Vendor Due Diligence: A $5M SaaS Vendor Was a 2-Person Operation With No Real Office
Vendor's 50-person team exposed as fabricated; 2-person reality confirmed; $5M contract avoided.
Background
A healthcare organization was in the final stages of committing to a SaaS vendor whose product would sit at the center of its regulatory compliance program. The headline figure was a $5M annual contract, and the platform would handle sensitive workflows touching protected health information. On paper the vendor looked established: a LinkedIn company page listing 52 employees, a polished website, named leadership, and team photographs that projected the scale of a mid-sized firm. Because a failure of this vendor would cascade directly into the client's own compliance posture, the CISO asked for independent, public-source verification before signatures were exchanged. The question was narrow and diligence-driven: does the operating capacity implied by the vendor's public presence actually exist?
Investigation Methodology
- Public web and corporate-registry review. We began by reconciling the vendor's self-published claims against neutral records — corporate registration, filing history, domain registration timelines, and any regulatory or trade listings discoverable across the open web.
- Social-profile authenticity analysis. Each publicly listed employee profile was examined for account creation windows, posting and engagement history, connection-graph density, and the consistency of employment claims across the wider network.
- Profile-photo and image review. Listed profile and team photographs were assessed with reverse-image lookups and generation-artifact review to separate original photography from stock imagery or synthetically produced faces.
- Address and premises verification. The published headquarters address was checked against property records, virtual-office and coworking provider directories, and publicly available satellite and street-level imagery.
- Technical-footprint assessment. Public code repositories, commit metadata, and website hosting signals were reviewed as an independent proxy for genuine engineering headcount.
Key Findings
The public-source review surfaced a consistent pattern of overstated scale. Of the 52 listed profiles, 48 had been created inside a single three-month window, carried apparently AI-generated profile photos, and showed no engagement activity beyond their initial posts — a signature inconsistent with an organically grown workforce. The published headquarters resolved to a virtual-office address inside a coworking space, with no evidence of a dedicated suite or on-site staff. The vendor's team photographs matched stock images whose backgrounds had been digitally replaced. Most tellingly, the public code footprint showed commits originating from only two unique contributors, aligning the real engineering capacity with a two-person operation rather than the workforce advertised.
Evidence and Sources
Every finding rested on classes of public evidence, cross-checked so that no single artifact carried a conclusion on its own. Social-profile signals were corroborated against corporate-registry and domain-age records; the address claim was triangulated across property data, provider directories, and imagery; and the headcount inference was anchored to observable commit metadata rather than a self-reported profile count. Breach-exposure references and other historical public traces were also consulted to test whether the named individuals had any verifiable footprint predating the vendor's launch, and the pattern held: the advertised team left almost no trace outside the profiles themselves. Where an individual signal was ambiguous, it was treated as indicative only until a second, independent public source pointed in the same direction. This convergence of sources — not any one screenshot — is what elevated the observations from suspicion into a defensible finding.
Limitations and Review Notes
Public-source review reflects what is discoverable at a point in time; profiles, listings, and repositories can change or be removed, and the absence of a signal is not proof of absence. Automated indicators such as creation dates, image artifacts, and commit counts establish a probability, not a certainty, which is precisely why a human analyst reviewed each thread and weighed corroboration before anything was reported. Importantly, this work does not allege intent, does not adjudicate fraud, and does not establish the vendor's ability or inability to perform beyond what the public record reasonably supports. It informs a business decision; it does not render a legal verdict.
Outcome
The healthcare company terminated contract negotiations immediately. The discovery likely prevented a costly vendor dependency on a company that could not credibly deliver on its SLA commitments, and it gave the CISO a documented, evidence-led basis for walking away from the $5M commitment and redirecting the selection process toward vendors whose operating capacity could be independently corroborated. Total investigation time: 10 business days.