For Immediate Release
vCISO Lite Ships Enterprise-Defensible Diligence Rooms — Ed25519 Deletion Certificates, Isolated Document Viewer, and Two-Stage Watermarking for Growing Companies Handing Cyber Materials to Acquirers, LPs, and Investors
The v2.0 hardening release replaces every component a general counsel could reasonably object to: RFC 7515 Ed25519 JWS deletion certificates anyone can independently verify against a public key, a Guacamole-based viewer that keeps raw document bytes out of the reader's browser, two-stage watermarking that identifies which specific reader saw a leaked page, and ephemeral per-room storage buckets that don't survive close. Live today on Business tier and above, no separate SKU.
ATLANTA — March 30, 2026 — vCISO Lite today shipped an enterprise-defensible release of Diligence Rooms, the surface growing companies use to hand their cyber materials to a would-be acquirer’s deal team, an LP performing operational due diligence, or an investor running pre-investment cyber review — with cryptographic guarantees the material will not leak. The v2.0 hardening release replaces every component of the earlier stack that a general counsel could reasonably object to: Ed25519 JWS deletion certificates that anyone can independently verify, a Guacamole-based isolated document viewer that keeps raw file bytes out of the reader’s browser entirely, and a two-stage watermarking pipeline that identifies which specific reader saw a leaked page.
Cyber diligence in the middle market runs on email attachments, shared Google Drives, and one-off consulting engagements — none of which produce artifacts that survive a follow-up question a year later, and none of which give the target company confidence that the SOC 2 report, pen-test findings, or incident write-up it just handed over will be destroyed at close. Two forces are making that gap acute in 2026. The SEC’s 8-K cyber disclosure rule, effective December 2023, requires public companies to disclose material cybersecurity incidents within four business days — which means the diligence materials a target hands over during a deal become the record every future disclosure gets measured against. And private equity deal teams now treat cyber posture as a first-order diligence workstream rather than an optional add-on, with dedicated cyber leads asking sharper, more technical questions than the questionnaire templates from three years ago anticipated.
“The tension that’s never been resolved in cyber diligence is that the material has to leave the target company’s hands to do the work, but it should never leave the target company’s control,” said Yolonda Smith, founder of vCISO Lite. “Every founder who has raised a round or been approached by an acquirer has hesitated before uploading a pen-test report or an incident write-up to a shared drive — because the counterparty is not going to email you a screenshot of the delete button. Diligence Rooms answers that with mechanism, not policy: an Ed25519 deletion certificate the counterparty’s counsel can verify against a public key, a viewer that never puts raw bytes in the reader’s browser, and a watermark that identifies who saw a page if it ever surfaces somewhere it shouldn’t.”
What’s in the release
The v2.0 release makes Diligence Rooms defensible to an enterprise legal team — the general counsel of a growing company handing material to an acquirer, and the counterparty’s counsel who has to trust the destruction after close. The delivered components:
- Ed25519 JWS deletion certificates— every document destroyed at room closure produces a certificate in RFC 7515 compact serialization, signed with an asymmetric key. Anyone with the published public key can independently verify the certificate without cooperation from vCISO Lite. Replaces the earlier HMAC-SHA256 model, which required disclosing the shared secret to allow third-party verification.
- Guacamole-based isolated document viewer— documents render on the platform, not in the reader’s browser. Rasterized pages are streamed as pixels; raw file bytes never leave the ephemeral per-room storage bucket. Screenshot and copy protections are enforced at the viewer, not through a client-side library the reader can disable.
- Two-stage watermarking— a room-code watermark is baked into every page at rasterization time; a viewer- identity watermark (reader’s email plus session timestamp) is overlaid dynamically at view time. If a page surfaces on a competitor deck or in a leaked slide, the second stage identifies which specific reader saw it.
- Ephemeral per-room GCS storage buckets— each diligence room provisions its own tenant-isolated storage bucket at the moment it goes active; the bucket is destroyed at room closure. There is no shared bucket where cross-tenant data could intermingle, and bucket-level destruction is a stronger guarantee than object-level deletion for the general counsel who has to sign off on the destruction attestation.
- Two-pass analysis architecture— per-document classification runs at upload against the room’s scope and the artifact type the document was uploaded against (Gemini 2.0 Flash); a room-level synthesis pass runs on demand across every document, interview response, artifact-checklist gap, and external-intelligence finding (Claude). Findings are extracted with direct evidence quotes from the source document; the risk score uses a deterministic logarithmic formula that produces identical output for identical inputs.
- Artifact checklist system— 37 artifact types organized across six categories (Technology, Security, Compliance, Operations, Business & Legal, People) with gap-weighted scoring. The target contact interacts with the checklist through an external portal, marks items uploaded, N/A with explanation, or unavailable with explanation. The gaps are visible to the deal team and feed the risk score with defensible penalties.
- Certificate download endpoint— the customer, the external reader, or the reader’s counsel can download the Ed25519 deletion certificate from a documented API endpoint any time after room closure, verify the signature against the published public key, and keep the artifact in their own deal file.
Why this ships now
The v2.0 release closes a gap the earlier stack could not close. The earlier deletion-proof scheme used HMAC-SHA256, which is cryptographically fine but operationally weak: verifying an HMAC requires the shared secret, which means the counterparty’s counsel cannot check the destruction was real without vCISO Lite handing them the key. Ed25519 asymmetric signatures resolve that: the signing key stays on the platform, the public key is published, and anyone — opposing counsel, the target company’s board, an auditor two years later — can independently verify the certificate.
The isolated viewer replaces an earlier browser-side rendering path that, however carefully instrumented, still delivered raw file bytes to a machine the platform did not control. Guacamole with the HTTP tunnel transport (WebSocket is not used because the platform ingress strips upgrade headers) keeps the file bytes on platform infrastructure and streams only pixels — the raw document cannot be exfiltrated by right-click, by developer tools, or by a browser extension.
The two-stage watermark closes the last exfiltration path: a determined reader can still photograph the screen with a phone. The viewer-identity overlay applied at view time means the resulting image identifies the specific reader whose session produced it, which is a materially different deterrent than a static “confidential” stamp.
How the surface is scoped
Diligence Rooms is the target-sidesurface — it serves growing companies handing cyber materials outto counterparties. It is not, and has never been, an acquirer’s diligence workbench: buy-side workflows for firms performing diligence on portfolio targets are a separate product surface with different customer, threat model, and permission structure. The boundary is deliberate. The target company is protecting its own material; an acquirer analyzing a target is asking a different set of questions with a different set of authorizations.
The frameworks the AI analysis draws on are the ones vCISO Lite already supports on the compliance side: SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF, NIST 800-53, CMMC, and the other frameworks in the platform’s compliance catalog. Findings are anchored in direct evidence quotes from the target document, not in generic AI generalizations; the risk score is deterministic and reproducible; and no analysis output is generated for artifact categories the room did not receive documents against.
Diligence Rooms is the second surface in vCISO Lite’s target-side diligence family. The Investor Portal, launched February 2, is the lighter-weight counterpart — a scoped, revocable reader channel for handing security posture materials to investors, LPs, and lenders during a fundraise or credit review. Diligence Rooms is the deeper counterpart for the full document exchange that runs during an acquisition or an LP’s operational due diligence, where the material at stake is sensitive enough that the general counsel needs cryptographic destruction proof, not a checkbox.
Availability
Diligence Rooms v2.0 is live today on the vCISO Lite Business tier and above at no additional cost. Existing Business-and-above customers will see Diligence Rooms in the platform navigation on their next sign-in; new signups can provision their first room from the diligence surface after upgrading to Business tier or higher on vcisolite.com. There is no separate SKU; the surface is included in the tier.
About vCISO Lite
vCISO Lite is a compliance and cyber risk platform for growing companies that don’t have a full-time CISO. The platform helps customers close compliance gaps (SOC 2, ISO 27001, PCI DSS, HIPAA, and similar frameworks), generate defensible security policies, complete enterprise security questionnaires, manage vendor risk, and — with Diligence Rooms — hand their cyber materials to acquirers, investors, and LPs with cryptographic proof the material will not persist beyond the deal. Founded by Yolonda Smith, a career cybersecurity leader with 20+ years building security programs from zero to IPO. vCISO Lite is headquartered in Atlanta, Georgia. Learn more at vcisolite.com or read the founding story.
Media Contact
Press & Analyst Inquiries
Yolonda Smith, Founder
press@vcisolite.com
###
Related reading
The Private Equity Buyer's Playbook for Cyber Due Diligence — the 72-hour LOI-to-IC pathway Diligence Rooms operationalizes.
Cyber Cost of Deal: A Worked Example — the CCOD walk-through Diligence Rooms produces per engagement.
The Year-Zero Cyber Baseline for Portfolios — the post-close baseline handoff Diligence Rooms wires into portfolio ops.