March 30, 2026 · Diligence Rooms · Signed Artifacts

Diligence Rooms — Ed25519 deletion certificates, isolated viewer, watermarking

The Diligence Room becomes a cryptographically auditable record. Ed25519 JWS deletion certificates, a Guacamole-based isolated viewer for customer-uploaded documents, and two-stage watermarking (visible + steganographic) that identifies the external reader if a page turns up somewhere it shouldn't.

What changed

Diligence Rooms shipped a hardening pass this week that turns the room from an engagement-scoped workspace into a cryptographically auditable record: every artifact the room produces is now signed, every deletion is certificated, and the isolated viewer that lets external readers see the customer’s uploaded documents runs through a two-stage watermarking pipeline.

Deletion certificates
When a room closes, the platform issues a JSON Web Signature (RFC 7515 compact serialization) using an Ed25519 key that names the room, the engagement, the close timestamp, the artifacts purged, and the parties who can verify it. Replaces the earlier HMAC-SHA256 model.
Certificate download
The vCISO Lite customer and every named external reader on a closed engagement can download the deletion certificate at any point after close. It is a first-class artifact of the engagement, not a transient log entry.
Isolated viewer
Customer-uploaded documents render inside a Guacamole-based isolated viewer that runs the render workload on the platform rather than shipping the document to the external reader's browser. The document never leaves the room's ephemeral GCS bucket. HTTP-tunneled for browser compatibility.
Two-stage watermarking
Every page rendered through the viewer carries a per-reader watermark applied in two stages: at render time (visible watermark) and at pixel level (steganographic watermark). If a page is screenshotted and surfaces somewhere it should not, the watermark identifies which reader in which room saw it.

Why it matters

When a growing company hands sensitive cyber materials to an investor, an LP, or an acquirer’s deal team, the counterparty wants to read the material and the customer wants confidence that the material won’t leak elsewhere. The signed-artifact, isolated-viewer, and watermark stack is what makes the customer comfortable enough to upload the material at all, and what gives the external reader a receipt they can defend to their own auditors or LPs later. Together with the February DD Room framework, this is the first version of the Diligence Room that’s actually enterprise-defensible.

The signed-log discipline these artifacts build on is covered in Autonomy You Can Audit: Signed Action Logs. The LOI-to-IC workflow the signed artifacts flow through is covered in The PE Buyer’s Playbook for Cyber Due Diligence.

Availability

Shipping today to every Diligence Rooms engagement. Any room closed on or after today ships with the Ed25519 certificate.

The isolated viewer and the two-stage watermark apply to every document opened by a named external reader, starting now. Customers and external readers do not need to re-provision keys or install anything; the public key used to verify deletion certificates is published and the viewer runs in-browser over the existing room URL.

Known limitations

The steganographic watermark survives screen-capture tools and image compression. A photograph of a monitor, or an OCR-reconstructed excerpt, can bypass it.

Certificate verification is done with any standard JWS library against the published Ed25519 public key. A one-click in-product verifier is not shipped yet.

Rooms closed before this release keep their original HMAC-SHA256 certificates. The new Ed25519 model applies to rooms closed on or after today.