February 2, 2026 · Diligence Rooms + Investor Portal

Diligence Rooms and Investor Portals — controlled sharing for cyber materials

For vCISO Lite customers who need to hand cyber materials to an investor, LP, or would-be acquirer. RFC-021 lands the engagement-scoped, tenant-isolated Diligence Room with ephemeral per-room storage, a separate investor / external-reader portal, and deletion certificates as first-class artifacts.

What changed

Diligence Rooms and Investor Portals landed inside vCISO Lite this week. This is the controlled-sharing feature for customers who need to hand cyber materials to an investor during a fundraise, an LP performing operational due diligence, or a would-be acquirer during a sale process. RFC-021 defines the engagement-scoped room as the unit of work.

Room lifecycle
A customer creates a room for a named external reader, grants scoped access, uploads the cyber materials being asked for, and closes the room when the review finishes. Every state transition is auditable and bound to a named engagement owner on the customer side.
Ephemeral storage
Every room gets its own GCS bucket for the life of the engagement. When the room closes, the bucket is deleted. No cross-room data persistence, no shared storage that could leak between simultaneous engagements.
External portal
The invited reader reaches the materials through a separate portal with its own scoped access. They don't see any other room the customer runs, and the customer's primary tenant isn't reachable from the external portal. Same passwordless authentication as the rest of the platform.
Deletion certificates
Closing a room emits a signed deletion certificate that the external reader (and the customer's counsel, if named) can verify against a published public key. The receipt that says the room is closed and the data is gone.

Why it matters

Growing companies constantly get asked to hand cyber materials to someone outside the company — a VC doing pre-investment diligence, an LP asking a fund’s portfolio company for a cyber posture summary, an acquirer’s deal team during an LOI process. Most of that material flow happens over email, in shared drives, or in a hastily-provisioned data room that no one closes cleanly at the end.

Diligence Rooms turn it into a first-class, engagement-scoped, closeable workflow inside vCISO Lite, alongside the compliance work the customer is already doing on the platform. The target company gets a receipt at close rather than a vague assurance that the data room has been shut down.

Related reading: The PE Buyer’s Playbook for Cyber Due Diligence covers the LOI-to-IC workflow Diligence Rooms power, and Cyber Cost of Deal: A Worked Example walks through the CCOD output a room produces.

Availability

Shipping this week to vCISO Lite customers on diligence-enabled plans. Rooms are created from the Diligence workspace inside the customer’s existing tenant.

No change to the customer’s primary tenant. Each room stands up its own GCS bucket on creation and tears it down on close; a room never shares storage with another room, and the external portal never has a route back into the customer’s tenant. Existing engagements that were being run informally over email or shared drives do not migrate automatically; start a new room when the next counterparty asks.

Known limitations

A room is scoped to a single engagement and a single external reader or deal team. Multi-reader orchestration from one room isn't in this cut.

A deletion certificate attests that the room's GCS bucket is gone. It doesn't recover copies a reader downloaded while the room was open; the room's audit log is where you see what was accessed and by whom.

This is iteration one of the diligence workflow. CCOD outputs produced inside a room are not yet exportable as a standalone artifact outside the room; they live with the engagement.