If you're an investor or an operating partner
Our diligence is written for an investment committee, not an engineering team. You get what should change the price, what should become a condition of closing, what can wait until year two, and a remediation cost estimate you can actually underwrite.
Across a portfolio, the same control failures repeat company to company, which is annoying as a risk and useful as a program. One set of standards, a security leader assigned per company, and reporting in one format instead of twelve.
We also treat this as value creation rather than insurance. Security certifications increasingly unblock enterprise sales, and AI governance credentials are starting to work the same way. Getting a company defensible before diligence is cheaper than explaining it during.