Red flag analysis is a deliberately narrow pass: it looks for the things that would change whether the deal happens at all, and it looks for them before the full review has finished.
What it looks for
- Licensing and intellectual-property exposure in the codebase or its dependencies.
- Security positions that are asserted but not evidenced — a claimed attestation with no report behind it, for example.
- Concentration risk, including key person risk where one named person holds knowledge nobody else does.
- Architecture or scaling constraints that put the investment case at risk.
- Contradictions between what the target says in one document and another.
How to read it
Each item carries its rating and its citations, like any other finding. A red flag is a Critical or Warning finding that has been surfaced early because of what it would cost to discover late — not a separate class of statement with weaker evidence behind it.
Two cautions:
- An empty red flag report is not a clean bill of health. It means nothing in the material you have provided so far triggers one. If the material is thin, the absence tells you about the material.
- A red flag is a question for the target, not a conclusion. Most of them resolve into a condition, a price adjustment or a remediation plan once the target answers.
Where it appears
On the project overview as its own view, and its items also appear inside the review areas they belong to. Availability depends on your plan — see Settings → Plan and billing.