What a serious reader examines in a commercial security company, and why owners keep the file ready before anyone asks.

There is a rhythm to how deals happen in this industry. SDM Magazine’s review of 2025 M&A activity reported on nearly 100 security company acquisitions, with roughly 65 percent closing in the second half of the year. If 2026 follows the same rhythm, this industry’s busiest closing season is underway right now.

Between the first conversation and the closing sits a stretch of quiet work with a dry name: due diligence. From the chair where I sit, diligence is something plainer than its reputation. It is a careful reading of the company’s records by someone who was not in the room when they were made. I am one of those readers, and I want to walk through the heart of that reading, then make the case for a discipline that serves an owner whatever the company’s plans: keeping the file clean, and reading it yourself first.

A file with two jobs

Every security company’s records were built for one job: running the company. The monitoring agreements got signed and filed, the billing system grew account by account, and the license renewals happened on time because someone made sure they did. Records like that are shaped by years of reasonable calls made in the middle of busy weeks, and they do their first job well. The company runs.

The second job arrives later, and quietly. A banker reviewing a credit line. An insurance carrier at renewal. A partner, a possible buyer, or the next generation stepping in. Sooner or later, someone who was not there asks the file to speak for the company. We wrote in the five fundamentals that drive the value of a commercial security company that diligence slows down wherever records and reality disagree. The file’s second job is to say, clearly and on paper, what the owner already knows to be true.

That second job is what a serious reader examines. Every reading adjusts to the company in front of it, but its heart is consistent: seven things, in roughly this order.

What a serious reader examines

1. The recurring base, told three ways

We wrote about the attrition ledger, the running account-level record that proves how the recurring base behaves, and we said plainly that the retention record is where we start when we study a company. The fuller reading asks three sources to tell the same story: the agreements, the billing system, and the financial statements. The rate on the monitoring agreement matches the rate on the invoice. The accounts being billed match the agreements in force. The recurring revenue in the financials matches the billing detail underneath it. When those three agree, the reader can trust the base the whole company stands on.

Alongside that record sits concentration: the share of recurring revenue carried by the ten largest customers, and the mix across monitoring, service agreements, and inspections. Neither number is good or bad on its own. What matters is that the company knows its own numbers and can show where they come from.

2. The agreements themselves

Then the reading turns to the paper. Signed agreements, findable for every recurring account. Current terms, with renewals and rate changes captured in writing rather than remembered. It is common, in companies with decades-old accounts, for the oldest relationships to have the thinnest paper. Those customers are staying for the right reasons, and the relationship is real. The work is simply to let the paper catch up, account by account, on the next service visit or renewal.

3. The statements underneath

Behind all of it sit the financial statements, and commercial security has a signature the reader knows to look for. Monitoring billed in advance creates deferred revenue, so a portion of the cash on hand belongs, in accounting terms, to the months ahead. Receivables aging tells its own story about the customer base. Installation work in progress shows how the company manages the jobs that feed the recurring base. None of this requires a big-company finance department. It requires statements prepared consistently, on a basis the company can explain, year after year.

4. The compliance shelf

Licenses current in every state and jurisdiction the company serves. Technician certifications on file. Insurance policies current, with certificates easy to produce. Where fire and life safety are part of the business, inspection records complete and retrievable. None of this makes exciting reading, which is exactly the point. A complete compliance shelf tells a reader that the company’s habits are sound in the places nobody is watching.

5. The monitoring chain

For most commercial security companies, the promise to the customer runs through a central station, whether the company’s own or a wholesale partner’s. A reader will want to see that agreement: its term, its pricing, and how accounts are handled under it. Customers’ confidence runs through that chain every night, so a reader’s confidence will too.

6. The team, on paper

We wrote in the five fundamentals piece that a security company’s value walks around in work trucks. The file version of that truth is a picture of the team a reader can follow: who leads what, how long people have been aboard, and which relationships live with which people. This is usually the proudest page in the file. Tenure, in this industry, is its own kind of proof.

7. The story, checked against the file

The last part of the reading is not a document at all. It is the walk-through, the conversation, the owner’s telling of how the company came to be what it is. A serious reader is checking one thing: that the story and the file agree. In well-run companies they almost always do. The file just lets the agreement be seen.

Read your own file first

One advisor quoted in SDM’s review of 2025 said it directly: owners should conduct their own diligence, before anyone else does. The review’s larger theme said why. The companies that reached premium outcomes were ready long before a buyer appeared.

We would make it a standing habit: read your own file once a year, the same week every year, the way a stranger would. Lay the three tellings of the recurring base side by side. Pull ten agreements and check them against ten invoices. Walk the compliance shelf. Most gaps found this way are small: a rate change never papered, an agreement filed somewhere only one person knows, a certificate that needs reissuing. Found now, they are quiet fixes on the company’s own schedule. The occasional larger find is worth even more, because the most expensive place to discover it is across the table from a reader. A gap found by someone else becomes a question, and questions have a way of multiplying.

The annual read pays the company back whether an outside reader ever arrives or not. Credit renewals go faster. Insurance conversations start from evidence. A successor could find their footing. The company becomes easier to run for the same reason it would be easier to read.

To make the habit easy to start, we put the whole reading on one page: download The Clean File checklist, free to print and hand to whoever keeps the records.

What a clean file changes

When we study a company whose file is clean, the entire process changes temperature. Questions get answered by pages instead of memory. Weeks that would have gone to reconstruction go to conversation instead. Speed protects value, and the file is where speed comes from.

The deeper change is leverage, and it belongs to the owner. The owner who has read their own file walks into every conversation already knowing what a reader will find, with their own numbers, on their own definitions, telling their own story. Nothing in diligence should ever be a surprise to the person who built the company. A clean file is how they make sure of it.

Where we stand

We built Halo Service Partners on the conviction that in commercial security, trust is the product. A clean file matters to us for exactly that reason: it is decades of kept promises, organized so anyone can see them.

And because we read files for a living, we can say something else plainly: we rarely meet a finished one. Most of the files we read sit somewhere in the middle, exactly where years of busy weeks leave them, and good outcomes get built from there. The clean file is a head start an owner gives themselves. It has never been an entry requirement with us.

Continuity is the center of how we partner. The name stays, the team stays, and the customer relationships stay. ProTech Security and Verified Security both run under their own names today, with the leaders and teams who built them still serving the customers who know them. When we read an owner’s file, we are reading the record of everything we intend to protect.

If you’re thinking about the future

If you own a commercial security company and you are thinking about its future, in any direction, we are glad to compare notes: on the reading, on the market, and on what your next chapter could look like. Wherever your file stands, the conversation starts there.

Start a conversation