Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes · Documents Ingested: 11
Assessment Scores — 8-Domain Profile
Buyer Discount Risk
EBITDA (most recent FY): $476,000 (AI-extracted) · Exit Readiness: 4.5/10 — Material Gaps
| Score | Band | Buyer Discount Risk |
|---|---|---|
| 8.0 – 10.0 | Institutional Ready | Minimal — few gaps for buyers to exploit |
| 6.5 – 7.9 | Market Ready | Low — some negotiating leverage for buyers |
| 5.0 – 6.4 | Needs Preparation | Moderate — expect re-trade attempts |
| 3.5 – 4.9 | Material Gaps | High — significant discount likely |
| Below 3.5 | Not Ready | Very High — consider delaying go-to-market |
Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.
↑ What strengthens your position
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Top 3 Strengths
- No domain in this assessment reached the level this report will describe as a strength. That is a statement about where the scores sit today, not a judgement that the business has none — the Priority Fixes below are where the nearest ones are.
Top 3 Risks
- OROwner Risk at 3.0/10 (CRITICAL RISK) represents a critical gap that will trigger a buyer discount during negotiation. Buyers will conduct extensive diligence into founder dependencies, decision-making concentration, and transition planning; a CRITICAL RISK posture here signals to acquisition teams that post-close operational continuity cannot be assumed, creating material liability exposure and a basis for price concession before close.
- DRDiligence Risk at 4.1/10 (NEEDS WORK) creates a material liability that will surface across financial records, contract documentation, and system audits during buyer due diligence. This needs-work posture indicates gaps in documentation, data integrity, or disclosure readiness that buyers will require remediation on before listing, and unresolved findings will trigger a haircut to deal valuation as buyers protect themselves against hidden obligations or incomplete revenue records.
- TMTechnology & Systems Maturity at 3.8/10 (NEEDS WORK) poses a deal-risk factor around infrastructure scalability, system architecture, and technical debt that buyers will flag as a post-close investment requirement. The needs-work posture indicates that legacy systems, manual workflows, or fragmented tooling will require buyer capital to integrate or modernize, creating re-trade risk and a basis for discount negotiations as acquirers model remediation costs into their offer.
Recommended Priority Fixes
The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap below.
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| dr_01 | Tier A Document Set Completeness Document evidence ATS_Employee_Roster.csv · ATS_GL_Export.csv · ATS_Customer_Onboarding_SOP.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_CRM_Pipeline.csv Atlas Security Technologies has provided an employee roster with 16 staff members including hire dates and salaries, and general ledger exports showing revenue and expense transactions from January–March 2025, along with one executed customer contract (Regional Health System, $16,000/month). However, critical Tier A documents are absent or incomplete: no consolidated financial statements, tax returns, or corporate formation records appear in the retrieved excerpts; only a single customer contract is represented despite the GL and CRM data indicating multiple active clients (Regional Property Group, Peachtree Hills Apts, Cumberland Mall, Marietta City Schools, Vinings Apts); and no insurance certificates are provided despite OpEx entries referencing "Contractors GL + auto" coverage. | 5/10 | NEEDS WORK | |
| dr_02 | Evidence Currency Document evidence ATS_CIM.txt · ATS_Financials.csv · ATS_HC_Profile.txt · ATS_Customer_Contract_RegionalHealthSystem.txt The Confidential Information Memorandum is dated April 2026 and reflects 2025 revenue of $2.8M, providing current financial context for an exit process underway at that time. However, the Human Capital Profile is also dated April 2026 but contains internal workforce data (28 FTE + 14 PT security personnel, 4 management staff) that contradicts the CIM's stated headcount of "16 employees," creating material ambiguity about which snapshot is current. The Regional Health System contract is dated January 1, 2025 with a 36-month term and auto-renewal provisions, placing it within an acceptable window, but the absence of explicit dates on the financial data excerpt and the internal inconsistency between contemporaneously-prepared documents introduce clarity gaps that would typically trigger buyer verification before closing. | 6/10 | ADEQUATE | |
| dr_03 | Substantiation of Stated Figures Document evidence ATS_GL_Export.csv · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Customer_Onboarding_SOP.txt · ATS_HC_Profile.txt Atlas Security Technologies presents headline figures only as narrative claims without systematic underlying documentation. While the general ledger exports (ATS_GL_Export.csv) show individual transactions for January and March 2025—including monitoring revenue of $16,000–$16,000 monthly from Regional Property Group and project revenue ranging from $9,000 to $48,000—there is no comprehensive revenue summary, EBITDA calculation, headcount roster, customer count list, or retention metric documented anywhere in the retrieved materials. The company's customer relationship and operational documents reference specific accounts (Regional Health System at 18% of revenue, nine of 22 accounts held by one employee) but provide no consolidated customer roster, total headcount count, or retention rates that a reader could independently verify. | 3/10 | CRITICAL RISK | |
| dr_04 | Corporate Records Completeness Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_CIM.txt · ATS_HC_Profile.txt · ATS_Financials.csv · ATS_Customer_Onboarding_SOP.txt Atlas Security Technologies LLC has a formation certificate (established as an LLC in Smyrna, Georgia, founded in 2018) and customer contracts filed, but critical corporate governance records are absent from the retrieved documents. No operating agreement, shareholder agreement, current capitalization table, or formal governance records (board minutes, equity ledgers, or ownership documentation) appear in any of the internal documents provided, creating significant gaps in exit readiness documentation. | 3/10 | CRITICAL RISK | |
| dr_05 | Contract File Completeness Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv Atlas Security Technologies maintains executed customer contracts filed in its onboarding system, with specific evidence including a fully executed Regional Health System agreement signed by the President and filed with supporting business associate documentation. However, the retrieved documents provide evidence of only one material customer contract on file; while the CIM references 52 active monitoring and managed service clients, no comprehensive inventory of executed contracts by counterparty is presented, and vendor and lease agreements are not evidenced in the materials provided. | 6/10 | ADEQUATE | |
| dr_06 | Employment File Completeness Document evidence ATS_Customer_Onboarding_SOP.txt · ATS_HC_Profile.txt · ATS_Employee_Roster.csv · ATS_Cybersecurity_Assessment.txt Atlas Security Technologies maintains an employee roster documenting 16 staff members with hire dates, roles, and compensation, but critical employment documentation is absent from the retrieved records. While a compensation and benefits structure is documented in internal profiles, there is no evidence of filed offer letters, employment agreements, employee handbook, organizational chart, or eligibility records (such as I-9s or benefits enrollment documentation) for the workforce. The company operates with documented policies for background checks, drug screening, and Georgia POST certification verification, but these do not constitute comprehensive employment file completeness. | 3/10 | CRITICAL RISK | |
| dr_07 | Data Room Organisation & Access Document evidence ATS_GL_Export.csv · ATS_CIM.txt · ATS_IT_Asset_Inventory.csv · ATS_Cybersecurity_Assessment.txt · ATS_Employee_Roster.csv Atlas Security Technologies' filed materials exist as disconnected CSV exports and text files without a coherent organizational structure or index—the general ledger, IT asset inventory, employee roster, and cybersecurity assessment appear to be point-in-time exports rather than an organized data repository. File naming is generic (e.g., "ATS_GL_Export.csv," "ATS_IT_Asset_Inventory.csv") and provides minimal discoverability, and there is no evidence of a centralized index, controlled access framework, or documented retrieval procedures that would enable a buyer to navigate and selectively access materials without substantial reassembly and manual organization. A due diligence process would require the company to reconstruct and systematize these materials rather than granting access to an existing organized collection. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness Document evidence ATS_HC_Profile.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_CIM.txt · ATS_Employee_Roster.csv Atlas Security Technologies has no formal succession plan in place, and the business exhibits acute owner dependency with no documented transition protocols. The owner holds all major client relationships and approves all proposals over $25K; the Regional Health System account (18% of revenue) is owner-held with only a secondary contact identified, creating material risk if the owner were unavailable for more than 2 weeks. No key employee agreements, successor identification, or handoff documentation exist, and the business has not operated without the owner for extended periods. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture Document evidence ATS_Customer_Onboarding_SOP.txt · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_HC_Profile.txt · ATS_CIM.txt Atlas Security Technologies has documented its customer onboarding process in a formal SOP (version 2.1, last updated September 2025) and maintains post orders manuals for all 22 active accounts, but the CIM explicitly identifies "Owner dependency — a key employee holds all major client relationships and approves all proposals over $25K" and "Key technical risk — Lead Technician (a key employee, 5 years) holds most system design and integration knowledge" as critical risk factors. The cybersecurity assessment reveals that client VPN credentials are stored in a shared spreadsheet with no password vault, field device access relies on shared credentials among technicians, and there is no formal access review process, indicating that despite some process documentation, the majority of institutional knowledge and critical client relationships remain concentrated in key individuals without systematic transfer mechanisms. | 3/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth Document evidence ATS_HC_Profile.txt · ATS_Customer_Onboarding_SOP.txt · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt Atlas Security Technologies has a stable 4-person management layer with 0% turnover and 2–5 year tenure, but the business remains heavily dependent on the owner for critical functions. The owner personally manages all new client onboarding (contract execution, site survey, installation, commissioning, and handoff), holds the direct relationship with the largest client (Regional Health System, 18% of revenue), and approves all supervisor-level hires; the company has no documented backup for operations and no formal succession plan. The business operated without the owner for up to 1 week during vacation, but client escalations were not handled, and the owner acknowledges that a 2+ week absence would put the largest account relationship at risk. | 4/10 | NEEDS WORK | |
| owr_04 | Key Person Concentration Beyond Owner Document evidence ATS_HC_Profile.txt · ATS_Employee_Roster.csv · ATS_CRM_Pipeline.csv · ATS_GL_Export.csv Atlas Security Technologies has material key person concentration beyond the owner. The Operations Manager holds the direct relationship with Regional Health System, which represents 18% of revenue, with no documented backup; the documents explicitly state that "if a key employee were unavailable for more than 2 weeks, the Regional Health System account relationship would be at risk." Additionally, the Operations Manager manages operations with "no documented backup," and the company has operated without formal succession planning, with only ad-hoc coverage during the owner's absences that excluded client escalations. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration Document evidence ATS_HC_Profile.txt · ATS_Financials.csv · ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt Atlas Security Technologies' largest customer, Regional Health System Properties, represents 6.9% of FY2025 revenue ($192,000 of $2.8M), while the top 5 customers combined account for approximately 23.6% of revenue ($660,000). The company serves 52 active monitoring and managed service clients with an average contract value of $31,200 annually, and revenue is well-distributed across healthcare, retail, multifamily residential, and education verticals, though internal documentation identifies the Regional Health System account as holding elevated relationship risk due to key employee dependency. | 7/10 | ADEQUATE | |
| cq_02 | Revenue Predictability & Recurring Mix Document evidence ATS_CIM.txt · ATS_GL_Export.csv · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Financials.csv Atlas Security Technologies derives 58% of FY2025 revenue ($1,624,000) from recurring sources under annual and multi-year contracts, with the largest customer (Regional Health System Properties) on a 36-month auto-renewing agreement at $192,000 annually and documented monthly recurring revenue of approximately $135,300. Monthly recurring revenue data from January through December 2025 shows consistent growth and stability ($124,000–$138,000 range), demonstrating predictable 12-month forward visibility, though the company lacks formal documented renewal rate tracking and relies on project revenue ($1,176,000 in FY2025) to supplement the recurring base. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_HC_Profile.txt Atlas Security Technologies' Regional Health System contract includes an assignment clause permitting the provider to assign to a successor entity in connection with acquisition or merger with 60 days client notice, and the contract explicitly acknowledges that security systems integrators are frequently acquired by larger platform companies. The company operates 52 active monitoring and managed service clients documented in ServiceMax with standardized contract execution via DocuSign, indicating a centralized approach to contract management that supports transferability, though the documents do not confirm assignment language across the full contract portfolio. | 8/10 | STRONG | |
| cq_04 | Churn Rate & Retention Metrics Document evidence ATS_CIM.txt · ATS_HC_Profile.txt · ATS_Financials.csv · ATS_GL_Export.csv · ATS_Customer_Contract_RegionalHealthSystem.txt Atlas Security Technologies does not track or disclose customer churn rate or net revenue retention metrics in any of the provided documents. While recurring revenue grew from $1.05M (FY2023) to $1.624M (FY2025) and the company maintains a customer base of at least 22 active accounts, there is no evidence of formal retention programs, documented churn analysis, or proactive customer retention initiatives beyond standard contract terms—the company's approach to customer retention appears reactive and undocumented. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability Document evidence ATS_Customer_Onboarding_SOP.txt · ATS_IT_Asset_Inventory.csv · ATS_HC_Profile.txt · ATS_Financials.csv · ATS_GL_Export.csv Atlas Security Technologies has a formal New Client Onboarding SOP (Version 2.1) that documents the five-stage process from contract through handoff, but execution is heavily concentrated in specific individuals—the SOP lists "a key employee" as the owner across all five stages, with critical steps like contract execution, commissioning, and account handoff showing no documented backup or role delegation. The IT Asset Inventory and HR Profile reveal that two key employees manage all client relationships and set operational standards, with no evidence of formal supervisory development programs or cross-training protocols that would enable independent execution by other staff members. | 4/10 | NEEDS WORK | |
| ops_02 | Technology & Systems Scalability Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt · ATS_Customer_Onboarding_SOP.txt · ATS_GL_Export.csv · ATS_Financials.csv Atlas Security Technologies relies on third-party cloud platforms (Avigilon, Lenel S2, Milestone VMS) for core service delivery, which provide inherent scalability, but the company's internal systems show concerning gaps that would impede 3x growth. The cybersecurity assessment identifies critical vulnerabilities including unvaulted client credentials stored in shared spreadsheets, lack of privileged access management, no EDR deployment, and absent formal access reviews—issues that would compound significantly under accelerated growth. Additionally, onboarding and service delivery processes are heavily dependent on key personnel (referenced repeatedly as process owners), and the company lacks documented backup testing and cloud backup for local files, indicating incomplete operational infrastructure needed to support rapid scaling without architectural intervention. | 5/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration Document evidence ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_IT_Asset_Inventory.csv · ATS_Financials.csv Atlas Security Technologies exhibits critical single-source dependencies that create material exit risk. The company outsources UL-listed central station monitoring to a third party with a contract renewal due Q4 2026, and relies on preferred installer relationships with Avigilon, Lenel S2, and Axis Communications for core platform delivery—yet the documents provide no evidence of formal alternative vendors, documented switching procedures, or contractual protections beyond the standard assignment clause in client agreements. Additionally, the Lead Technician holds "most system design and integration knowledge" with no documented succession plan, and a key employee controls all major client relationships and approvals over $25K, creating operational dependencies that mirror vendor concentration risk. | 4/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_Financials.csv Atlas Security Technologies lacks documented financial controls and a formal close process. The retrieved documents contain only high-level annual and monthly revenue data (FY2023–FY2025 and Jan–Dec 2025 actuals) with no evidence of monthly financial close timelines, budget vs. actual reviews, documented control procedures, or a CFO or Controller role—the company's financial management appears ad hoc, with the owner setting compensation and rates based on contract terms rather than a formal review process. No audit trail, reconciliation procedures, or management financial oversight cadence is documented in the available materials. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship No evidence submitted · withheld from score ATS_HC_Profile.txt · ATS_Financials.csv · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Onboarding_SOP.txt Atlas Security Technologies' financial records are internally maintained in QuickBooks with no evidence of CPA review, audit, or compilation engagement in the retrieved documents. The company lacks a formal CPA relationship, and financial statements appear to be generated internally from operational data (revenue figures are tracked monthly in ServiceMax and QuickBooks, per the onboarding SOP), with no third-party accounting firm involvement documented for FY2023–FY2025. Material rework of books and formal financial statement preparation by an external CPA will be required before M&A diligence can proceed. | — | ||
| fr_02 | Add-Back Documentation Document evidence ATS_HC_Profile.txt · ATS_CIM.txt · ATS_Customer_Onboarding_SOP.txt Atlas Security Technologies identifies only $48,000 in add-backs for 2025 normalized EBITDA ($36,000 owner compensation above market and $12,000 personal vehicle expenses), but provides no supporting documentation, schedules, or verification of these adjustments in the retrieved materials. The documents show owner compensation is drawn as $155,000 in S-corp distributions rather than payroll, with no formal benchmarking process or independent CPA review evident, and the company lacks a formal add-back schedule that separates personal and business expenses for buyer verification. | 3/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency Document evidence ATS_HC_Profile.txt · ATS_Financials.csv · ATS_CIM.txt · ATS_GL_Export.csv Atlas Security Technologies recognizes revenue across two categories—recurring (monitoring and managed services at 58% of total revenue) and project-based work—with transactions consistently coded to revenue accounts in the general ledger by transaction type (e.g., "Revenue:Monitoring" and "Revenue:Project" entries dated throughout March 2025). However, the documents provide no evidence of documented revenue recognition policies, formal audit procedures, or explicit deferred revenue tracking mechanisms, and no GAAP compliance statement or accounting policy documentation appears in the retrieved materials. The company's recurring revenue is consistent month-to-month ($136K–$138K in 2025), but without evidence of a formal accounting framework or policy audit, the consistency of application across periods cannot be fully verified. | 6/10 | ADEQUATE | |
| fr_04 | Three-Year Financial Trend Document evidence ATS_CIM.txt · ATS_Financials.csv · ATS_HC_Profile.txt Atlas Security Technologies demonstrates strong financial performance over the three-year period from FY 2023 to FY 2025, with total revenue growing from $2.1M to $2.8M (16.7% growth in FY 2024, 14.3% in FY 2025) and EBITDA expanding from $252K to $476K while gross margins remain stable at 40% and EBITDA margins improved from 12.0% to 17.0%. The financial trend is supported by clean year-over-year comparability with normalized EBITDA of $524K after documented add-backs, and recurring revenue growing from 50% to 58% of total revenue, indicating a strengthening subscription-based foundation. | 8/10 | STRONG |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits Document evidence ATS_CIM.txt · ATS_Financials.csv · ATS_HC_Profile.txt · ATS_Employee_Roster.csv Atlas Security Technologies holds two required Georgia licenses—Low-Voltage Contractor license LVA008821 and Alarm Systems Contractor license GA-ASC-41209—both stated as current in the Confidential Information Memorandum. However, the documents do not address transferability of these licenses in a change-of-control transaction, nor do they confirm whether the licenses are held in the entity's name versus tied to individual personnel, which is a material gap for exit readiness given the security contractor licensing environment. | 7/10 | ADEQUATE | |
| lc_02 | Contract Change-of-Control Provisions Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_HC_Profile.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt Atlas Security Technologies has secured assignment language in its largest customer contract—the Regional Health System agreement ($192,000 annually) explicitly permits assignment to a successor entity with 60 days' notice and acknowledges that security integrators are frequently acquired. However, the documents do not evidence systematic legal review of change-of-control provisions across the full portfolio of 52 active monitoring and managed service clients, nor do they address assignment status for vendor agreements with preferred installer partners (Avigilon, Lenel S2, Axis Communications) or lease terms for the Smyrna office and warehouse facility. | 7/10 | ADEQUATE | |
| lc_03 | Employment Law Compliance Document evidence ATS_Customer_Onboarding_SOP.txt · ATS_HC_Profile.txt · ATS_CIM.txt · ATS_Employee_Roster.csv Atlas Security Technologies lacks formal employment compliance documentation across multiple critical areas. The Human Capital Profile contains no mention of I-9 verification procedures, non-compete or non-solicitation agreements for field technicians or management, or documented employment classification rationale, despite the business model creating significant risk of employee departure with client relationships (the Operations Manager notes that owner holds direct relationship with Regional Health System representing 18% of revenue with no documented backup). Compensation structures show inconsistent benchmarking—the Account Supervisor salary is documented as "slightly below ASIS median" with no formal review process since 2023, and the owner draws S-corp distributions rather than payroll with vehicle and cell allowances requiring add-back treatment at close, creating tax classification and documentation risk. | 5/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership Document evidence ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt Atlas Security Technologies exhibits significant IP ownership ambiguity across critical business assets. Client credentials—a core operational asset—are stored in an unvaulted shared spreadsheet rather than a secure vault, and the cybersecurity assessment identifies that "some client system passwords [are] not rotated after tech departures" with "no formal access review for client system credentials," creating material risk that departing employees could retain unauthorized access to client systems. Additionally, field iPads used for security system programming contain client network diagrams and configurations with no mobile device management, encryption, or remote wipe capability, and there is no documentation establishing formal IP assignment of ServiceMax data, client configurations, or technical designs to the entity level versus individual technician access. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability Document evidence ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_GL_Export.csv · ATS_CIM.txt · ATS_Customer_Onboarding_SOP.txt Atlas Security Technologies maintains general liability and contractors insurance (Contractors GL + auto noted in January 2026 payroll records), but the retrieved documents contain no evidence of professional liability or errors & omissions coverage specific to security systems integration work, nor any disclosure regarding claims history, open matters, or tail coverage arrangements. The company's critical cybersecurity gaps—including unvaulted client system credentials stored in a shared spreadsheet and lack of formal access credential management—create material contingent liability exposure; a client breach via compromised Atlas credentials would trigger potential E&O claims, client indemnification demands, and reputational harm, yet no reserves or insurance provisions are documented to address this exposure. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership Document evidence ATS_Cybersecurity_Assessment.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_HC_Profile.txt · ATS_Customer_Contract_RegionalHealthSystem.txt Atlas Security Technologies has significant undocumented system dependencies and relies heavily on personal account control across critical functions. The cybersecurity assessment identifies that client VPN credentials are stored in a shared spreadsheet with no password vault, ServiceMax field service uses shared credentials among 6 technicians, and the customer onboarding SOP lists "a key employee" as the owner of contract execution, site survey, installation, commissioning, and handoff processes with no formal documented backups. Additionally, the Regional Health System account—representing 18% of revenue—is held directly by a key employee with only partial backup coverage, creating a single point of failure for a material revenue stream. | 3/10 | CRITICAL RISK | |
| tm_02 | Cybersecurity & Data Protection Posture Document evidence ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_HC_Profile.txt Atlas Security Technologies has deployed Microsoft Defender and Fortinet FortiGate UTM but lacks critical controls required for exit readiness. The external cybersecurity assessment identifies five material gaps including no EDR solution, unvaulted client credentials stored in a shared spreadsheet, MFA not enforced for field technicians, no MDM on field iPads, and no documented incident response plan or cyber insurance. The assessment rates overall risk as MEDIUM and flags client credential management as CRITICAL, noting that "client breach via compromised Atlas credentials would be reputationally devastating" — a material liability for an acquirer inheriting the company's healthcare and institutional client base. | 4/10 | NEEDS WORK | |
| tm_03 | Data Integrity & Business Intelligence Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_GL_Export.csv · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt Atlas Security Technologies maintains basic financial and operational records but exhibits significant data fragmentation and accessibility risks. The GL export shows transactional data recorded by a single key employee with no documented audit trail or segregation of duties, while the CRM pipeline is owned entirely by one individual with no backup access; simultaneously, the cybersecurity assessment identifies critical gaps including unmanaged client credentials stored in shared files and compromised field devices holding sensitive client configurations, indicating that operational intelligence depends heavily on individual knowledge holders rather than systematic, secure data infrastructure. | 4/10 | NEEDS WORK | |
| tm_04 | Technology Vendor & Subscription Management Document evidence ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt Atlas Security Technologies has documented core vendor relationships with Avigilon, Lenel S2, Axis Communications, and UL central station monitoring reflected in customer contracts and preferred installer status, but critical operational tools lack formal vendor management documentation. The cybersecurity assessment identifies that client VPN credentials and system access passwords are stored in a shared spreadsheet rather than a centralized password vault, and the onboarding SOP shows that client network credentials are "collected and stored" without specifying entity-owned credential management systems, creating significant transferability risk and potential breach liability upon ownership transition. | 4/10 | NEEDS WORK | |
| tm_05 | Technical Debt & Modernization Risk Document evidence ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_Financials.csv Atlas Security Technologies operates on a cloud-based foundation (Microsoft 365, ServiceMax, Avigilon, Lenel S2) but exhibits material technical debt concentrated in endpoint and access security rather than core infrastructure modernization. The cybersecurity assessment identifies five gaps requiring remediation totaling $2,500 one-time plus $300/month ongoing, with critical findings including unvaulted client credentials stored in shared spreadsheets, field devices lacking MDM enrollment or encryption, and six field technicians operating without MFA—exposures that create both immediate operational risk and post-close remediation obligations for a buyer. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Workforce Retention & Tenure Document evidence ATS_HC_Profile.txt · ATS_Employee_Roster.csv · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_CRM_Pipeline.csv Atlas Security Technologies maintains stable management (0% turnover over 24 months, average tenure 3.8 years) and acceptable post supervisor turnover (12%), but field-level security officer turnover stands at 48% annually with an average tenure of only 1.4 years—typical for the contract security industry at this price point. Critical revenue risk exists in client relationships: the founder holds the direct relationship with Regional Health System (18% of revenue) with no formal backup, and a key employee manages 9 of 22 accounts directly; the company documents that loss of the founder for more than 2 weeks would put the Regional Health System account at risk, and there is no documented succession plan. | 6/10 | ADEQUATE | |
| hc_02 | Compensation Competitiveness Document evidence ATS_HC_Profile.txt · ATS_CIM.txt · ATS_Customer_Onboarding_SOP.txt Atlas Security Technologies has benchmarked select roles against ASIS standards (Operations Manager at benchmark, Account Supervisor slightly below at $58,000 vs. $62,000 median), but lacks a formal compensation review process—compensation for key employees has not been reviewed since 2023 and is set by the owner based on client contract terms rather than systematic market analysis. Armed security officers are paid $19.00–$21.00/hr, which is noted as slightly below union rates, creating retention risk for a role critical to service delivery; additionally, there are no retention bonuses or group retirement plan, and the buyer would likely need to establish retirement benefits to retain the management layer post-close. | 4/10 | NEEDS WORK | |
| hc_03 | Recruiting & Training Capability Document evidence ATS_HC_Profile.txt · ATS_Customer_Onboarding_SOP.txt · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_CIM.txt Atlas Security Technologies has documented hiring processes (background checks, drug screens, Georgia POST verification) and a 2-day unarmed officer onboarding program with post orders manuals for all 22 active accounts, but the organization exhibits critical scalability constraints. Owner approval is required for all supervisor-level and above hires, there is no formal supervisory development program, and the company lacks a formal compensation review process—with the Operations Manager's compensation last reviewed in 2023. While 90-day new-hire retention of 61% is within industry norms, the absence of owner-independent recruiting authority and documented promotion criteria limits the business's ability to scale hiring without founder involvement. | 4/10 | NEEDS WORK | |
| hc_04 | Bench Depth & Succession Beyond Owner Document evidence ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_Employee_Roster.csv Atlas Security Technologies has significant single points of failure beyond the owner in critical roles. The Operations Manager role has no documented backup, and a key employee holds the direct relationship with Regional Health System (18% of revenue) with only partial secondary coverage; the company acknowledges that if this individual were unavailable for more than 2 weeks, the account relationship would be at risk. No formal succession planning exists, and while the business has operated without the owner for up to one week during vacation, client escalations were not handled during that period, demonstrating that key operational and client-facing functions lack tested redundancy. | 3/10 | CRITICAL RISK | |
| hc_05 | Compensation/Benefits Structure Transferability Document evidence ATS_HC_Profile.txt · ATS_CIM.txt · ATS_GL_Export.csv · ATS_Customer_Onboarding_SOP.txt Atlas Security Technologies has formal, portable group health (UnitedHealthcare) and dental benefits (MetLife), but compensation structure contains significant owner-specific arrangements requiring cleanup at close: the owner draws $155,000 in S-corp distributions rather than W-2 payroll, discretionary supervisor bonuses (~$4,000/yr) flow through the owner's account, and personal expenses including a vehicle ($720/mo) and cell phone ($145/mo) are add-backs. The company lacks a retirement plan entirely, with only the owner maintaining a personal account, creating a gap that a buyer would need to address to retain management staff. No formal compensation review process exists since 2023, and the structure is not documented in an employee handbook. | 4/10 | NEEDS WORK |
Complete remediation plan across all scored domains. The Priority Fixes section above highlights the five ranked starting points.
| Domain | Layer8 Service | Value at Risk | Est. Timeline | Typical Investment |
|---|---|---|---|---|
CQCustomer Quality | Contract Audit & CRM Implementation | $79,968 | ⏱ 6–8 wks | $5,000 – $9,000 |
DRDiligence Risk | Security Hardening & Data Room Preparation | $68,544 | ⏱ 4–6 wks | $2,500 – $4,500 |
OROwner Risk | Succession Planning & Knowledge Capture Sprint | $57,120 | ⏱ 8–10 wks | $6,000 – $10,000 |
OSOperational Scalability | Process Documentation & Systems Audit | $49,504 | ⏱ 8–10 wks | $4,000 – $7,000 |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | $38,080 | ⏱ 8–12 wks | $5,000 – $9,000 |
HCHuman Capital | Workforce Retention & Bench Depth Sprint | $38,080 | ⏱ 8–10 wks | $2,500 – $5,000 |
FRFinancial Readiness | Books Cleanup & Add-Back Schedule | $26,656 | ⏱ 4–6 wks | $2,000 – $4,000 |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | $22,848 | ⏱ 6–8 wks | $3,500 – $6,500 |
| TOTAL | $380,800 | — | $30,500 – $55,000 | |
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group LLC provides formal engagement proposals following assessment delivery.
Layer8 Tech Group LLC delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Layer8 Tech Group LLC delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.Schedule a Discovery Call →
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling No evidence submitted · withheld from score ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt The retrieved documents contain no evidence of AI voice agents or automated after-hours call handling capabilities; the company's operations focus on field service management, monitoring contracts, and client onboarding through manual processes with no mention of inbound call automation or voice AI systems. | — | ||
| R02 | CRM Presence & Workflow Automation Document evidence ATS_Customer_Onboarding_SOP.txt · ATS_CIM.txt · ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt Atlas Security Technologies uses ServiceMax as a CRM for client records and system documentation, and maintains a tracked pipeline in a CSV file with deal stages and probabilities; however, the system is heavily owner-dependent with all 12 active opportunities assigned to a single key employee, and there is no evidence of automated workflows—follow-ups, notifications, and client communications appear to be manually managed. The CRM presence is inconsistent and non-transferable, creating significant business continuity risk. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture No evidence submitted · withheld from score ATS_IT_Asset_Inventory.csv · ATS_CIM.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_AR_Aging.csv · ATS_CRM_Pipeline.csv The retrieved documents contain no evidence of after-hours or 24/7 lead capture capabilities; the company operates a traditional security systems integration business with no mention of website forms, chatbots, or automated lead routing systems. All sales activity documented in the CRM pipeline shows deals assigned to individual sales representatives, indicating manual prospecting and lead handling rather than automated capture infrastructure. | — | ||
| R04 | SMS Appointment Reminders & Confirmations No evidence submitted · withheld from score ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_Customer_Onboarding_SOP.txt · ATS_Customer_Contract_RegionalHealthSystem.txt The retrieved documents contain no evidence of automated SMS appointment reminders, confirmations, or follow-up workflows; the company's onboarding and customer communication processes rely on manual calls, emails (monitoring confirmation letters), and scheduled check-in calls managed by key employees. SMS appointment management automation is not mentioned or referenced in any operational procedures, tools stack, or system documentation reviewed. | — | ||
| R05 | Automated Review Solicitation No evidence submitted · withheld from score ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_Customer_Onboarding_SOP.txt · ATS_Customer_Contract_RegionalHealthSystem.txt The retrieved documents contain no evidence of automated post-service review solicitation; the onboarding SOP mentions only a "30-day check-in call" and "quarterly review rotation" with no indication of systematic review requests, and no automated SMS or email review triggers are referenced in any operational procedures or systems documentation. | — | ||
| R06 | Smart Follow-Up Sequences No evidence submitted · withheld from score ATS_Cybersecurity_Assessment.txt · ATS_Customer_Contract_RegionalHealthSystem.txt · ATS_Customer_Onboarding_SOP.txt · ATS_HC_Profile.txt · ATS_CIM.txt The retrieved documents contain no evidence of automated follow-up sequences for leads or dormant clients; the onboarding SOP describes a manual, owner-dependent process with a single 30-day check-in call scheduled, and there is no mention of drip campaigns, email automation, or re-engagement workflows for unconverted leads or lapsed accounts. | — |
No automation maturity band is published for this company. 1 of 6 criteria were scored; 5 had no evidence in the material provided, and a band selected from the remainder would describe the criteria that happened to be answerable rather than the revenue infrastructure.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 1/2 | PARTIAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows — on a defined scope and a fixed timeline.Schedule a Discovery Call →
Compliance Notes
PII was detected and redacted in 9 document(s) prior to ingestion:
ATS_CIM.txt: PERSONATS_CRM_Pipeline.csv: PERSONATS_Customer_Contract_RegionalHealthSystem.txt: PERSONATS_Customer_Onboarding_SOP.txt: PERSONATS_Cybersecurity_Assessment.txt: PERSONATS_Employee_Roster.csv: PERSONATS_GL_Export.csv: PERSONATS_HC_Profile.txt: PERSONATS_IT_Asset_Inventory.csv: PERSON