Diligence Rooms and Investor Portals — controlled sharing for cyber materials
For vCISO Lite customers who need to hand cyber materials to an investor, LP, or would-be acquirer. RFC-021 lands the engagement-scoped, tenant-isolated Diligence Room with ephemeral per-room storage, a separate investor / external-reader portal, and deletion certificates as first-class artifacts.
Diligence Rooms and Investor Portalslanded inside vCISO Lite this week — the controlled-sharing surface for vCISO Lite customers who need to hand cyber materials to an investor during a fundraise, an LP performing operational due diligence, or a would-be acquirer during a sale process. RFC-021 defines the engagement-scoped room as the unit of work.
What’s in the release
- Room lifecycle model.A customer creates a room for a named external reader (an investor, an LP, an acquirer’s deal team), grants scoped access, uploads the cyber materials the reader is asking for, and closes the room when the review finishes. Every state transition is auditable and bound to a named engagement owner on the customer side.
- Ephemeral per-room storage.Every room gets its own GCS bucket for the life of the engagement. When the room closes, the bucket is deleted — no cross-room data persistence, no shared storage layer that could leak between simultaneous engagements. Full tenant isolation at the storage layer, not just the application layer.
- Investor / external-reader portal.The external reader (whoever the customer invited to review) reaches the materials through a separate portal with its own scoped access — they don’t see any other room the customer runs, and the customer’s primary vCISO Lite tenant isn’t reachable from the external portal. Same passwordless authentication model as the rest of the platform.
- Deletion certificates as first-class artifacts.Closing a room emits a signed deletion certificate that the external reader (and the customer’s counsel, if named) can verify against a published public key. It’s the receipt that says “the room is closed, the data is gone, here is the proof” — addressed at the anxiety a target company feels about handing sensitive material to a counterparty.
Why this matters
Growing companies constantly get asked to hand cyber materials to someone outside the company — a VC doing pre-investment diligence, an LP asking a fund’s portfolio company for a cyber posture summary, an acquirer’s deal team during an LOI process. Most of that material flow happens over email, in shared drives, or in a hastily-provisioned data room that no one closes cleanly at the end. The Diligence Room feature turns it into a first-class, engagement-scoped, closeable workflow inside vCISO Lite — alongside the compliance work the customer is already doing on the platform.
Related reading
The PE Buyer's Playbook for Cyber Due Diligence — the LOI-to-IC workflow the Diligence Room substrate powers.
Cyber Cost of Deal: A Worked Example — the CCOD output the Diligence Room substrate produces.