Certification
What makes a tech asset truly certifiable?
The objective criteria that distinguish a certifiable asset from one requiring a remediation plan, according to the Aegryn Grade protocol.
75% of assets submitted to the Aegryn Grade protocol require a remediation plan before reaching a publishable grade. This figure is not an indictment of the market, it reflects a structural reality: most founders build for scale, not for exit. Certifying an asset means making it readable, enforceable, and transferable. Here is what that means in practice.
The 4 dimensions of the Aegryn Grade protocol
C, Code & Architecture
Source code quality (test coverage, documentation, absence of hardcoded secrets), architecture (microservices vs monolith, identified debt), dependencies (versions, licences, vulnerabilities), and IP filing (INPI, EUIPO or equivalent). An asset failing on dimension C cannot receive a grade above B.
I, Infrastructure & Security
Hosting sovereignty (cloud provider, data region, SLA), operational security (WAF, MFA access, audit logs, tested backups), compliance (ISO 27001, SOC 2, or documented equivalent), and absence of critical single point of failure. Non-sovereign or undocumented infrastructure is the second most common blocking point in certification.
F, Finance & Metrics
MRR/ARR verifiable from raw data (Stripe, Chargebee, or accounting export), churn calculated to a standard definition, NRR calculated on a customer basis without non-recurring expansions, and documented infrastructure costs. Non-auditable metrics are treated as non-existent, they cannot serve as a valuation basis.
S, Strategy & Transferability
Founder dependency (score 1–5), operational documentation (runbooks, onboarding, documented processes), client contractualisation (duration, termination conditions, client concentration), and post-acquisition growth potential. An asset whose operation depends entirely on a single non-replaceable individual receives a critical S score, even with excellent financial metrics.
Why 75% fail at first pass
- IP not filed or filed late (cause #1)
- Self-reported financial metrics without traceability
- Infrastructure hosted on the founder's personal account
- Total operational dependency on the founder
- Absence of formalised client contracts (informal payments)
Pre-submission checklist
- ✓ Source code IP filing completed
- ✓ Automated tests covering ≥60% of codebase
- ✓ MRR exportable from billing source
- ✓ Infrastructure hosted under company account (not personal)
- ✓ GDPR compliance documented (processing register, sub-processor DPAs)
- ✓ At least one employee or contractor capable of operating without the founder
“A certifiable asset is not a perfect asset. It is an asset whose strengths and weaknesses are documented, measured, and enforceable.”
— Aegryn Grade Protocol, v2.1
This article was written with the assistance of artificial intelligence and reviewed under Aegryn editorial responsibility. In accordance with Article 50 of the EU AI Act, we assume editorial responsibility for this content.
Ready to submit your asset or access the catalogue?