By Ricardo Normand · Published 7 October 2026
Buyers check what they are paying for and what could go wrong once they own it: who owns the code, how customer data is handled, how much revenue sits with a few customers, and which contracts restrict the business. The 2025 merger agreement between Adobe and Semrush turns each of those into a written promise by the seller. Adobe's checking took about six weeks from data-room access to signing.
- A merger agreement lists what the seller promises about the business. Read as a checklist, it is a map of what the buyer will check.
- Semrush promised that everyone who built its software had signed over their rights, that it had enough licenses for the third-party software it uses, and that open source did not force it to publish its code.
- Customer concentration is explicit: the 25 largest customers by recurring revenue, and a promise that none had given written notice of leaving.
- Contracts that restrict competing are disclosed, including restrictions that would bind the buyer after closing.
- A public-company agreement does not show everything. Terms such as escrow or indemnity in private deals are not visible in it.
What does a buyer actually check?
Most founders picture due diligence as a pile of document requests. A more useful picture is what the buyer is trying to learn: what they are really buying, and what could go wrong once they own it.
You can see that list in a real document. In November 2025, Adobe agreed to buy Semrush, a listed software company that describes itself as an online visibility management SaaS platform, for $12.00 a share in cash. The merger agreement is attached to the proxy statement Semrush sent its shareholders (Semrush, proxy statement, filed 29 December 2025). Article III is a list of promises Semrush made about itself, in 26 numbered sections. Each is a topic the buyer cared enough to put in writing.
Semrush is a listed company, so some of the sections (SEC filings, takeover statutes) don't apply to a private founder. The ones below do.
Who owns the code?
Section 3.14, on intellectual property, is the longest. Four parts are worth reading closely.
Assignments. Whenever Semrush hired an employee, consultant or contractor to build anything, it must have obtained "exclusive ownership" of the result, by law or by a valid written transfer of rights. If a contractor wrote part of your product, can you show the document that moved the rights to your company?
Licenses for software you use. Semrush promised, to its knowledge, that it had bought or licensed enough seats and enough rights for all the third-party software it uses, and that it wasn't under audit or dispute about it. A buyer is checking that the product isn't built on software you aren't licensed to use.
Open source. Semrush stated that it had not used open source in a way that would force it to publish its own source code, license it for others to modify, or give it away at little or no charge.
Trade secrets and unpaid developers. The company promised to keep a policy requiring employees, consultants and contractors with access to trade secrets to sign confidentiality agreements. It also promised, to its knowledge, that amounts owed to people who developed its important IP had been paid in full.
Most of these promises are qualified: they apply "except as has not been and would not reasonably be expected to be" material, or only "to the Company's Knowledge." That wording is common. A private deal may use tighter or looser wording. I haven't read one here.
How is customer data handled?
Section 3.15 covers privacy and data protection. Since 1 January 2023, Semrush's handling of personal and other protected information had to comply with five things: its contracts, privacy laws, the card-payment security standard PCI DSS where it applies, its own published privacy statements, and any consents it had collected. It also promised, to its knowledge, that there had been no data breach or unauthorized access to its products or systems, and that none of its systems or products contained backdoors, spyware, "time bombs" or similar code.
If you sell to businesses, this is where your security questionnaires, breach history and privacy policy meet. A buyer will want to see whether what you do matches what you say.
How much depends on a few customers?
Section 3.19 asks for a list of the 25 largest customers by annual recurring revenue over the 12 months to 30 September 2025, and a promise that none had given written notice that it would leave or materially worsen its contract. It asks for similar lists of the 25 largest suppliers and of technology vendors and partners above a spending threshold.
That is a direct way to ask: how concentrated is the revenue, and is any of it at risk? If three customers are a third of your revenue, expect to discuss it.
Which contracts limit the business?
Section 3.17 lists the contracts Semrush had to disclose. Several matter to a founder.
- Contracts that restrict competing, or selling to certain customers or regions. The wording covers restrictions on the company's affiliates "including Parent and its affiliates after the Effective Time," meaning a clause that stops you from selling to someone can stop the buyer's other businesses too.
- Contracts to put source code in escrow for a customer.
- Acquisition agreements with earn-outs or other future payments over $500,000.
- Settlements that restrict how the company operates.
It is worth reading your own contracts for these terms before a buyer does.
How long did the checking take?
The proxy statement's chronology gives a rough timeline. Adobe's first diligence questions to Semrush were answered by phone on 6 August 2025. Adobe gave a first verbal price on 27 August. Adobe held in-person diligence sessions with Semrush's executives on 24 and 25 September, and its advisors were given access to a virtual data room on 7 October. On 13 October Adobe proposed $12.00 a share and asked for 45 days of exclusivity so that it could finish diligence. After more sessions in late October, on 3 November Adobe said it needed more time. Semrush agreed on 5 November to extend exclusivity by one week, to 12 November, on condition that Adobe had completed its commercial and financial diligence apart from specified items. On 10 November Adobe said its diligence was substantially complete, and a second extension to 19 November was signed on 12 November. The merger agreement is dated 18 November, and the deal was announced the next day.
From data-room access on 7 October to signing on 18 November is 42 days. That is my arithmetic from the dates in the filing. It was a single buyer's schedule, with exclusivity, so I wouldn't treat it as typical. Adobe completed the acquisition on 28 April 2026 (Semrush, Form 8-K, 28 April 2026).
What does a public deal not show?
Three things, and they matter if your company is private.
First, the agreement says that none of the representations and warranties survive the closing (Semrush merger agreement, section 9.2). In a public-company sale, once shareholders are paid, the buyer has no claim against them for a breach. That is why the promises matter before signing and closing.
Second, private deals can have a different structure. Some hold money back or require sellers to cover certain losses after closing. I haven't read a primary source on how common that is, so I won't give numbers. If you are selling a private company, ask your lawyer how your deal handles it.
Third, Semrush's promises are qualified by a confidential disclosure letter and by what the company had already filed with the SEC. The public sees the promises, not the exceptions.
What would I do with this list?
This part is opinion.
I would use the sections above as questions about your own company and answer them in writing before a buyer asks:
- Can I show a signed assignment for everything anyone wrote for us, employee or contractor?
- Do we have licenses for all the third-party software we use, and do I know which open source is in the product and under which licenses?
- What is our record on security incidents, and does our privacy policy match what we do?
- Who are our largest customers, and what share of recurring revenue is that?
- Which contracts contain exclusivity, non-competes, source code escrow or earn-outs?
- What has changed since our last financial statements, and can I explain it?
None of this makes a deal happen. But a buyer who finds the answers ready tends to stop looking for what you're hiding. That last sentence is my view, not something the filing shows.
FAIR doesn't run diligence or a sale. It watches the buyers and deals around your company, so you know who is likely to ask these questions. To find them, see How to find potential acquirers for your SaaS company. For what an advisor does in a sale, see Do you need an investment banker to sell your startup?.
FAIR shows founders their likely buyers and the timing signals around them. See your own radar, free.
