Preflight · for venture capital
Cyber diligence built for how VCs actually work.
Meet Preflight— a 20-minute pre-investment red-flag scan on any target, term sheet covenants auto-generated from the findings, and portfolio-wide LP-letter reporting. From the team behind QCD, the five-pillar cyber diligence methodology used on the PE side of the table.
Why now
The 24-month shift.
What sat in the “nice to have” column two years ago is now showing up in LP RFPs, insurance underwriting, and exit valuations.
- 2023SEC cyber disclosure rules landed
- 2024LP RFP language shifted to require GP attestations
- 2025Insurance underwriting started pricing cyber DD process
- 2026AI-scaled attacks reach $10M-ARR portcos routinely
- 01
SEC cyber disclosure rules changed the calculus
Public companies must disclose material cyber incidents within 4 business days. Portcos going public inherit it. Underwriters and D&O insurers are pricing cyber DD posture in. Diligence you skipped becomes exit friction.
- 02
Institutional LPs are asking
CalPERS, university endowments, corporate pension funds — increasingly require GPs to attest to portfolio cyber DD practice. No answer means harder raises. Peer funds that can answer win the allocation.
- 03
Cyber insurance underwriting tightened
Premiums doubled 2020–2023. Underwriters ask what your cyber DD process is on new investments. No process means higher premiums — or no coverage on the fund’s own policy, and worse terms on the portco’s.
- 04
AI-scaled attacks reach small portcos
Deepfake CEO fraud, LLM-driven phishing, credential stuffing at scale. Portcos that were “too small to target” in 2022 are actively hit in 2026. Cyber posture on a $10M-ARR company matters now.
of deals with a cyber incident during or after close lose value.
FTI Consulting, M&A and Cybersecurity, 2026
of M&A deals delayed, repriced, or abandoned due to cyber diligence findings.
Westbourne, 2025
of institutional investors factor cybersecurity maturity into valuation decisions.
Marsh & McLennan, 2023
Verizon’s valuation reduction on Yahoo’s undisclosed breaches.
The reference case for every cyber-diligence conversation since
Why this exists
Venture is not a smaller version of private equity.
Every existing cyber-diligence workflow was built for PE deal teams — big checks, weeks of budget, dedicated operating partners. That shape doesn’t fit venture. You need a different shape entirely.
What you save. What you learn.
Fund reputation. Deal leverage. Exit valuation. LP confidence.
A 20-minute scan and a covenant library sound tactical. What they actually buy you is strategic — every one of these shows up on your fund’s ledger sooner or later.
Your fund's reputation
When a portco has an incident, LPs read about it. If you can point to the diligence you ran, the covenants you landed, and the posture reporting you've been doing, the conversation is very different from “we didn't check.”
Legal leverage in the term sheet
Covenants + reps & warranties are the only thing that gives you recourse if a portco misrepresents cyber posture pre-close. Board seat alone doesn't. This is what turns a finding into enforceable protection.
Valuation at exit
Every acquirer and IPO underwriter now runs cyber DD. Findings surfaced pre-investment give the founder 3–7 years to remediate. Findings discovered at exit become the Yahoo/Verizon story — valuation drag or a killed deal.
LPs before they ask
A one-page cyber section in the quarterly LP letter, generated from real portfolio posture data, wins fund raises against peer funds that shrug when the LP asks. Your GP annual meeting gets easier.
What “good” actually looks like
Every finding lands with a peer percentile: this target vs. companies at the same stage and in the same sector. You stop guessing what a Series B SaaS company's cyber posture should look like and start knowing.
Associate time and Google budget
Your associate is doing this diligence already — badly, in a spreadsheet, from Google. 20 minutes and a real output vs. a half-day of ad-hoc OSINT that misses things a scanner would catch. Cheaper per deal and better.
How it works
The scan finds it. The term sheet fixes it. The LP letter proves it.
- 01 · pre-term-sheet
20-minute red-flag scan
Fire on any target. External OSINT only — dark-web credential exposure, DMARC posture, attack surface, breach history, peer comparison. Output inside your partner meeting, not after it.
- 02 · term sheet + close
Every finding, a signed covenant
A finding on its own is a slide in a deck. A finding translated into a term-sheet covenant is enforceable protection — the thing you can hold a portco to three years from now. Every red flag maps to a proposed clause your counsel can drop straight into the term sheet or SPA.
- 03 · every quarter
LP-letter cyber section
A one-page cyber section for the quarterly LP letter, generated from the scans you’ve run + covenants you’ve landed + posture changes across the portfolio. Reportable to LPs. Defensible in the next raise.
The compounding output
Your next LP letter has a cyber section now.
Every scan you run flows into a portfolio view. Every quarter, a one-page cyber section is ready for the LP letter — specifically shaped for what institutional LPs are asking about right now.
(FAIR · probability-weighted)
(remediation-attributable)
this quarter
in signed term sheets
- Ember Retail dropped from the 68th to the 34th percentile after a credential-exposure incident on 2026-08-14 (external EAL estimate +$2.6M, driven by new signal on customer-data exposure). Remediation covenant already in place from Series A term sheet; board pushed for accelerated completion by 2026-Q4.
- Corvid AI completed Year-1 remediation of pre-investment findings, moving from the 5th to 82nd percentile for AI/ML at Series B (external EAL estimate −$4.1M). Full FAIR-quantified CCOD via QCD re-baseline attached as Exhibit B.
A worked example
What lands in your inbox 18 minutes later.
Stylized preview on a fictional Series B SaaS target. At GA, you’ll be able to run one yourself against a canned demo company from this page.
Not full QCD-worthy at this stage. Land covenants at term sheet; revisit at Series C.
- 42 employee credentials in known breach dumps (last 24 months)72p
- DMARC policy =
none— email spoofing possible48p - No public SOC 2 or Trust Center55p
- No exposed cloud storageclean
- No prior public breach or disclosureclean
Within 60 days of Closing, the Company shall complete credential rotation for all employees whose credentials appear in known breach databases as of the Cyber Red-Flag Scan dated [scan date], and shall implement mandatory password-manager adoption within 90 days.
Within 90 days of Closing, the Company shall implement DMARC with a p=reject policy, complete SPF and DKIM alignment, and provide the Board with evidence of enforcement.
Why us
Built by the team that already runs cyber diligence on the PE side.
Scan engine, covenant library, LP-letter template — all sit on the same platform that ships QCD, our PE-side cyber-diligence product, in 72 hours per deal.
Methodology
QCD — Quantitative Cyber Diligence
The five-pillar M&A cyber-cost methodology behind our PE product. Published book, referenced framework. VC-side covenants derive from the same finding taxonomy.
Read the methodologySubstrate
Federated tenants for the whole relationship
The same platform architecture that supports PE/Portco/LP/IC now supports VC/Portco/LP. When a portco onboards to vCISO Lite, your view and theirs are two lenses on the same data.
See the reporting layerTrack record
CISO-tested from the inside
Yolonda spent 20+ years building security programs at real companies — U.S. Air Force, Fortune 500 retail, a high-growth IPO, both sides of M&A. Every workflow here is one she needed at a real company.
See the full storyPricing
Design partners first. Pricing published at GA.
We’re running a design-partner cohort with a limited number of funds this fall. Public pricing lands with the GA release. If your fund would benefit from being on the cohort, get in touch — there’s no commitment beyond a weekly feedback call.
Own your side of the cyber-diligence table.
QCD runs cyber diligence on the PE side. Preflight brings it to venture. Get on the design-partner list before the cohort closes.