For Immediate Release
vCISO Lite Launches Preflight — Cyber Diligence Built for the Shape of a Venture Deal, With 20-Minute Red-Flag Scans, Term-Sheet Covenants Auto-Drafted From the Findings, and Portfolio-Wide LP-Letter Reporting
A cyber-diligence surface built for venture capital: pre-term-sheet red-flag scans that fit inside the partner meeting window, a covenant library reviewed quarterly with a tier-1 M&A firm, and a one-page LP-letter cyber section that regenerates every quarter — all on one subscription. Design-partner cohort open now.
ATLANTA — July 14, 2026 — vCISO Lite today launched Preflight, a cyber-diligence surface built for the shape of a venture deal. Preflight pairs a 20-minute pre-investment red-flag scan on any target with term-sheet covenants auto-drafted from the findings and a portfolio-wide LP-letter section that regenerates every quarter — on one subscription, for VCs who need cyber diligence at the pace of a Series A close, not a three-week PE engagement. A design-partner cohort opens today.
The launch answers a mismatch venture-fund associates have absorbed for years: every existing cyber-diligence workflow was built for private equity. FTI Consulting’s 2026 M&A and Cybersecurityreport found that 42% of deals encountering a cyber incident during or after close lose value. Westbourne Research (2025) put 21% of M&A deals as delayed, repriced, or abandoned over cybersecurity findings surfaced in diligence. Marsh & McLennan (2023) reported that 70% of institutional investors factor cybersecurity maturity into valuation decisions. The signal has been priced-in on every deal since the Verizon acquisition of Yahoo cut $350 million on undisclosed breaches — but the shape of the diligence a $50M PE check can afford does not fit a $5M Series A term sheet closing on Friday.
“Every VC associate I’ve talked to is already doing this diligence — badly, in a spreadsheet, from Google, on the morning of the partner meeting,” said Yolonda Smith, founder of vCISO Lite. “The PE side gets three weeks and a dedicated firm. The venture side gets an associate and a Google search bar, and the security line in the memo becomes a hedged one-liner because nobody wanted to say ‘we don’t know.’ Preflight ends the guessing — a real scan inside the partner meeting window, and every red flag mapped to a covenant your counsel can drop straight into the term sheet. Findings without covenants are findings. Findings in the term sheet are enforceable protection.”
What’s in the release
Preflight enters public beta today on the vCISO Lite platform, opening a design-partner cohort for venture funds who want to shape the covenant library their firm will use in real deals. In the beta release, design partners can run the following on any active or pipeline deal:
- The 20-minute red-flag scan. Fire on any target, external OSINT only. Dark-web credential exposure, DMARC posture, attack surface, breach history, and peer-percentile comparison against sector- and stage-matched companies. Delivered inside the partner meeting window, with a YELLOW / RED / CLEAR routing verdict and a recommended action.
- Term-sheet covenants, auto-drafted from the findings. Each red flag maps to a proposed covenant clause your counsel drops straight into the term sheet or SPA — soft, hard, and closing-condition variants, with location guidance built in. The covenant library is reviewed on a quarterly refresh cadence with a tier-1 M&A firm.
- Portfolio-wide LP-letter cyber section.Every scan you run and every covenant you land flows into a portfolio view; each quarter, a one-page cyber section — portfolio expected annual loss (FAIR-based, probability-weighted), per-portco peer-percentile movement, covenants landed — is generated for your quarterly LP letter.
- Shared substrate with Quantitative Cyber Diligence (QCD). Preflight is a sibling to QCD, the PE-side five-pillar Cyber-Cost-of-Deal methodology already live on the platform. Preflight and QCD share finding taxonomy, scan engine, and portfolio-baseline math — so a target Preflight-scanned at Series A can be re-baselined into a full CCOD at Series C without starting over.
- Design-partner terms. Design-partner funds receive free access through GA, direct input on the covenant library their firm will use in real deals, and a lifetime discount on their first subscription tier when public pricing lands.
The three moments Preflight is built for
Cyber diligence shows up in a venture deal in exactly three places — pre-term-sheet, at close, and every quarter after — and Preflight ends each one with its own tool on one subscription:
- Pre-term-sheet, the scan.When the partner meeting is Monday and someone needs a defensible answer on the target’s cyber posture by Friday, the associate stops running BuiltWith against the CEO’s email and starts sending real findings + peer percentile into the memo. What investors are already looking for is walked through in “What Investors Look For in Security Diligence.”
- At close, the covenants.Board seat gives you a voice, not recourse; covenants and reps & warranties are the only thing that gives the fund real recourse if a portco misrepresents cyber posture pre-close. Preflight’s covenant library is the compressed venture-shaped counterpart to the PE 72-hour engagement walked through in “The Private Equity Buyer’s Playbook for Cyber Due Diligence: From LOI to IC in 72 Hours.”
- Every quarter, the LP letter.Institutional LPs — CalPERS, university endowments, corporate pension funds — are increasingly requiring GP attestations on portfolio cyber posture. Preflight generates a one-page cyber section for the quarterly LP letter from real portfolio-scan data, on the same Year-0 baseline logic detailed in “The Year-Zero Cyber Baseline.”
What grounds the methodology
Preflight sits on the same substrate as vCISO Lite’s existing M&A cyber-diligence product, adapted to the timeline, budget, and deliverable shape of a venture deal:
- Quantitative Cyber Diligence (QCD).The five-pillar, dollar-denominated M&A cyber-cost methodology behind the PE product, published as an executive brief and academic paper at vcisolite.com/briefs-and-specs and treated at book length in Someone Else’s Debt (Smith, 2026). Preflight’s finding taxonomy and portfolio math derive from the same pillars; a mid-market worked example is in “Inside a Cyber Cost of Deal: A Worked Example for Investment Committee.”
- Factor Analysis of Information Risk (FAIR).The Open Group’s open standard for loss-event frequency × loss-magnitude decomposition. Preflight’s portfolio-wide expected annual loss on the LP-letter section uses FAIR-shaped math over observable inputs.
- SEC cybersecurity disclosure rule(Item 106 of Regulation S-K; Item 1.05 of Form 8-K) — effective December 2023. Makes cyber material to public-company reporting, which reaches every venture portco pointed at a public exit. The diligence you skip at Series A becomes exit friction at IPO underwriting.
- Covenant library, review cadence.The covenant-clause library is being reviewed on a quarterly refresh cadence with a tier-1 M&A firm; every proposed clause ships as “DRAFT / PROPOSED” for the fund’s counsel to red-line before signature.
For funds that want their Preflight scans and portfolio reporting run end-to-end by AI agents — with cryptographic proof of every action the agent takes — vCISO Lite’s Trustworthy Autonomy™ layer covers M&A cyber diligence in its public-beta program alongside TPRM, audit preparation, and KRI monitoring.
Availability
Preflight is in public beta today at vcisolite.com/preflight, with a design-partner cohort open for venture funds who want to shape the covenant library and product roadmap ahead of general availability. Design partners receive free access through GA, direct input on the covenant library, and a lifetime discount on their fund’s first subscription tier when public pricing is published at GA. The VC-audience deep dive on the “why now” and the “what changes” sits at vcisolite.com/industries/venture-capital, and companion editorial coverage lives in the M&A Security Diligence series and the Someone Else’s Breach series.
About vCISO Lite
vCISO Lite is a compliance and cyber risk platform for growing companies that don’t have a full-time CISO. The platform helps customers close compliance gaps across every framework mapped in the Secure Controls Framework (SOC 2, ISO 27001, PCI DSS, HIPAA, DORA, NYDFS Part 500, GDPR, NIST 800-53 and 800-171, FedRAMP, CMMC, and more), quantify cyber risk in the language their board and deal teams already speak, and — with Preflight and Quantitative Cyber Diligence — run both sides of the cyber-diligence table: venture-shaped covenants and 20-minute scans for VCs, dollar-denominated Cyber Cost of Deal for PE and corporate M&A. vCISO Lite is headquartered in Atlanta, Georgia. Learn more at vcisolite.com, read related product releases in the changelog, or explore the Trustworthy Autonomy editorial series.
Media Contact
Press & Analyst Inquiries
Yolonda Smith, Founder
press@vcisolite.com
###