All press releases

For Immediate Release

vCISO Lite Launches the Investor Portal — a Scoped, Revocable, Audited Channel for Growing Companies Handing Security Materials to Investors, LPs, and Lenders

Included on vCISO Lite Business tier and above. Growing companies use it to give investors, LPs, and lenders scoped read access to policies, DD interview content, and posture summaries — with magic-link + one-time-code sign-in, per-document view analytics, real-time revocation, and every access recorded in the platform's audit trail.

ATLANTA — February 2, 2026 — vCISO Lite today launched the Investor Portal— a scoped, revocable, audited channel that growing companies use to hand security materials to investors, LPs, and lenders during a fundraise or lender diligence. The Investor Portal replaces the ad-hoc Google Drive folder with a permissioned reader experience: customers choose which materials each investor sees, investors sign in with a magic link and one-time code, and every view is timestamped in the platform’s audit trail. Live today on the Business tier and above of vCISO Lite, with no separate SKU.

The context is a market change growing companies have already felt. Enterprise procurement now sends 200-question security assessments before any contract; investors bring the same posture questions into Series A and Series B diligence, and lenders bring them into credit reviews. Gartner has separately found that startups with early compliance certifications post 20% higher fundraising success— the flip side of which is that a growing company that can’t answer the security posture question quickly, and defensibly, keeps rounds open longer and closes at a worse valuation. Today most of that back-and-forth still runs over email chains and shared Drive folders. There is no audit trail for the founder, no scoped access for the investor, and no way for either side to know what actually got read.

“Every founder I know has assembled a ‘here’s our security stuff’ Google Drive folder at 11pm the night before an investor diligence call the next morning — policies, a SOC 2 letter, a screenshot of the compliance dashboard, whatever they can pull together,” said Yolonda Smith, founder of vCISO Lite. “It works exactly once, and it leaks. The investor forwards the folder, the deal moves, the founder never revokes anything, and the materials sit in three separate inboxes with no record of who saw what. The Investor Portal is the version of that moment I wish those founders could hand their investor instead: scoped to that engagement, revocable the day the deal moves, and timestamped so the founder can prove exactly what was shared.”

What’s in the release

The Investor Portal launches today with the capabilities a growing company needs to answer investor cyber diligence in a controlled way:

  • Scoped document library— the customer chooses which materials each investor sees. Security policies, DD interview responses, posture summaries, and uploaded artifacts (SOC 2 letter, pen test summary, insurance certificate) sit in a shared library, and per-investor access controls determine who can see what.
  • Passwordless investor sign-in— investors access the portal through a magic link plus a one-time code (TOTP), matching the authentication model used across the vCISO Lite platform. No accounts to provision, no passwords to reset, no shared credentials.
  • Time-bound sessions with instant revocation— investor sessions expire on a schedule the customer sets, and a single revoke action pulls magic links, invalidates active sessions, and locks the portal down. When a deal moves or falls through, access ends the same day.
  • Document view analytics— the customer sees which investor opened which document, when the session started, and how long the reader stayed on the page, with view-duration tracking for uploaded artifacts. Every view is written to the platform’s audit-trail service so the record is defensible later.
  • Real-time lifecycle enforcement— when the customer changes a permission or revokes an investor, the investor’s open session reflects the change immediately over a server-sent-events channel. There is no polling delay and no stale-permission window.
  • NDA acknowledgment tracking— if the customer requires an NDA, the investor acknowledges it before seeing any materials, and the acknowledgment is timestamped and bound to the investor record.
  • Activity timeline— a chronological feed of every material portal event: investor invited, NDA acknowledged, session started, document viewed, session revoked. The record a customer can hand a board, a QSA, or an audit committee later.

Why this belongs inside vCISO Lite

Investor cyber diligence is not an isolated workstream. The materials the investor asks for are the same materials the customer is already maintaining inside vCISO Lite to answer enterprise security questionnaires and pass a SOC 2 audit — the policies, the compliance status, the vendor risk register, the evidence library. Handling investor diligence in a separate tool means keeping two copies of the same posture up to date, and inevitably means the investor sees a version that’s already stale by the time it arrives.

The Investor Portal is a native surface of the vCISO Lite platform, so the materials the customer publishes to it are the same materials the platform is already tracking against the frameworks enterprise buyers care about — SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF, and other supported frameworks. When the customer’s posture changes inside vCISO Lite, the version the investor sees does too.

Availability

The Investor Portal is live today on the vCISO Lite Business tier and above, included in the plan at no additional cost. Existing customers on Business or Ultra will see the portal in their navigation. New customers can start the tier at vcisolite.com/pricing. Company background and the founder’s story are at vcisolite.com/about.


About vCISO Lite

vCISO Lite is a compliance and cyber risk platform for growing companies that don’t have a full-time CISO. The platform helps customers close compliance gaps (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF, and similar frameworks), generate defensible security policies, complete enterprise security questionnaires, manage vendor risk — and now, with the Investor Portal, hand security materials to investors, LPs, and lenders in a scoped, revocable, audited way. Founded by Yolonda Smith, a career cybersecurity leader with 20+ years building security programs from zero to IPO. vCISO Lite is headquartered in Atlanta, Georgia. Learn more at vcisolite.com or read the founding story.

Media Contact

Press & Analyst Inquiries
Yolonda Smith, Founder
press@vcisolite.com

###

Related reading

What Investors Look For in Security Diligence — the founder-side questions the Investor Portal is built to answer end-to-end.

Security Due Diligence in M&A — the both-sides framework Investor Portal aligns to.