Service 03

Risk assessment for startups

Every innovation carries risk. The question is never whether a venture has exposures — it is whether the founders can name them before somebody else does, price the ones that matter and ignore the ones that do not. A detailed analysis helps mitigate those risks and makes the path to a raise smoother.

A grid of squares of graduated density, darkest in one corner and fading across the field

Four domains

Where early-stage ventures actually break

A risk report that lists twenty items ranked equally is a document nobody acts on. We work in four domains and rank within them, because these are the categories that end companies.

Technical

Key management and custody, upgrade privileges, dependency on a single chain, bridge or provider, incident history, and whether anyone outside the team has reviewed the code that moves value.

Commercial

Concentration in one customer or channel, unit economics that only work at unreached volume, pricing that assumes a status you do not hold, and runway measured against optimistic collection.

Regulatory

Whether the product is a regulated activity in the markets it serves, whether the current structure supports the licence route, and what happens to the roadmap if the answer arrives late.

Counterparty

Banking and payment relationships that can be withdrawn without notice, custodians holding company assets, and a treasury denominated in the asset the company itself issues.

The deliverable

A document written to change a decision

The output is short enough to be read by everyone who has to act on it, and specific enough that each item names an owner and a next step.

  • Ranked findings Each exposure with a plain description, the realistic consequence, how quickly it could materialise, and whether it is worth fixing before a raise, after one, or never.
  • Evidence, not opinion Findings reference the contract, the configuration, the filing or the number they came from. Where evidence was unavailable, that gap is recorded as a gap rather than smoothed over.
  • Mitigations with costs Every recommended fix carries an honest estimate of effort and of what it delays. A mitigation nobody has time for is not a recommendation.
  • A diligence rehearsal The questions an investor or partner will ask about each finding, and the answer the company can currently give. That is usually the most uncomfortable page and the most useful one.
How an engagement works
A ranked column of bars beside a narrow margin of annotation marks

Questions

What founders ask about risk work

Is this a security audit?

No. A code audit is a specialist engagement with its own methodology, and where one is needed we will say so and help you scope it. Our assessment covers the business as a whole and tells you whether an audit is the right next spend.

Will the report be used against us in diligence?

The report belongs to you. Most founders share the summary voluntarily, because arriving at diligence with a ranked list of known issues and a plan is a far stronger position than being surprised.

How long does it take?

It depends on how much documentation already exists. Where contracts, configurations and numbers are available, a first draft is a matter of weeks; where they have to be assembled from scratch, that gap is itself a finding.

Do you assess the market opportunity?

Only as a risk. Whether the market is large enough is an investor's judgement; whether the company has bet on a single channel, a single customer or a single regulatory outcome is a risk, and that we do assess.

What if we disagree with a finding?

The disagreement goes in the report next to the finding, with your reasoning. A document that only records the adviser's view is less useful to a board than one that records both.

Find it before an investor does

Send a short description of the venture and what you already suspect is fragile. The first reply, within 24 hours, will say what an assessment would cover and where we would start.