Skip to main content
Home/Services/VC Due Diligence
Security Testing

VC Due Diligence

Security and technical due diligence for investors evaluating portfolio companies

SOC 2 ISO 27001 HIPAA PCI-DSS NIST CSF GDPR
engagement log VC Due Diligence testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingUnpatched critical vulnerabilities in productioncritical
day 03findingMisconfigured cloud storage exposing sensitive datahigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
1–2 weeks
typical duration
From $8,500
fixed scope, from
8
deliverables
8
methodology stages
Scope

What this engagement covers

The service

When you're writing a check, security posture matters. Our VC Due Diligence service gives investors and acquirers an independent, expert assessment of a target company's security risk. We evaluate the security of their product, infrastructure, code, and practices - and translate findings into clear risk ratings and deal-level recommendations your investment committee can act on.

What we test

Our due diligence assessment covers external attack surface and perimeter security, application security and architecture review, cloud infrastructure configuration and hardening, software supply chain and dependency risk, security policies and governance maturity, compliance posture (SOC 2, ISO 27001, HIPAA, PCI-DSS), incident history and response readiness, data handling and privacy practices, and engineering team security awareness.

Method

How we run it

Engagements begin with a scoping call to understand deal timeline and primary risk areas. We conduct passive and active reconnaissance, request access to relevant documentation and architecture diagrams, and run targeted security testing against agreed-upon scope. All findings are triaged and rated by business impact - not just technical severity. We deliver a confidential report to the investor with an executive summary, risk ratings by category, a deal recommendation, and a remediation roadmap the target company can act on post-close.

01

Scoping call and deal timeline alignment

02

Passive reconnaissance and OSINT

03

External attack surface assessment

04

Application and API security review

05

Cloud configuration and IAM audit

06

Dependency and supply chain risk analysis

07

Policy, governance, and compliance review

08

Risk-rated findings report with deal recommendation

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Confidential executive summary with deal-level risk rating
  • Security posture scorecard across 8 categories
  • Attack surface and vulnerability findings report
  • Cloud and infrastructure configuration review
  • Compliance gap analysis against relevant frameworks
  • Software supply chain and dependency risk assessment
  • Remediation roadmap for post-close integration
  • Optional: follow-up call with investment committee
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Unpatched critical vulnerabilities in production Misconfigured cloud storage exposing sensitive data No formal incident response process Missing SOC 2 or ISO 27001 compliance Third-party dependencies with known CVEs Weak access controls and no MFA enforcement No security testing history or pentest evidence Customer data handling inconsistent with stated policy
Fit

Who this is for

Venture capital firms evaluating Series A–C investments
Private equity firms conducting technical DD on acquisitions
Strategic acquirers assessing M&A targets
Growth equity investors with concentrated portfolio risk
LP risk committees requiring security validation
Founders preparing for investor security questionnaires
Standards this supports

Findings are mapped to SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST CSF, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!