on what happens to indexed content after the relationship ends, that silence is the finding — it means the platform likely has no enforced deletion process, which is both a contractual risk with existing customers and a compliance question under PIPEDA and, in Quebec, Law 25 wherever the indexed content includes personal information. Ask to see the actual deletion mechanism, not just the policy language describing it.

Foundation-model dependency for both embedding and generation

This platform typically depends on a foundation-model provider for two separate functions — generating embeddings for the retrieval layer and generating the final response — and a buyer should confirm whether both depend on the same single provider or are diversified. Review pricing terms and what happens if the provider changes access terms or discontinues a specific model, since this platform’s cost structure is more exposed to provider changes than a typical software product’s is.

Contractor-built retrieval and ranking code: the IP check

Confirm that every contractor or agency who worked on the retrieval or ranking layer signed an agreement formally assigning IP rights to the company, and where any fine-tuned embedding models were involved, confirm whether the underlying training data and resulting model can actually be transferred under its own licensing terms. A gap here is one of the more common findings in earlier-stage platforms in this category.

Breach-notification and incident-history review

Ask directly whether the platform has ever experienced a privacy or security incident involving indexed customer content, and request any records of it, because PIPEDA requires notification to affected individuals and to the Office of the Privacy Commissioner where a breach creates a real risk of significant harm. A seller with a clean incident history and a documented process for detecting and responding to one is a materially different diligence finding than a seller who has never formalized how they would even detect unauthorized access to indexed content in the first place. Where any enterprise or regulated-sector customers were affected by a past incident, confirm how it was disclosed to them and whether it affected the relationship, since that history often resurfaces during the customer-consent conversations a change of ownership can trigger.

Financial diligence alongside the technical review

Financial diligence should run in parallel with the technical review, not as an afterthought once retrieval quality is confirmed. Ask for financial statements normalized against actual bank and payment-processor records over several years, with recurring subscription revenue from enterprise and self-serve customers reported separately from one-time implementation or professional-services fees. Pay particular attention to how inference and embedding cost is presented: a business that reports it as a flat percentage of revenue, without breaking it out against both document volume and query volume, may be understating how much margin compression to expect as either driver grows, and that gap between reported and underlying margin is one a buyer should resolve before agreeing to a price.

How long this diligence takes

Permission-boundary testing and a genuine technical review of the retrieval and indexing pipeline take real time, particularly against a realistic volume of documents, and rushing this to meet a closing deadline is a common way buyers miss the kind of finding described above. Build enough time into the transaction timeline, and involve an independent technical reviewer rather than relying solely on the seller’s own representations.

Sources

Every requirement and figure referenced in this guide traces to a primary source. Links were last confirmed on the dates shown.

  1. 01
    Treadstone LawLegal commentary
    Cybersecurity and Data Privacy Due Diligence When Buying a Business in Ontario
    treadstonelaw.ca·Checked Aug 14, 2026
  2. 02
    Office of the Privacy Commissioner of CanadaGovernment
    The Personal Information Protection and Electronic Documents Act (PIPEDA)
    priv.gc.ca·Checked Aug 14, 2026
  3. 03
    Treadstone LawLegal commentary
    How Long Does Due Diligence Take When Buying a Business in Ontario?
    treadstonelaw.ca·Checked Aug 14, 2026
  4. 04
    Treadstone AssociatesAdvisory
    AI-Assisted Due Diligence
    treadstoneassociates.ca·Checked Aug 16, 2026
  5. 05
    Treadstone LawLegal commentary
    Intellectual Property Due Diligence When Buying a Business in Ontario
    treadstonelaw.ca·Checked Aug 14, 2026

Deavo is an advertising and listings platform, not a brokerage, law firm or valuation firm. This page is general information, not legal, tax, accounting or valuation advice, and rules differ by province. Confirm anything you rely on with a qualified professional before you act on it.