Aegryn — Grading System
Aegryn Grading System.
Aegryn introduces its own certification system for tech assets, with full transparency across the 4 fundamental dimensions of value.
Full documentation
2026
The CIFS framework
Each asset is assessed across four independent dimensions, each scored from 0 to 25 points. The total score out of 100 determines the grade.
Code
Code Quality & Architecture
Source code quality, test coverage, technical debt, documentation, implementation security and scalable architecture. Review by certified senior engineers.
- Test coverage ≥ 70%
- Documented technical debt
- No critical vulnerabilities (OWASP Top 10)
- Decoupled and scalable architecture
- Complete API documentation
IP
Intellectual Property & Moat
Intellectual property, barriers to entry, registered trademarks, patents, contractual exclusivities and sustainable differentiation in the target market.
- Trademarks registered in target jurisdictions
- No active IP disputes
- Third-party dependencies under compatible licences
- Identifiable moat (network, data, regulation)
- Client contracts with non-compete clauses
Finance
Financial Health & Traction
Key financial metrics: ARR, MRR, churn, LTV/CAC, burn rate, runway, margins and growth history. All data is audited against source documents.
- ARR documented over minimum 24 months
- Monthly churn < 3%
- Gross margins > 60% (SaaS)
- Runway ≥ 12 months
- YoY ARR growth documented
Security
Security & Governance
GDPR and Swiss LPD compliance, infrastructure security, access management, third-party security audits, vulnerability disclosure policy and data governance.
- GDPR / LPD compliance documented
- MFA authentication on all admin access
- Data encrypted at rest and in transit
- Third-party security audit within last 18 months
- Documented incident management policy
Aegryn Grades
Each grade corresponds to a precise score range and a distinct asset profile. AEG ★ and AAA grades are awarded to fewer than 15% of submitted assets.
Exceptional
90–100 / 100
< 5% of certified assets
Exceptional asset. Reference architecture, strong IP, top-decile financial metrics, perfect compliance. Eligible for institutional transactions.
B2B SaaS ARR > €2M, churn < 1%, test coverage > 90%, trademarks in 3+ jurisdictions.
Sous-codes typiques
Excellent
75–89 / 100
10–15% of certified assets
High-quality asset with solid fundamentals across all four dimensions. A few documented improvement areas but not blocking.
SaaS ARR > €500K, growth > 30% YoY, managed technical debt, full GDPR compliance.
Sous-codes typiques
Solid
60–74 / 100
25–30% of certified assets
Good quality asset with identified strengths and clearly documented improvement areas. Eligible for standard M&A processes.
Growing SaaS, some gaps in tests or compliance, IP in consolidation.
Sous-codes typiques
Developing
45–59 / 100
30–35% of certified assets
Developing asset with identifiable potential but structural weaknesses to address. Eligible for Aegryn Review with remediation plan.
Product in early traction, significant technical debt, partially documented financial metrics.
Sous-codes typiques
Emerging
30–44 / 100
15–20% of certified assets
Early stage asset with partial fundamentals. Certification accompanied by a detailed remediation report. Not eligible for M&A without improvement.
MVP or pre-revenue product, undocumented architecture, compliance to build.
Sous-codes typiques
Sub-code nomenclature
Each dimension receives a sub-code from M01 to M04 (Maturity) and D01 to D04 (Depth) specifying the exact level within the dimension.
N°
Label
Définition
01
Reference
Sector reference level, top 5%
02
Solid
Above median, fundamentals mastered
03
In progress
Below median, improvement areas identified
04
Remediation
Insufficient level, remediation plan required
Full code example
An asset graded AAA with code C1-D01 | I2-M02 | F1-A01 | S2 reads as follows:
Code: reference level, full depth of analysis
IP: solid, confirmed legal maturity
Finance: reference, full data audit
Security: solid, third-party audit validated
The analysis process
Submission & pre-qualification
Receipt of file, verification of document completeness (data room, financials, codebase access). Pre-qualification within 5 business days. An incomplete file is returned without rating.
Technical analysis (Code + Security)
Code review by two Aegryn-certified senior engineers. Automated security scan followed by manual review of critical components. Duration: 5–10 days.
Commercial analysis (IP + Finance)
Financial metrics audit against source documents, IP verification with competent registries (INPI, IGE/IPI, EUIPO). Interview with the founder. Duration: 5–10 days.
Deliberation & validation
Both analysts deliberate and produce the conclusive report, following a reproducible and independent protocol.
Issuance & publication
The grade is issued, documented and versioned. The certificate is sent to the holder and published in the Aegryn register. A blockchain certification layer will reinforce the anchoring of this register over time.
Independence principles
Strict separation
Aegryn analysts have no financial interest in the assets they certify. Any relationship with the holder or acquirer triggers automatic recusal.
Reproducibility
Two independent analysts applying protocol v2.1 must reach the same grade to within ±1 sub-code. A greater discrepancy triggers an arbitration procedure.
Traceability
Each grade is versioned. Any revision generates a new version with full history traceability. The original grade remains viewable.
Coming reinforcement
Aegryn is progressively building a network of expert partners who can enrich certain reports with a complementary cross-review, as well as a blockchain certification layer to strengthen the traceability of the register. These additions will complement the already fully operational independent protocol, never replace it.
2026
| Grade | Label | Score | Rareté |
|---|---|---|---|
| AEG ★ | Exceptional | 90–100 / 100 | < 5% of certified assets |
| AAA | Excellent | 75–89 / 100 | 10–15% of certified assets |
| AA | Solid | 60–74 / 100 | 25–30% of certified assets |
| A | Developing | 45–59 / 100 | 30–35% of certified assets |
| B | Emerging | 30–44 / 100 | 15–20% of certified assets |
Automatic refusal conditions
Certain configurations trigger an automatic refusal regardless of the overall score — the algorithm produces a score, the expert gives the final opinion, but an automatic refusal can never be overridden.
Unresolved exposed secrets (C-40) combined with unresolved critical CVEs (C-34) → Code dimension refused
Active trademark dispute (I-18) or unformalised rights on third-party-produced codebase (I-21) → IP dimension refused
Unresolved critical vulnerabilities (S-17) or ongoing unresolved security incident (S-37) → Security dimension refused
Financial data not verifiable despite request → Finance dimension refused
Refusal to cooperate during the audit → Global certification refusal
Catalogue eligibility by maturity
Aegryn adapts its evaluation criteria based on asset maturity.
Pre-revenue / < 6 months traction
★/AAA/AA grade impossible on F. Grade C possible only if I=1 and C=1. Maximum AEG: A.
6–12 months of revenue
NRR not significant (period too short). F based on growth and unit metric quality (LTV:CAC, churn).
12–24 months of revenue
Full standard evaluation. All grades possible.
> 24 months of revenue
Audited ARR required for F-1 or F-2. NRR retention history over at least 4 quarters.
Pre-revenue with exceptional IP
Valuation on tangible assets only. F dimension gets a special "Pre-revenue" note with no numeric score. Maximum AEG: A.
Mandatory notice
While every effort has been made to remain objective, clients are informed that any certification involves an element of expert judgement. The information contained in an Aegryn Grade report is provided as professional certification, issued by Aegryn certified analysts. It does not constitute a guarantee of market value.
Certify your asset
Ready to submit your asset to the Aegryn Grade protocol?