What changed
Diligence Rooms and Investor Portals landed inside vCISO Lite this week. This is the controlled-sharing feature for customers who need to hand cyber materials to an investor during a fundraise, an LP performing operational due diligence, or a would-be acquirer during a sale process. RFC-021 defines the engagement-scoped room as the unit of work.
Why it matters
Growing companies constantly get asked to hand cyber materials to someone outside the company — a VC doing pre-investment diligence, an LP asking a fund’s portfolio company for a cyber posture summary, an acquirer’s deal team during an LOI process. Most of that material flow happens over email, in shared drives, or in a hastily-provisioned data room that no one closes cleanly at the end.
Diligence Rooms turn it into a first-class, engagement-scoped, closeable workflow inside vCISO Lite, alongside the compliance work the customer is already doing on the platform. The target company gets a receipt at close rather than a vague assurance that the data room has been shut down.
Related reading: The PE Buyer’s Playbook for Cyber Due Diligence covers the LOI-to-IC workflow Diligence Rooms power, and Cyber Cost of Deal: A Worked Example walks through the CCOD output a room produces.
Availability
Shipping this week to vCISO Lite customers on diligence-enabled plans. Rooms are created from the Diligence workspace inside the customer’s existing tenant.
No change to the customer’s primary tenant. Each room stands up its own GCS bucket on creation and tears it down on close; a room never shares storage with another room, and the external portal never has a route back into the customer’s tenant. Existing engagements that were being run informally over email or shared drives do not migrate automatically; start a new room when the next counterparty asks.
Known limitations
A room is scoped to a single engagement and a single external reader or deal team. Multi-reader orchestration from one room isn't in this cut.
A deletion certificate attests that the room's GCS bucket is gone. It doesn't recover copies a reader downloaded while the room was open; the room's audit log is where you see what was accessed and by whom.
This is iteration one of the diligence workflow. CCOD outputs produced inside a room are not yet exportable as a standalone artifact outside the room; they live with the engagement.