Partner and Vendor Due Diligence

What should you check before partnering with a company?

Before partnering, check what a company runs, not what its deck claims. One keyless call on their domain returns five correlated layers: tech stack, infrastructure and email-auth posture, firmographics, AI-readiness, and a security grade. Bassethound reads the whole signal in a single dossier, so you walk into the first real call already knowing who you are dealing with.

Best move: run their domain through a five-layer dossier before the first serious call, and read the security grade and email-auth booleans first.

Why it works: a partner’s public surface leaks operational competence. A missing DMARC record, an expired cert, or an F header grade is a cheap tell for how they run everything you cannot see.

Key takeaways

  • A domain returns five correlated layers of pre-partnership signal in one keyless call: tech stack, infrastructure, firmographics, AI-readiness, and security.
  • Email-auth booleans (SPF, DKIM, DMARC) and TLS days_remaining are the fastest reads on whether a company owns its own basics.
  • The security header grade (A to F) and TLS grade are a smoke test for operational discipline, not a penetration test.
  • The AI-readiness verdict (shipping, experimenting, none) separates partners who build from partners who market.
  • A static crawl can miss server-side or proxied components, so the dossier reports the gap instead of guessing past it.

Which layers matter most before a partnership?

Read the five layers in order of cost-to-fake. Security and infrastructure are hardest to fake and fastest to read. Email-auth booleans tell you whether a company gets its DNS right and cares about spoofing. The certificate’s days_remaining tells you whether someone owns renewal. A header grade of D or F means they ship their own marketing site without HSTS, CSP, or X-Content-Type-Options, and that carelessness rarely stops at the edge. Tech stack tells you integration surface: do they run the frameworks and payment rails you will interoperate with. Firmographics confirm the company is who the deck says. AI-readiness tells you whether a “we use AI” claim survives contact with their backend. You do not weigh these equally. Security leads for a data-handling partner. Tech stack and infrastructure lead for a technical integration, AI-readiness and firmographics for a co-sell. The dossier returns all five correlated, so you pick the lens that fits the deal instead of running five tools and stitching the answers by hand.

What does a partner’s security posture reveal?

The security layer grades response headers A to F and TLS separately. Both are proxies for operational discipline. HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are cheap to set and public to check. A company that skips them on its own marketing site tends to skip them everywhere. The TLS grade catches weak protocol versions and short-dated or near-expiry certs. None of this is a penetration test. It is a smoke test. A clean grade does not prove a partner is secure. A failing grade proves they left easy points on the table, and you should ask why before you route customer data through them. Pair the grade with the infrastructure layer: who hosts them, which CDN sits in front, whether they enforce email auth. A partner with strong SPF and DMARC plus an A header grade has someone who owns this surface. A partner with none of it may still be fine, but now you know to raise it in the first call instead of the security review three months in.

How do you tell a builder from a marketer?

Every deck says “AI-powered.” The backend does not lie. The AI-readiness layer fingerprints what a company loads and calls: model providers (Anthropic, OpenAI, Gemini), SDKs (Anthropic SDK, OpenAI SDK, Vercel AI SDK), orchestration (LangChain, LlamaIndex), vector stores (Pinecone, Weaviate, Qdrant), and observability (Helicone, Langfuse). It checks llms.txt, MCP endpoints, and .well-known AI files. Then it scores distinct signal groups hit and returns a verdict: shipping, experimenting, or none. A partner pitching an AI roadmap with a “none” verdict is selling you a plan, not a product. A “shipping” verdict with a detected vector store and a named model provider is a company that has already paid the cost of building. Be honest about the limit: fully server-side or proxied AI backends can hide from a static crawl, so “none” means “no signal found,” not “no AI.” The dossier says which. For a co-sell or a technical partnership, this is the layer most competitors cannot give you, because their AI-readiness stops at a homepage keyword scan and an llms.txt fetch.

What can a domain check not tell you?

Plenty, and pretending otherwise is how due diligence fails. A domain read is the public, technical surface. It does not tell you about revenue, runway, litigation, key-person risk, or whether the founder returns email. It does not read private repos or internal systems. A static crawl plus optional JS render can miss components that render fully server-side or sit behind a reverse proxy, and the dossier flags those gaps instead of guessing. A clean security grade is a smoke test, not an audit. Bassethound pulls firmographics from structured data and public profiles, so a thin web presence yields a thin firmographic layer. Use the dossier for what it is good at: a fast, keyless, pre-call read that tells you whether a company is real, competent, technically aligned, and building rather than talking. Then let it direct your expensive diligence. It tells you which questions to ask in the first call and which claims to pressure-test before you spend a lawyer’s hour. The dossier casts the wide net so your team can spend its hours on the deep verification that matters.

How fast can you vet a shortlist?

One domain, one call, no key, a few seconds. The fast profile is deterministic, keyless, and returns in roughly one to three seconds: tech stack, infrastructure, and the security-relevant infra booleans. The standard profile adds the AI stack and firmographics. The deep profile adds follow-on probes, the full security grade, and Wayback first-seen history, so you can see how long a company has existed at that domain. Because the endpoint is a stateless remote MCP server, your agent host (Claude, Cursor, ChatGPT) can loop it over a list. Feed a shortlist of ten prospective partners and get ten correlated dossiers back, each self-contained, nothing carried from one call to the next. That turns partner screening from a research project into a batch job. You reserve human time for the two or three that clear the bar, and you walk into those calls already knowing their stack, their security posture, and whether their AI claims hold. The keyless free tier rate-limits; the paid tier runs over OAuth for higher depth and volume.

Bassethound perspective

Firmographic tools confirm a company exists: its size, its funding, its headquarters. They will not tell you whether it can ship. That gap is where partnerships die: you sign with a company that looks right on paper and discover, three months in, that the “AI platform” is a landing page and the security posture is an F. Apollo, ZoomInfo, and Clearbit sell you the paper. BuiltWith and Wappalyzer sell you one layer of the reality. Neither correlates competence. The conviction competitors dispute: the public technical surface is a better pre-partnership signal than any firmographic record, because it is expensive to fake and pointless to fake. A company that enforces DMARC, ships an A header grade, and runs a real vector store has people who own those surfaces, and that discipline predicts how they will run the partnership. Bassethound fuses five layers in one keyless call so you read competence, not just existence, before the first serious conversation. An agent can fan out to five separate MCPs and stitch the answer. It cannot cheaply get the correlation. Fusion is the moat.

Sources

Frequently asked questions

Can a domain check replace real due diligence?

No. It is the fast, keyless first pass, not the audit. It tells you whether a company is real, competent, and building, then points your expensive diligence at the right questions. Financials, legal, and key-person risk stay a human job.

What is the single fastest signal of a careless partner?

Missing email auth. A domain with no SPF or DMARC and a near-expiry TLS cert shows nobody owns the basics. It is not proof of trouble, but it is the first question to ask.

How is this different from Apollo or ZoomInfo?

Bassethound adds four more correlated layers on top of what Apollo or ZoomInfo return, including deep AI-stack detection and a security grade, so you read operational competence, not just existence. Those tools return firmographics: who a company is, how big, how funded.

Can you tell if a partner ships AI, or just claims it?

Often, yes. The AI-readiness layer fingerprints model providers, SDKs, vector stores, and observability, then returns a shipping, experimenting, or none verdict. Fully server-side backends can hide from a static crawl, and the dossier says when it could not reach one.

Do you store the dossier for later?

Every call is stateless and self-contained, so no call depends on the one before it. Your results are stored against your account, and the privacy policy covers what is kept.

Sniff a domain.

Run sniff_domain on any site and read its five-layer dossier in one call.

Sniff a domain