Diligence Gateway
SECURITY & TRUST

Built around deliberate boundaries.

Diligence Gateway separates the client-facing environment from the investigator-facing environment, governs who sees what, moves work through controlled review and delivery, and leaves an auditable record of investigative activity.

THE TRUST MODEL AT A GLANCE

Four structural principles

  • 01
    Deliberate separation

    Client and investigator environments are distinct by design.

  • 02
    Controlled visibility

    Access follows role and purpose.

  • 03
    Auditable workflows

    Investigative work leaves a record.

  • 04
    Governed deliverable release

    Internal work becomes client-facing only through controlled release.

ARCHITECTURAL SEPARATION

Separation Is Architectural, Not Cosmetic.

ClientView and Dragonfly are deliberately different environments with different jobs — not one system with certain fields hidden from clients.

CLIENTVIEW · CLIENT-FACING

What the client environment holds

  • Requesting organization and requestor context
  • Subjects and documents the client submitted
  • Client-safe status of the engagement
  • Approved, client-safe deliverables
DRAGONFLY · INVESTIGATOR-FACING

What the internal environment holds

  • Internal findings and investigator notes
  • Confidence assessments and analytical context
  • Review state and working drafts
  • Report-development material prior to release
ACCESS & RECORD

Access Follows Role and Purpose.

Visibility in Diligence Gateway is governed — and the work itself is built to leave a record.

Governed Visibility

Team members work within the boundaries their role and engagement assignment call for. Client contacts operate in the client environment; investigators operate in the internal environment.

Bounded Investigator Access

Role-based access concepts govern who can work on which engagements, so investigative material stays with the teams authorized to handle it.

Controlled Release Paths

Information moves between environments through defined workflows — not ad-hoc exports — so what leaves the internal environment is a deliberate act.

Auditable Activity

Investigative work should leave a record. Review activity, workflow transitions, and deliverable release are part of an auditable trail of how a matter progressed.

DELIVERABLE GOVERNANCE

Internal Work Becomes Client-Facing Only Through Controlled Release.

A report is not an attachment that leaves by email. It moves through a governed lifecycle before a client ever sees it.

01INTERNAL

Investigative Work

Findings, evidence, notes, and drafts remain in Dragonfly.

02GOVERNED

Review & Finalization

Deliverables pass through structured review before release.

03APPROVED

Client-Safe Deliverable

The approved deliverable carries client-safe findings and risk band.

04CLIENTVIEW

Publication

The client receives the deliverable through the controlled portal.

CERTIFICATION ROADMAP

SOC 2 Type II Is on the Roadmap.

SOC 2 Type II certification is on the Diligence Gateway roadmap. This page does not claim certification status today — when certification is achieved, this section will say so explicitly.

Diligence Gateway does not currently claim SOC 2, ISO 27001, or any other certification.

EVALUATE THE TRUST MODEL

Evaluate the Trust Model in Context.

Security posture matters most in the shape of your actual workflows. Request a walkthrough to examine separation, visibility, auditability, and deliverable governance against your requirements.

Direct engagement. Detailed security discussions are handled with your team.