Built around deliberate boundaries.
Diligence Gateway separates the client-facing environment from the investigator-facing environment, governs who sees what, moves work through controlled review and delivery, and leaves an auditable record of investigative activity.
Four structural principles
- 01Deliberate separation
Client and investigator environments are distinct by design.
- 02Controlled visibility
Access follows role and purpose.
- 03Auditable workflows
Investigative work leaves a record.
- 04Governed deliverable release
Internal work becomes client-facing only through controlled release.
Separation Is Architectural, Not Cosmetic.
ClientView and Dragonfly are deliberately different environments with different jobs — not one system with certain fields hidden from clients.
What the client environment holds
- Requesting organization and requestor context
- Subjects and documents the client submitted
- Client-safe status of the engagement
- Approved, client-safe deliverables
What the internal environment holds
- Internal findings and investigator notes
- Confidence assessments and analytical context
- Review state and working drafts
- Report-development material prior to release
Access Follows Role and Purpose.
Visibility in Diligence Gateway is governed — and the work itself is built to leave a record.
Governed Visibility
Team members work within the boundaries their role and engagement assignment call for. Client contacts operate in the client environment; investigators operate in the internal environment.
Bounded Investigator Access
Role-based access concepts govern who can work on which engagements, so investigative material stays with the teams authorized to handle it.
Controlled Release Paths
Information moves between environments through defined workflows — not ad-hoc exports — so what leaves the internal environment is a deliberate act.
Auditable Activity
Investigative work should leave a record. Review activity, workflow transitions, and deliverable release are part of an auditable trail of how a matter progressed.
Internal Work Becomes Client-Facing Only Through Controlled Release.
A report is not an attachment that leaves by email. It moves through a governed lifecycle before a client ever sees it.
Investigative Work
Findings, evidence, notes, and drafts remain in Dragonfly.
Review & Finalization
Deliverables pass through structured review before release.
Client-Safe Deliverable
The approved deliverable carries client-safe findings and risk band.
Publication
The client receives the deliverable through the controlled portal.
SOC 2 Type II Is on the Roadmap.
SOC 2 Type II certification is on the Diligence Gateway roadmap. This page does not claim certification status today — when certification is achieved, this section will say so explicitly.
Diligence Gateway does not currently claim SOC 2, ISO 27001, or any other certification.
Evaluate the Trust Model in Context.
Security posture matters most in the shape of your actual workflows. Request a walkthrough to examine separation, visibility, auditability, and deliverable governance against your requirements.
Direct engagement. Detailed security discussions are handled with your team.