Decide

Technical red flags at pre-seed and seed

Technical red flags at pre-seed and seed are the signals an angel can see in a screen share, without reading code, that the product is less real, less durable or less honest than the deck says. There are nine that matter at these two stages. Two should stop the conversation until resolved: a founder who will not show a real account, and a founder who cannot open the company's own code. Four become terms in the round. Three are normal at pre-seed and worth a note. This page scopes the list to those two stages only. The general list for a larger deal and the AI-specific list by stage live in their own guides and are linked from here.

Published September 17, 2026. Editorial.

Key takeaways

  • Nine flags matter at pre-seed and seed, and an angel can see all nine in one screen share without technical knowledge.
  • Two flags stop the conversation: a refused screen share of a real customer account, and a founder who cannot open the company's own code repository.
  • Four flags become terms rather than reasons to pass: a single developer with no written deployment steps, an AI claim without a test, no security scan ever run, and a commit history that only moves before investor meetings.
  • Three flags are normal at pre-seed and belong in the notes rather than the decision: one developer, no revenue, and a product that changes shape between meetings.

A red flag at pre-seed is something you can see on a screen that changes what the deal is. This page lists nine, scoped to pre-seed and seed only, and sorts them into three groups: the two that stop the conversation, the four that become terms, and the three that are normal at this stage and should be written down rather than acted on. The general list for a Series A or later deal is on the technical due diligence red flags page, and the AI-specific list by stage is on AI startup diligence red flags by stage. Neither is repeated here.

Which two flags stop the conversation?

The founder will demo but will not screen share a real customer account. Customer data can be shown with a customer's permission, and a founder raising money has asked for that permission before you did. A founder who offers the demo account instead, twice, is telling you that either no customer is using the product or the product does not survive a real account. Both are things to know before the cheque. Ask once more, in writing, and wait for the answer before any further meeting. Demo versus production has the tells if the account you are then shown is still a demo with a customer's name on it.

The founder cannot open the company's own code. When you ask to see the commit history and the answer is "I would need to check with my developer", the company does not control its product. The code lives with a contractor, an agency, or a former co-founder, and until it lives in a repository the company owns, with a signed assignment of the work, the company is buying its own product back one invoice at a time. This is the single-developer risk in its worst form, and the single-developer risk covers the cases where it is fixable.

Neither flag means the deal is dead. Both mean the deal is paused until something is shown, and the founder should be told in plain words what that something is: a real account on screen, or the repository open with the founder logged in. Most founders can produce both within a week. A founder who cannot has told you what the pause was for. Reveneau's angel review treats these two as the only "stop" flags at pre-seed, because every other finding on this page can be priced, and these two cannot be priced until they are resolved.

Which four flags become terms?

One developer and no written deployment steps. A bus factor of one is normal at pre-seed. A bus factor of one with the deployment sequence in one person's head is a term: written steps within thirty days, a second person with access, and a second engineer as a named use of funds. The 2016 study by Avelino, Passos, Hora and Valente found 65 percent of 133 popular open-source projects had a truck factor of 2 or less, so the concentration is common; the absence of a plan to reduce it is the flag.

An AI claim with no test. "We use AI" with no named model, no measured failure rate and no fallback for a wrong answer is a marketing line. The term is a test before close: twenty inputs, pass or fail, a number. The SEC's March 2024 fines against Delphia ($225,000) and Global Predictions ($175,000) and the FTC's September 2024 settlement with DoNotPay ($193,000) were all for AI claims with nothing behind them. What "we use AI" should mean at pre-seed is the ten-minute check.

No security scan, ever. At pre-seed this is common and it becomes a flag when the code was written with AI tools and the company sells to businesses. Veracode's July 2025 report found 45 percent of code samples from more than 100 language models failed security tests. The term is a scan before the first enterprise customer, with the results shared with the board.

A commit history that moves only before investor meetings. Scroll back three months. If the log shows gaps of weeks and then a burst of changes in the days before each pitch, the product is being built for the pitch. The term is a monthly product update to investors with the commit count in it, which costs the founder nothing and makes the pattern visible to everyone on the cap table from the first month.

Which three flags are normal at pre-seed?

These belong in the notes. Acting on them means passing on companies that are exactly where they should be.

One developer. A pre-seed company with one engineer is a pre-seed company. Wiltbank and Boeker's November 2007 study of 1,137 angel exits found 34 percent of deals were done at the seed stage and 41 percent at the start-up stage; small teams are the population. Note the bus factor and move on to whether there is a plan.

No revenue. The same study found 45 percent of ventures had no revenue when the angel invested and the median across all of them was $125,000. Pre-revenue is not a technical flag. Unused is, and MVP diligence separates the two.

A product that changed shape between meetings. At pre-seed the product should be changing. A founder who shows you a different onboarding flow from the one you saw last month has been watching users. The flag is the opposite: a product that looks identical three months apart while the commit history shows work, which usually means the work went somewhere the customer does not see.

What does the full list look like in one place?

Flag What you see Group Action
No real account shown Demo account offered twice Stop Ask in writing, wait
Founder cannot open the code "I would need to check with my developer" Stop Assignment agreement and repository access before continuing
One developer, no written deployment Deployment steps in one head Term Written steps in 30 days, second engineer in use of funds
AI claim, no test No model named, no failure rate Term A test before close
No security scan "We have not had a problem" Term Scan before first enterprise customer
Commits only before pitches Gaps, then bursts Term Monthly update with commit count
One developer One name in the log Normal Note the bus factor
No revenue Pre-revenue company Normal Check that users exist
Product changed shape Different flow from last month Normal Ask what users said

Why is the list this short?

Because long checklists fail in a specific way. In March 2023 a 100-question diligence checklist reached 253 points on Hacker News, and the top comment warned that "there are precisely zero companies in the world to which the answer to all of these questions is positive", and that many of the questions contradict each other across company sizes. A checklist with a hundred items gives the angel a hundred things to feel bad about and no way to rank them.

Nine items, in three groups, with an action against each, is a list an angel can carry into a meeting and act on afterwards. It is also a list a founder can be told about in advance, which is fair: Y Combinator's guide to seed fundraising tells founders that an investor asking for too much diligence at seed is one to avoid, and a founder who knows the nine things you will look at can prepare them in an afternoon without building a data room.

The pillar page places these flags inside the six-block check they come from, and the one-hour technical check is where each flag is first seen. If a deal shows both stop flags, or the round is large enough that being wrong costs more than a review, when to pay for a professional technical review is the next page.

What is deliberately not on this list?

Architecture. Choice of programming language or framework. Test coverage percentages. Cloud cost. Code quality as a technical reviewer would judge it. All of these matter at Series A and are on the general red flags page. At pre-seed the product is small enough that the wrong framework is a month's rewrite, and the questions that decide the deal are whether it runs, who can change it, and whether the claims are true.

Best for

  • An angel about to decide on a pre-seed or seed deal after the technical check
  • A group lead sorting a reviewer's page into stop, term and note
  • A founder who wants to know which technical findings will cost them terms

Avoid if

  • The deal is Series A or later, where the general red flags page applies
  • The AI is the company, where the AI red flags by stage page is the primary list

Verify before you commit

  • Both stop flags were tested by asking, in writing, for a real account and for the commit history
  • Each term flag has a specific term attached in the deal memo rather than a note
  • The normal flags are in the notes and did not change the decision on their own

Common questions

What are the biggest technical red flags at pre-seed?

Two stop the conversation: a founder who will demo but will not screen share a real customer account, and a founder who cannot open the company's own code repository. Four become terms: a single developer with no written deployment steps, an AI claim with no test, no security scan ever run, and a commit history that only moves before investor meetings. Three are normal: one developer, no revenue, and a changing product.

Is a single developer a red flag at pre-seed?

On its own, no. Avelino and colleagues' 2016 study found 65 percent of 133 popular open-source projects had a truck factor of 2 or less, so concentration is normal at small scale, and Wiltbank and Boeker's 2007 data shows angels invest at seed and start-up stage where small teams are the norm. It becomes a term when the deployment steps exist only in that person's head and there is no second engineer in the plan.

Is no revenue a technical red flag?

No. In Wiltbank and Boeker's November 2007 study of 1,137 angel exits, 45 percent of ventures had no revenue at investment and the median across all of them was $125,000. The technical flag is unused rather than unpaid: a product that has been built and given to nobody. Ask for two named users who will take a call, and check the sign-up dates on screen.

What should an angel do if the founder refuses to show a real account?

Ask once more, in writing, and wait. Customer data can be shown with a customer's permission and a founder raising money has usually asked already. A second refusal means either no customer is using the product or the product does not survive a real account, and both are things to know before the cheque. The deal is paused rather than dead until a real account is shown.

What does it mean if the founder cannot open the code?

The company does not control its product. The code lives with a contractor, an agency or a former co-founder. Until it sits in a repository the company owns with a signed assignment of the work, the company buys its own product back one invoice at a time. This is a stop flag: resolve ownership and access before continuing, and check the IP section of the standard checklist too.

Why is an AI claim without a test a term rather than a stop?

Because it can be fixed before close. The term is a test: twenty inputs, a pass or fail against each, a number, shown on screen. The SEC's March 2024 fines against Delphia and Global Predictions and the FTC's September 2024 DoNotPay settlement were for AI claims with nothing behind them, so the test protects the founder as much as the investor. A founder who refuses to run one turns the term into a stop.

Is no security scan a red flag at pre-seed?

It is common, and it becomes a term when the code was written with AI tools and the company sells to businesses. Veracode's July 2025 report found 45 percent of generated code samples from more than 100 models failed security tests, and that newer models did no better. The term is a scan before the first enterprise customer, with results shared with the board.

What does a commit history that moves only before pitches tell an angel?

That the product is being built for the pitch. Scroll back three months; gaps of weeks followed by a burst of changes in the days before each investor meeting is the pattern. The term is a monthly product update to investors with the commit count in it, which costs the founder nothing and makes the pattern visible to everyone on the cap table.

Why not use a longer red flag checklist?

Because long lists cannot be ranked or acted on. When a 100-question diligence checklist reached 253 points on Hacker News in March 2023, the top comment warned that no company in the world answers all of them positively and that many contradict each other across company sizes. Nine flags in three groups with an action against each is a list an angel can carry into a meeting.

What technical issues are not red flags at pre-seed?

Architecture, choice of language or framework, test coverage percentages, cloud cost, and code quality as a reviewer would judge it. All of these matter at Series A and appear on the general technical due diligence red flags page. At pre-seed the product is small enough that the wrong framework is a month's rewrite, and the deal turns on whether it runs, who can change it, and whether the claims are true.