Every release worth marking — product launches, new surfaces, methodology publications. Reverse-chron. No release notes theatre; the ones that actually change what customers can do.
A 20-minute pre-investment red-flag scan on any target, term-sheet covenants auto-drafted from the findings, and a one-page LP-letter cyber section that gets easier every quarter. Design-partner cohort open now.
vCISO Lite’s compliance agents, working end-to-end — with cryptographically signed actions, reasoning traces you can read, and freshness-verified evidence. As much or as little of the work as you want to hand over.
The first shipping GRC risk register that auto-generates customer-environment-specific scenarios from live signals across the platform — not from a pre-built library. Three-layer architecture (board appetite / risk / deficiency) per FAIR discipline. NACD, NIST CSF 2.0, NISTIR 8286A, ISO 31000 grounded.
For regional security VARs, GRC implementers, and small MSPs. Sliding-scale recurring margin up to 30% on Enterprise. Operator-track white-label lands in Q4 2026.
The QCD product is live at diligence.vcisolite.com. Per-engagement, deal-team-shaped diligence that returns a single Cyber Cost of Deal (CCOD) number — five defensible pillars, priced against the acquirer's valuation model, not a red/yellow/green rating.
The MCP surface for vCISO Lite. Ask your compliance program anything from Claude, GPT, or your own agent — get evidence-backed answers with the citations attached.
Quantitative Cyber Diligence for M&A: how to translate cyber risk into a dollar figure your deal team can act on. The methodology that drives our diligence surface, in book form.
Progressive-disclosure UI backed by live FAIR-style Monte Carlo simulation. Loss Exceedance Curves from real percentiles, per-finding ALE and remediation cost derived from BLS + Gartner data, assessment findings that flow into the operating program instead of a shelved report.
RFC-017 lands the Cyber Risk Quantification engine: FAIR-shaped LEF × LM decomposition, 10,000-run Monte Carlo per scenario, Loss Exceedance Curves as primary output, BLS + Gartner blended labor rates for remediation cost. Every dollar figure downstream is now live simulation, not a lookup table.
The Diligence Room becomes a cryptographically auditable record. Ed25519 JWS deletion certificates, a Guacamole-based isolated viewer for customer-uploaded documents, and two-stage watermarking (visible + steganographic) that identifies the external reader if a page turns up somewhere it shouldn't.
RFC-027 consolidates every compliance framework into a shared Go module with canonical IDs, alias resolution, and TypeScript codegen for the frontend. Every service now imports from the same registry — no more hardcoded framework maps scattered across the platform.
Credential stuffing is the top attack vector against SaaS. Removing passwords eliminates the class. Magic link + mandatory TOTP is the primary flow, with passkeys and social login as alternatives. The external portals (DD room, investor portal, vendor portal) use the same passwordless model — no easier back door.
Two invisible-but-load-bearing substrate pieces: OpenFGA answers per-resource authorization questions (not role checks), and Lago handles metered consumption between the platform and Stripe. Every tier-gated feature and metered service downstream of this week inherits both.
RFC-016 lands the Knowledge Base as first-class content infrastructure, alongside launch articles for business controls, N/A overrides, security testing, action items, inbound questionnaires, and the enforceability matrix. Versioned, in-context, cross-linked to the surfaces they explain.
RFC-024 and RFC-014 land the same week. Unified Work Management brings pipeline / bottleneck / assignment views across every service; the Standards Tab is rewritten as a prioritized work queue driven by framework deadlines, gap analysis, evidence freshness, and dependencies. Compliance becomes an operating queue, not a spreadsheet.
Where the Diligence Room is the container, the Investor Portal is what the investor actually sees. Scoped external-reader access, passwordless authentication, document view analytics, letterhead on generated policies, time-bound access. For every founder assembling a Google Drive folder at midnight the night before a term-sheet call.
For vCISO Lite customers who need to hand cyber materials to an investor, LP, or would-be acquirer. RFC-021 lands the engagement-scoped, tenant-isolated Diligence Room with ephemeral per-room storage, a separate investor / external-reader portal, and deletion certificates as first-class artifacts.
A three-step mandatory wizard for essential business context, progressive disclosure for depth, and a Stripe-style persistent checklist for first-value actions. Two days before official incorporation, this was the first substantive customer flow to ship.