ProofStack

Micro-SaaS due diligence: how to verify revenue claims before you buy

When you buy a micro-SaaS, most of the "evidence" comes from the seller: dashboard screenshots, a verbal MRR figure, one growth curve. Our day job is verifying small software products' public revenue disclosures line by line (47 cases, every figure linked to its source). Below is that craft applied to buy-side due diligence — every claim carries its source and observation date, so you can reproduce each check yourself.

Ground rule: a screenshot is not evidence

Of the 47 products we have audited, only 14 carry a dated, clickable public revenue disclosure; the rest are recorded as "not disclosed". The industry default is the opposite: Indie Hackers' product directory showed 17 self-reported revenue markers against a single verified one in its static HTML (observed 2026-09-03), and Starter Story's 2026 breakdown pages now label figures "Estimated from public sources" (observed 2026-09-06) — even content platforms concede that most circulating numbers are estimates or self-reports.

Three evidence grades (the same scale we grade all 47 cases on)

The five-step verification checklist

  1. Ask for read-only payment-provider access. This is now a category standard: the marketplace TrustMRR builds its entire business on Stripe read-only API verification (listed products' financials are physically checked over the API; deals settle via Escrow.com with a 3% commission — trustmrr.com FAQ, observed in full 2026-09-06). A seller refusing read-only access is itself a signal.
  2. Do arithmetic against the pricing page. Public tiers times claimed customer count should land in the same order of magnitude as claimed MRR. Our pricing benchmarks (43+ audited pricing pages, median first paid tier per category) give you the cross-reference.
  3. Check the claim's history. Use the Web Archive to compare the seller's pages over time: how often pricing changed, whether the revenue framing shifted. Several of our own verifications survived only via archives (Omnivore's shutdown notice 404s on the original site; the archive still verifies).
  4. Verify the sources themselves. Open every interview and article the seller cites. Link rot is worse than you expect — even founder-written pages we cite go dead (nathanbarry.com/convertkit-story returned 403, observed 2026-09-03). A number resting on a dead link needs a fresh source.
  5. Treat "not disclosed" as unknown — not as zero, and not as fine. Traffic, churn, customer concentration: every figure the seller did not give belongs on your question list, not in your imagination.

Four red flags

Don't want to run the five steps yourself?

That is exactly what our $99 evidence audit does: pricing benchmarks, search demand, competitor teardowns and revenue-claim verification for the specific product you are buying (or building), human-verified line by line, delivered in 48 hours — you pay after delivery. Read a complete sample first. Spending $99 to sanity-check a five-figure decision is the best-priced insurance in this market.

Every statement about a third party reflects public pages on the stated observation dates; verify each one yourself.