VC Due Diligence
Security and technical due diligence for investors evaluating portfolio companies
What this engagement covers
The service
When you're writing a check, security posture matters. Our VC Due Diligence service gives investors and acquirers an independent, expert assessment of a target company's security risk. We evaluate the security of their product, infrastructure, code, and practices - and translate findings into clear risk ratings and deal-level recommendations your investment committee can act on.
What we test
Our due diligence assessment covers external attack surface and perimeter security, application security and architecture review, cloud infrastructure configuration and hardening, software supply chain and dependency risk, security policies and governance maturity, compliance posture (SOC 2, ISO 27001, HIPAA, PCI-DSS), incident history and response readiness, data handling and privacy practices, and engineering team security awareness.
Scoping & Assessment Depth
Black Box Assessment
Zero-KnowledgeSimulates an external adversary targeting VC Due Diligence with no internal credentials, source code, or architecture documentation. Assesses perimeter exposure, unauthenticated attack paths, and edge resilience.
Gray Box Assessment (Recommended)
CredentialedSimulates an authenticated user, tenant, or insider threat within VC Due Diligence. We evaluate role segregation, authorization boundaries, privilege escalation, and business logic flaws across user tiers.
White Box / Source-Assisted
Full-KnowledgeConducted with direct access to architecture schematics, configuration files, and API/code documentation. Eliminates blind spots and provides exhaustive coverage of security mechanisms governing VC Due Diligence.
Attack Surface & Vulnerability Vectors
Unpatched critical vulnerabilities in production
Rigorous testing and validation to uncover Unpatched critical vulnerabilities in production across your VC Due Diligence environment. We produce deterministic proof-of-concept exploits to verify exploitability without risking service stability.
Misconfigured cloud storage exposing sensitive data
Rigorous testing and validation to uncover Misconfigured cloud storage exposing sensitive data across your VC Due Diligence environment. We produce deterministic proof-of-concept exploits to verify exploitability without risking service stability.
No formal incident response process
Rigorous testing and validation to uncover No formal incident response process across your VC Due Diligence environment. We produce deterministic proof-of-concept exploits to verify exploitability without risking service stability.
Missing SOC 2 or ISO 27001 compliance
Rigorous testing and validation to uncover Missing SOC 2 or ISO 27001 compliance across your VC Due Diligence environment. We produce deterministic proof-of-concept exploits to verify exploitability without risking service stability.
Third-party dependencies with known CVEs
Rigorous testing and validation to uncover Third-party dependencies with known CVEs across your VC Due Diligence environment. We produce deterministic proof-of-concept exploits to verify exploitability without risking service stability.
Weak access controls and no MFA enforcement
Rigorous testing and validation to uncover Weak access controls and no MFA enforcement across your VC Due Diligence environment. We produce deterministic proof-of-concept exploits to verify exploitability without risking service stability.
How we run it
Engagements begin with a scoping call to understand deal timeline and primary risk areas. We conduct passive and active reconnaissance, request access to relevant documentation and architecture diagrams, and run targeted security testing against agreed-upon scope. All findings are triaged and rated by business impact - not just technical severity. We deliver a confidential report to the investor with an executive summary, risk ratings by category, a deal recommendation, and a remediation roadmap the target company can act on post-close.
Scoping call and deal timeline alignment
Rigorous technical execution, boundary verification, and manual exploitation testing targeting scoping call and deal timeline alignment across your vc due diligence deployment.
Passive reconnaissance and OSINT
Rigorous technical execution, boundary verification, and manual exploitation testing targeting passive reconnaissance and osint across your vc due diligence deployment.
External attack surface assessment
Rigorous technical execution, boundary verification, and manual exploitation testing targeting external attack surface assessment across your vc due diligence deployment.
Application and API security review
Rigorous technical execution, boundary verification, and manual exploitation testing targeting application and api security review across your vc due diligence deployment.
Cloud configuration and IAM audit
Rigorous technical execution, boundary verification, and manual exploitation testing targeting cloud configuration and iam audit across your vc due diligence deployment.
Dependency and supply chain risk analysis
Rigorous technical execution, boundary verification, and manual exploitation testing targeting dependency and supply chain risk analysis across your vc due diligence deployment.
Policy, governance, and compliance review
Rigorous technical execution, boundary verification, and manual exploitation testing targeting policy, governance, and compliance review across your vc due diligence deployment.
Risk-rated findings report with deal recommendation
Rigorous technical execution, boundary verification, and manual exploitation testing targeting risk-rated findings report with deal recommendation across your vc due diligence deployment.
What you receive
Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.
- Confidential executive summary with deal-level risk rating
- Security posture scorecard across 8 categories
- Attack surface and vulnerability findings report
- Cloud and infrastructure configuration review
- Compliance gap analysis against relevant frameworks
- Software supply chain and dependency risk assessment
- Remediation roadmap for post-close integration
- Optional: follow-up call with investment committee
What we usually find
The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.
Who this is for
Auditor-Ready Compliance Crosswalk
| Framework | Control Section | Testing Evidence & Report Deliverable |
|---|---|---|
| SOC 2 Type II | CC4.1, CC7.1, CC7.2 | Technical testing evidence validating system boundaries, access restrictions, and vulnerability identification controls. |
| ISO/IEC 27001:2022 | Control A.8.8 & A.8.20 | Management of technical vulnerabilities and network security verification through independent technical assessments. |
| HIPAA Security Rule | 45 CFR § 164.308(a)(8) | Formal technical evaluation verifying the integrity of ePHI safeguards, network segmentation, and privileged access safeguards. |
| PCI DSS v4.0 | Requirement 11.4 & 11.4.3 | Adversary-driven external and internal penetration testing with application-layer validation and vulnerability remediation verification. |
| NIST Cybersecurity Framework | PR.AC, DE.CM, RS.AN | Technical testing verifying access controls, anomaly detection efficacy, and incident response mitigation capabilities. |
| GDPR Article 32 | Art. 32(1)(d) | Documented evidence of regular testing, assessing, and evaluating the effectiveness of technical measures protecting personal data. |
Findings are mapped to SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST CSF, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.
Frequently Asked Questions
Direct answers on scoping, methodology, compliance validation, and deliverables.
Our VC Due Diligence service combines deep manual testing with automated verification. We cover: Confidential executive summary with deal-level risk rating, Security posture scorecard across 8 categories, Attack surface and vulnerability findings report, Cloud and infrastructure configuration review, Compliance gap analysis against relevant frameworks. Every engagement includes reproducible proof-of-concept exploits, developer-ready remediation guidance, and a free retest.
Yes. Findings are directly mapped to SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST CSF, GDPR control requirements. The resulting report is auditor-ready and formatted for immediate submission to SOC 2 CPAs, PCI QSAs, and enterprise vendor risk assessment teams.
Yes. Every Lorikeet Security engagement includes free retesting within 30 to 60 days to validate that your remediation patches successfully resolve the identified vulnerabilities before your final report is issued.
Typical active testing turnaround is 1–2 weeks, with critical findings reported immediately via your Talon portal so your engineering team can begin remediation without waiting for the final PDF.
Pricing starts from From $8,500. We scope the engagement in one call based on your environment's surface area, user roles, and complexity, providing a transparent, fixed-price quote with no hidden change orders.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.