Back to blog

Due Diligence for a Sub-$500k Business (When You Don't Have a Lawyer or a Data Room)

Indiemaker Team avatar Indiemaker Team 8 min read
Due Diligence for a Sub-$500k Business (When You Don't Have a Lawyer or a Data Room)

The standard due diligence guides are built for $5M deals. Here's what actually matters at $40k.

Most major guides to buying a digital business are written by and for the people who broker $1M+ SaaS transactions. They're calibrated for businesses with ARR, cohort retention data, and an NDA process that runs four to six weeks. The frameworks are sound – they're just a professional-grade instrument for a job that doesn't need one.

A $40k Chrome extension is not a $4M SaaS. Running a 27-point enterprise review on it is like hiring a structural engineer to hang a picture.

The instinct is understandable. You're spending a meaningful amount of money. You're nervous. You want to be thorough. So you find the most rigorous checklist you can, and you try to apply it. The result is either paralysis – the process feels so complex you never close a deal – or cargo-cult diligence, where you request documents you don't know how to read and treat their arrival as confirmation that everything is fine.

There's a better approach. It requires less paperwork, less time, and sharper attention.

The four things that actually kill small deals

Most diligence frameworks try to be comprehensive. At sub-$500k, comprehensive is the wrong goal. The honest version of this checklist is four items, because those are the four ways a deal at this size actually goes wrong.

Revenue that isn't real, or doesn't survive the handover

Not fraud – though that happens. More often it's revenue that's structurally tied to the seller in ways neither party has fully thought through: a newsletter where open rates depend on the founder's personal audience, a tool where the top three enterprise customers are close contacts of the seller, a service business where "recurring revenue" means the same clients keep coming back because they like dealing with this particular person. The money is real. Whether it stays real after the ownership changes is a separate question.

A single dependency the seller won't mention

This is the one that kills deals quietly. A tool whose traffic is 85% one Google keyword. A plugin whose entire distribution runs through one developer community the seller is personally embedded in. An app that lives and dies on a platform API the seller has had a cordial relationship with, which you won't inherit. The dependency is almost never hidden deliberately – the seller often doesn't see it as a risk because it hasn't caused a problem yet. Your job is to find it before it becomes your problem.

Platform or SEO risk priced as stability

A business showing flat, stable revenue for 24 months can still be carrying enormous undisclosed risk if that stability is sitting on a single platform or a handful of keywords. A $60k asking price on a 2× multiple looks reasonable until you notice that 70% of traffic came from a content strategy that hasn't been updated in eight months and is already losing rankings. The revenue hasn't moved yet. It will – which is exactly why platform risk has to be priced into the multiple, not mistaken for stability.

An asset that can't actually be moved

Sometimes what looks like a product is actually a set of relationships, manual processes, or platform accounts that are technically non-transferable. App Store listings are tied to developer accounts in ways that require specific transfer processes. Stripe accounts have policies on ownership changes. Some revenue streams require the seller's continued involvement to sustain – which either makes the deal contingent on a handover arrangement you haven't priced, or means the asset is worth less than it appears. What actually transfers cleanly, and what doesn't, is worth understanding before you sign.

Everything else – capitalisation tables, employment agreements, formal valuation methodologies – is noise at this price point. Bracket it out. None of it matters if any of the four above apply.

How to verify revenue without a finance background

You don't need to understand ARR bridges. You need to answer three questions: is the money real, is it recurring, and does it survive without the seller?

For the first: ask for read-only Stripe access covering the trailing 12 months. Not a spreadsheet, not a screenshot – read-only Stripe access. Reconcile the claimed MRR against actual payout amounts for the same period. If they roughly match, the revenue is real. A consistent gap – payouts running 30% below the MRR figure – is worth understanding before you ask anything else.

For the second: distinguish between recurring and repeating. A subscription product has contractually recurring revenue. A productised service where the same clients re-engage each month has repeating revenue – it looks the same in a spreadsheet but won't behave the same after the handover. If the claimed recurring revenue is actually customer loyalty, ask yourself whether that loyalty is to the product or to the person.

For the third: trace one full customer lifecycle yourself. Where did they hear about it? Who answered their first support question? Is any part of that journey personally reliant on the seller being present? If the seller stopped responding to DMs tomorrow, would the business run at the same level for six months? If not, that's not a disqualifier – but it changes what the asset is worth and what needs to be built into the deal structure.

The diligence that costs nothing but time

Before you pay for anything, spend an afternoon on the following. None of it requires a professional, a login, or a tool you don't already have.

Look up where the traffic comes from. Similarweb's free tier will give you a rough traffic source breakdown for most sites. You're not looking for precision – you're looking for concentration. If 60% or more of organic traffic comes from one keyword cluster, you have a dependency. If traffic is dominated by direct or branded, go back to the revenue-survival question.

Search for the seller's footprint in the product. Read the About page. Check the social account tied to the domain. Look at the product's review profile on G2, ProductHunt, or wherever it lives. Is the seller's personal brand woven through the product's identity? A business can still be worth owning if it carries the seller's name – but you need to know that going in, and you need to price the rebrand or the gradual identity transition into your offer.

Run the seller's name through Google alongside the product name. You're looking for their community presence: the forum activity, the Slack group they run, the podcast they appear on. These are often where the actual moat lives, and they're often not transferable.

Check the product's dependency stack. If it's a plugin, what platforms does it touch? If it's a SaaS, what APIs is it integrated with? What happens to those integrations if the developer account changes? This takes an hour and a browser; it doesn't require a lawyer.

Look at the support history if you can access it. Where do conversations break down? What issues recur? The support inbox is a remarkably honest record of where the product is fragile.

When to walk, when to pay for help

Most deals at sub-$500k don't justify professional legal review. But some do, and knowing the threshold matters.

Pay for a specialist – a digital business attorney or a broker-of-record service – if any of the following apply: the asset involves user data with GDPR implications and the seller can't produce a clear privacy policy and data processing record; the transaction requires a formal asset purchase agreement covering IP assignment and you're not certain what IP is actually being transferred; the seller is asking you to assume outstanding liabilities you can't fully enumerate; or the deal involves a significant earnout structure tied to post-sale performance.

If none of those apply, a well-structured LOI and a clear asset purchase agreement built from a reputable template will take you further than you'd expect at this price. The legal risk in a $40k deal is usually not contract complexity – it's failure to do the basic verification above before signing anything.

The other version of "when to walk" is simpler. If you ask a reasonable question and the seller gets defensive rather than transparent, that is the answer. Not every hesitation is deception – sellers are sometimes nervous or disorganised. But a pattern of deflection on the revenue question, the traffic question, or the dependency question is worth taking seriously. At this deal size, you're buying something from someone, and the relationship between buyer and seller in the first 90 days of a handover matters more than the legal documents.

Right-size the process to the deal

Diligence is not a signal of seriousness. Proportionality is.

A buyer who runs a 27-point checklist on a $40k side project is not more thorough than one who runs four focused checks. They are either inexperienced or stalling. The experienced small-deal buyer knows what kills small deals, focuses time there, and moves. That speed isn't recklessness – it's the competitive advantage of the solo acquirer over a firm running a formal process.

Part of what Indiemaker is built around is making the transfer of small digital assets less opaque and less cumbersome. Part of solving that is making the pricing legible. Another part is making the diligence proportionate. The point is to know exactly which risks you're taking on, price them correctly, and move.

The four checks above take an afternoon. They will tell you more than a 27-point checklist run by someone who doesn't know where to look.

Start there.

Related reading:

How can we help?