February 2, 2026 · Investor Portal · Reader Experience

Investor Portal — the reader experience for investor cyber diligence

Where the Diligence Room is the container, the Investor Portal is what the investor actually sees. Scoped external-reader access, passwordless authentication, document view analytics, letterhead on generated policies, time-bound access. For every founder assembling a Google Drive folder at midnight the night before a term-sheet call.

What changed

The Investor Portal lands as the reader-side experience for vCISO Lite customers who need to give investors, LPs, or lenders scoped access to security posture, policy library, and due-diligence interview content. Where the Diligence Room is the container the customer builds, the Investor Portal is what the investor actually sees when they open the link.

Scope
The customer picks which artifacts each investor can see. An investor invited to review one section cannot browse into another; scoping is a first-class property, not a URL-obscurity trick.
Sign-in
Passwordless with magic link + TOTP, the same model as the rest of the platform. No shared passwords, no expired sign-in links, no "can you resend that Google Drive link" support thread.
Analytics
The customer sees which investor opened which document, when, and for how long, so they know whether their prospective backer has actually read the material before the next follow-up call.
Letterhead
Platform-generated policies render with the customer's letterhead when they land in the Investor Portal, without the founder having to do a Google Docs template pass at 11pm the night before.
Expiry
Investor sessions expire on a schedule the customer sets. Renewal is one click; unauthorized access after expiration is impossible.

Why it matters

Every founder raising a round hits the same 48 hours: the term sheet arrives, the diligence packet gets requested, and now someone is assembling a Google Drive folder of policies, questionnaires, prior audit reports, and posture summaries at midnight. It works, badly, until it doesn’t. The Investor Portal turns that scramble into a controlled, scoped, revocable, audited reader experience the investor can trust and the customer can defend.

Context for both sides of the table: What Investors Look For in Security Diligence is the founder-side workflow the Investor Portal is built for, and Security Due Diligence in M&A is the both-sides framing the portal aligns to.

Availability

Shipping today to every Diligence Room customer. No migration needed; existing scoped artifacts become portal-visible as soon as an investor is invited.

Investors sign in with magic link + TOTP on first visit and session expiry runs on the schedule the customer sets. Renewal is one click, revocation is immediate, and every open is written to the audit trail the customer can hand to counsel.

Known limitations

This is v1. The portal is read-only today — investors open and read; questions, redlines, and replies still happen outside the portal.

The Investor Portal is the reader side of a Diligence Room. A customer must have a Diligence Room with scoped artifacts in place before an investor can be invited.

Document analytics report opens and dwell time, not attention or comprehension. A document left open in a backgrounded tab still accrues time.