TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one partner Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Home  /  Who We Serve  /  Investors & Portfolio Companies

A portfolio risk and value creation partner, not another security vendor.

Somebody described us that way recently and it stuck, because it's the honest version of what we do. We work the same four moments your operating partners already work: diligence, the first hundred days, the hold, and the run-up to exit.

The lifecycle

Four moments, and we'd like to own all of them.

Most security firms show up once, hand over a report, and leave. That's a poor fit for how a fund actually holds a company, so we structured the whole practice around the timeline you already run.

BEFORE CLOSE

Cyber and AI diligence

Security liabilities, compliance gaps, AI exposure, data handling, technical debt, incident history, vendor risk. Written for an investment committee, delivered on your timeline, with a remediation cost estimate you can underwrite rather than a list of findings you can't price.

0–100 DAYS

Security transformation

The only window where a management team will genuinely accept change. Governance, policy, MFA and identity, endpoint, backup, monitoring, a compliance roadmap, and AI governance stood up before the company gets busy again.

THE HOLD

Managed security and fractional CISO

Retained monthly, per company. Somebody named who knows the environment, attends the board meeting, answers the security questionnaires that are holding up enterprise deals, and calls you before you hear it from somewhere else.

BEFORE EXIT

Exit readiness

We run the company through the diligence a buyer will run, twelve months early, so the findings that would have become price adjustments get fixed while they're still cheap. This is the piece nobody thinks about until the data room is already open.

Why the framing matters

Security spend justified the way you actually justify spend.

Protection is a cost line, and a cost line is an argument you have to win again every year. We'd rather be measured the way your operating partners are measured. Here is where the money actually moves.

Line
What we do
Where it shows up
Revenue
Get a company through enterprise security review and the certifications its buyers demand, and answer the questionnaires for the sales team.
Deals unstick in procurement. Usually the fastest return in the engagement, and the one a CEO notices first.
Multiple
Run the company clean through diligence so a buyer's technical review turns up nothing that becomes a negotiating lever.
Exit price. Kroll found 26% of firms saw a reduced valuation or exit price tied to cyber findings.
EBITDA
Prevent the incident. Then cut the duplicate tooling you're paying for three times across three companies.
Avoided cost. Average cyber impact during the hold period runs around $2.1 million.
Your time
One security leader per company, one control baseline, one reporting format across the fund.
Operating partner hours, and a board packet somebody else assembles.

Kroll surveyed 325 portfolio leaders across six countries in December 2025. Every figure on this site carries its source, because there's a great deal of unsourced noise in our industry and we'd rather you check us.

The wedge

Every company you back is an AI company now, whether or not that was the thesis.

Plenty of firms will sell a portfolio managed IT and call it cyber. The thing that's actually changed underneath your companies in the last eighteen months is AI, and almost nobody is governing it. IBM's 2026 research put shadow AI in 43% of security incidents, roughly double the year before, with more than two thirds of organizations having nothing in place to limit unauthorized AI use.

IN YOUR OWN ROOM

The calls you're already on

Note-takers sit in board meetings, LP updates and diligence calls, keeping recordings nobody has reviewed. In 2024 a VC firm's assistant emailed a founder the transcript of what the partners said after he dropped off, and he walked away from the deal. Boards are getting formal legal advice on this now.

IN THE PORTFOLIO

What they're shipping

Companies building AI features inherit an attack surface that didn't exist when you invested. Prompt injection, agents holding credentials nobody can audit, model supply chain, MCP servers wired into production. We red team it and build the governance an enterprise buyer will ask to see.

AT EXIT

The new diligence question

Buyers have worked out that a vendor's SOC 2 says nothing about what downstream model providers do with data. Auditors are already asking for AI data-flow evidence, and an ISO 42001-aligned AI program is turning into a credential that unblocks enterprise sales rather than a compliance chore.

Shadow AI discoveryAI usage & governance policyAI risk assessment AI data protection reviewAI vendor risk reviewAI runtime defense Prompt injection mitigationAgentic AI governanceAI agent identity MCP server securityAI red teamingModel scanning & provenance AI-BOMCopilot & Gemini tenant remediationAI security training AI incident responseNIST AI RMF & ISO/IEC 42001 Executive AI risk dashboardQuarterly AI risk review
Pricing

Published, because you shouldn't need three calls to find out what something costs.

Diligence is quoted per deal against your timeline. Everything after close is a monthly retainer per company, priced on size and risk, and it improves as more of the portfolio comes on.

Portfolio AI & Cyber Risk Assessment
The way most funds start. One company, or five at once.
$2,500–$5,000per companyBoard-ready report
  • AI tools actually in use, and shadow AI
  • Sensitive data exposure and AI vendor risk
  • Identity, MFA, endpoint, backup and recovery
  • Compliance exposure and cyber insurance gaps
  • Executive risk score and 90-day remediation plan
Most common
Portfolio AI + Cyber Secure
The managed program for a company through the hold period.
$3,000–$5,000/ month, per companyEverything in the assessment, run continuously
  • AI governance and employee AI policy
  • AI security and awareness training
  • Security monitoring and SOC coverage
  • Vulnerability management
  • Compliance support and vendor risk
  • Incident response planning
  • Quarterly executive review
Portfolio vCISO
For the larger or higher-risk companies, and anything heading toward a sale.
$5,000–$10,000/ month, per companyA named security executive
  • Fractional CISO and security strategy
  • Board reporting and compliance leadership
  • Security architecture, SOC and SIEM oversight
  • Penetration testing and incident response
  • Cyber insurance renewal and control validation
  • AI governance and M&A security assessments
Where funds usually begin

The $25,000 portfolio assessment

Five portfolio companies, assessed together. Each one gets a cyber and AI risk assessment, an executive scorecard and a 90-day roadmap. You get a heatmap across all five, which is usually the first time anyone has seen the portfolio's risk side by side. Companies that need ongoing work convert to a monthly retainer. The ones that don't, don't.

Retainers run month to month after an initial term. A security firm that needs a long lock-in to keep you is telling you something. ACA's 2026 benchmarking of 300+ portfolio companies found that those under structured monitoring for a year or more were twice as likely to reach low risk, which is the only honest argument for retaining anybody rather than buying a one-off project.

The part that changed

In March, the exposure reached the sponsor.

A federal court allowed negligence and aiding-and-abetting claims to proceed against a private equity firm over a portfolio company's breach. The reasoning was that the sponsor exercised control over that company's cybersecurity decisions, so agency applied, and some of what was at issue predated the closing.

Board seats and operating partners are the model. It now appears they're also how liability travels, and we don't think most funds have worked out what to do about that yet.

A compliance platform, or an IT provider
TriVigil
Tracks whether controls are documented
Verifies whether controls actually work
A cost line you defend at every renewal
Measured on revenue unblocked and exit price protected
Managed IT with security attached
AI and cyber readiness, which is what actually changed
Shows up once, hands over a report
Diligence, the first 100 days, the hold, and exit
Every company buys its own tools separately
One baseline, one reporting format, one invoice

Start with the five that worry you most.

Assess five companies together, see the heatmap, and decide from there which ones need somebody retained. If the answer is none of them, that's a good outcome and you'll have the report either way.