Build a Company Due Diligence Agent with Claude Code
A proper first pass on a public company means hours in EDGAR: the 10-K, the 8-Ks, the Form 4s, the 13D filings. An agent can do that pass in minutes, from a single ticker.
A due diligence agent is an AI assistant that pulls a company's public record and flags what matters: its legal structure, its financials, who is buying or selling the stock, and the 8-K red flags like restatements and auditor changes. You can build one in Claude Code by connecting a single MCP server to SEC and federal data, with no enterprise seat and no scraper to maintain. This guide shows the setup, the workflow, and what it honestly cannot do.
claude mcp add, then saving a subagent that chains the tools and cites every filing. It handles the public-record screening pass, not the private data room or legal review.What can a company due diligence agent actually check?
A due diligence agent built on public filings can check the parts of diligence that live in the SEC and federal record: the company's legal structure and subsidiaries, its financials and ratios, insider buying and selling, 8-K material events, activist stakes, and the risk sections of its 10-K. It will not open a private data room or read unfiled contracts, so it covers the screening pass, not the full legal review a deal needs.
That screening pass is most of the early work, though.
Classic due diligence splits into financial, legal, and operational review, as any due diligence checklist lays out. The agent owns the parts that are public and filed: the financial statements, the legal-entity structure, the regulatory events, and the ownership signals. The private-side items, the unfiled contracts and the data room, stay with your team.
The enterprise tools do more, at a price. AlphaSense, Charli AI, and similar platforms add news, analyst research, and expert calls, billed as a seat.
The build-your-own version trades that breadth for ownership and cost. You run it locally, you point it at any ticker, and you pay for API credits instead of a subscription.
| Option | What it does | Data | Cost |
|---|---|---|---|
| Build-your-own (this guide) | Chains SEC and federal tools into a Claude Code agent | Public SEC + federal | API credits, you own it |
| AlphaSense Due Diligence | Deal-team workflow automation, expert calls | Filings + news + experts | Enterprise seat |
| Charli AI | Enter a ticker, get a report | SEC + FactSet + news | Subscription |
| Manual EDGAR | You read every filing yourself | Public | Free, your time |
What do you need to build a due diligence agent in Claude Code?
You need three things, and two of them are free. First, Claude Code, Anthropic's terminal coding agent. Second, a data source the agent can call, which is where a Model Context Protocol server comes in. Third, an API key for that server. For SEC and federal data, edgrapi exposes 19 tools over one MCP endpoint, with a free tier and no card, so the whole build costs nothing to try.
MCP is the piece that makes this simple.
It is an open standard that lets an agent call external tools in a uniform way. Instead of writing a client for each data source, you point Claude Code at one MCP server and it discovers the tools on its own.
Edgrapi's server carries the tools a company pass needs on a single key: entity resolution, subsidiaries, fundamentals, ratios, insider trades, 8-K events, 13D activist stakes, and the federal contract and spending feeds. One connection, one key.
That breadth is the reason to use one MCP server instead of wiring up five APIs. Without it, a due diligence chain means a separate client, a separate auth, and a separate response shape for filings, for insider data, for fund holdings, and for the federal feeds. The MCP server collapses all of that into one connection the agent discovers on its own.
Grab a free key from the dashboard first. You will paste it into the connection in the next step.
How do you connect SEC and government data to Claude Code?
You add the MCP server with one command. Claude Code speaks MCP natively, so connecting edgrapi's HTTP server is a single claude mcp add call with your key passed as a bearer header. Run it in your project, and the agent can call every tool the moment the command returns.
Here is the command, straight from the Claude Code MCP docs.
claude mcp add --transport http edgrapi \
https://api.edgrapi.com/mcp \
--header "Authorization: Bearer YOUR_EDGR_KEY"
Run /mcp inside Claude Code to confirm it connected and to see the tool list. You should see the 19 tools, from resolve_entity to get_events.
If you want your team to share the server, add it at project scope instead, which writes a .mcp.json to the repo root that you can commit.
{
"mcpServers": {
"edgrapi": {
"type": "http",
"url": "https://api.edgrapi.com/mcp",
"headers": { "Authorization": "Bearer ${EDGRAPI_KEY}" }
}
}
}
Using the ${EDGRAPI_KEY} variable keeps the key out of version control. Set it in your environment, and Claude Code expands it at connection time. Project-scoped servers prompt each teammate for approval before they run, which is the safe default.
What does the agent check, step by step?
The agent runs a chain, each step feeding the next. It starts by resolving the company to its SEC identity, then pulls structure, financials, insider activity, and red flags in order, and ends with a written summary. You can trigger the whole thing with one plain-language request once the tools are connected.
The chain looks like this.
It calls resolve_entity with the ticker to get the canonical name, CIK, exchange, and industry, the same ticker-and-CUSIP resolution you would use on its own. A CUSIP or a messy name resolves the same way.
It calls get_subsidiaries for the legal-entity structure and jurisdictions, then get_fundamentals and get_ratios for the financial picture, margins, returns, solvency, and liquidity.
It calls get_insider for recent Form 4 activity, where each trade carries a buy-or-sell signal and a flag for whether it was a pre-scheduled 10b5-1 sale.
It calls get_events for 8-K material events and get_activist for any 13D or 13G stake above 5%, the two richest sources of red flags.
For a deeper read, it can also call get_company for the profile, get_sections to pull the risk-factors and MD&A text from the 10-K, and search_filings to scan the full-text index for litigation or a named counterparty. Each wraps a single SEC source, so the agent is orchestrating the same public filings you would open by hand, in the order you would open them.
You do not script any of this. You describe the job, and the agent sequences the calls:
Run due diligence on NVDA. Resolve the entity, list its
subsidiaries and jurisdictions, summarize the latest financials
and key ratios, flag any notable insider selling, and surface any
8-K restatements, auditor changes, or activist stakes. Cite the
filing behind each finding.
How do you save it as a reusable subagent?
You turn the workflow into a Claude Code subagent so you can run it on any ticker without retyping the prompt. A subagent is a markdown file at .claude/agents/ with a short frontmatter block and a system prompt. It runs in its own context window, calls only the tools you allow, and returns a clean summary to your main session.
Create the file .claude/agents/due diligence.md.
---
name: due diligence
description: Public-company due diligence pass from SEC and federal data
tools: resolve_entity, get_subsidiaries, get_fundamentals, get_ratios, get_insider, get_events, get_activist
---
You run a first-pass due diligence review on a US public company.
Given a ticker, resolve the entity, then report: legal structure
and jurisdictions, financial summary and key ratios, insider
buy/sell activity (flag 10b5-1 vs discretionary), and red flags
(8-K item 4.02 restatements, 4.01 auditor changes, 13D/G stakes).
Cite the filing behind every claim. State clearly what the public
record does not cover. Do not give investment advice.
Now you invoke it by name. In Claude Code, ask the due diligence subagent to review a ticker, and it runs the chain in isolation and hands back the report. The main window stays clean.
This is the pattern the Claude Code docs recommend: keep heavy, multi-step work in a subagent with a narrow tool list, so it does not fill your main context. Pair it with a short CLAUDE.md that holds your house rules, like "always cite the accession number," and the agent behaves the same way every run.
The subagent also keeps the review contained and honest. Its tool list is fixed in the frontmatter, so it can only pull the sources you approved, never wander into something you did not intend. It runs in its own context window, so a long diligence chain does not crowd out whatever else you have open. And it hands back a cited summary rather than a wall of raw tool output. When you want it to cover more later, you add a tool to the list, not a new integration to your stack.
What red flags does the agent catch?
The agent is strongest at the forensic red flags, because the SEC data marks them cleanly. An 8-K item 4.02 is a non-reliance notice, the formal start of a restatement. An item 4.01 is an auditor change, often the quieter signal that comes first. On the insider side, the agent flags open-market sales and separates discretionary trades from pre-scheduled 10b5-1 plans. A 13D filing shows an activist crossing 5%.
These are the signals a human analyst hunts for, and they are exactly what the filings tag.
Take insider activity. In one real Apple filing, an officer sold 2,399 shares at about $332 for roughly $796,000, on a 10b5-1 plan. The agent reports the sale, the role, the value, and the plan flag, so you know it was scheduled, not a reaction.
The agent reads the same 8-K event feed that specialist tools do, including the item 5.02 executive departures and any going-concern language in the filings. On the ownership side, it reads the insider trade signal, which is what separates one routine scheduled sale from a cluster of discretionary selling worth a second look.
Restatements and auditor changes are rarer and heavier. When one fires, it is worth a human read, and the agent points you straight at the filing.
The point is not that the agent judges these for you. It is that it never misses one and always cites the source, which is the part a tired analyst gets wrong at 6pm.
What can a due diligence agent not do?
A due diligence agent built on public filings cannot replace legal or commercial due diligence. It sees the SEC and federal record, not the private data room: no unfiled contracts, no customer lists, no management interviews, no cap table beyond what filings disclose. It also does not judge materiality or give investment advice, and its output needs a human to verify before anyone relies on it.
Treat it as a fast first pass, not a verdict.
It is scoped to US public companies, too. A private target, a foreign issuer with no US listing, or a pre-IPO startup has little or none of this data, so the agent comes back thin.
And the output is only as current as the filings. The regulators have noticed the trend, too: the SEC's 2026 examination priorities name firms' use of AI as a focus area, and the standing advice is to document how a tool fits your process and to confirm its sources before you act on them. An agent that cites every filing makes that verification easy, which is the whole reason to build it this way rather than trusting a black box that just hands you a conclusion.
What does it cost to run a due diligence agent?
A single company pass costs a handful of API credits, not a subscription. Each tool call bills by weight: a light lookup like resolve_entity is 1 credit, a parse like get_fundamentals is a few, and the heaviest filing pulls are 5. A full chain across six or seven tools runs on the order of 20 credits, so a free account covers several complete passes before you spend anything.
That is the real contrast with the enterprise tools.
A seat in a diligence platform is a fixed monthly cost whether you run one company or none. A build-your-own agent costs only what it calls, so it scales down to zero when you are not using it and up cleanly when you are.
Run the numbers against a platform seat. A diligence tool at a few hundred dollars a month earns its price for a team screening dozens of targets a week. For an analyst who checks a handful of companies before calls, the same work is a few dollars of credits, and the agent sits idle for free the rest of the month.
Failed and empty calls are not billed in full, so an agent probing a thin private company does not run up a bill chasing data that is not there.
Point it at a ticker before your next call
If you screen public companies, a due diligence agent you build in Claude Code turns an afternoon of EDGAR into a few minutes and a cited report. Connect the MCP server, save the subagent, and point it at the next ticker on your list. Keep a human on the verification, lean on the forensic red flags it catches cleanly, and start free on the docs.
Frequently asked questions
What is a due diligence agent?
A due diligence agent is an AI assistant that gathers a company's public record and flags what matters for a research or investment decision: its structure, financials, insider trading, and regulatory red flags. Built on SEC data, it automates the screening pass of due diligence, pulling and citing filings in minutes. It does not replace legal diligence or human judgment.
How do I build a due diligence agent in Claude Code?
Connect an MCP server that exposes SEC data to Claude Code with claude mcp add --transport http, then save a subagent in .claude/agents/ that chains the tools: resolve the entity, pull subsidiaries, financials, insider trades, and 8-K events, and write a cited summary. Edgrapi's MCP server carries all 19 tools on one free key, so the whole build costs nothing to try.
How do I connect SEC data to Claude Code?
Run claude mcp add --transport http edgrapi https://api.edgrapi.com/mcp --header "Authorization: Bearer YOUR_KEY". Claude Code speaks MCP natively, so that one command connects the server and discovers its tools. Use /mcp to confirm the connection. To share it with your team, add it at project scope, which writes a .mcp.json to the repo you can commit.
What red flags can an AI agent catch in SEC filings?
The clearest ones are 8-K item 4.02 (non-reliance, the start of a restatement), item 4.01 (an auditor change), insider open-market selling, and 13D filings showing an activist crossing 5% ownership. The SEC data tags each of these, so an agent can surface them reliably and cite the filing. It flags them for a human to judge, rather than judging them itself.
Can an AI agent replace due diligence?
No. An agent automates the public-record screening pass, not the full review. It cannot see a private data room, unfiled contracts, customer lists, or management, and it does not judge materiality or give investment advice. Its output needs human verification before anyone relies on it, which is why an agent that cites every filing is worth more than one that just summarizes.
Is SEC data free to use through an agent?
The SEC filings themselves are public and free. What you pay for is the parsing and the API that turns them into tool calls an agent can make. Edgrapi offers a free tier with no card, and each tool call bills by weight (1 to 5 credits), so a full company pass costs about 20 credits and a free account covers several passes before you spend anything.