IC memo cyber risk section built from available diligence evidence. No scanner deployment, bounded financial estimate included.
Valty ingests the artifacts available at deal close, including assessments, questionnaires, and posture reports, and returns a bounded EBITDA exposure estimate with method visible, ready for the IC memo cyber section and the 100-day plan.
A deal-speed exposure estimate, not a benchmark guess.
IC memo
Cyber risk section of the IC memo with bounded financial exposure, gap summary, and 100-day plan path, packaged at deal speed.
Available
Valty ingests the evidence available at deal time. No scanner deployment or company cooperation required to produce a first-pass exposure estimate.
Illustrative
All financial figures carry method, confidence range, and the specific assumption gaps that additional diligence could replace with sourced inputs.
The questions this page needs to answer before anyone treats a number as fact.
What is the cyber risk section of the IC memo, and how defensible is the financial figure?
IC memos require a bounded cyber-risk estimate with method visible, not a qualitative summary that the investment committee cannot price and a legal team cannot review.
Which findings matter at this business scale, and what does a 100-day fix plan look like?
Post-IC the operating partner needs a ranked action list tied to the exposure estimate, so the first 100 days move on value, not on assessment volume.
What evidence supports the exposure figure if a co-investor or LP asks during the IC?
IC-quality claims need a source log: which artifacts were reviewed, what their freshness was, and what assumptions the model used to fill gaps where evidence was unavailable.

Financial exposure at deal speed, built from evidence, not from benchmarks.
The EBITDA bridge is the financial anchor of the IC cyber section. It converts the evidence available at deal time into a bounded exposure estimate and surfaces assumption gaps that additional diligence could replace with sourced inputs in the 100-day plan.
- Exposure estimate: P10 / base / P90 with method and confidence
- Top three findings by EBITDA materiality, not by severity score
- Assumption gap log: what evidence is missing and what it costs the estimate
- 100-day action path: ranked by exposure delta and evidence required to prove closure
- IC export format: claim state, evidence source, and freshness per finding
Estimates are decision-support models, not actuarial opinions, FAIR-certified quantifications, or legal risk assessments. Evidence sufficiency is labeled separately from the explicit model inputs; V1 does not automatically widen or narrow PERT ranges when connector coverage changes.
Available artifacts in. IC-ready exposure estimate out.
The IC cyber workflow is built for deal timelines: ingest what exists, surface what is missing, bound the estimate, and produce an IC memo section that a legal and finance team can stand behind.
Available diligence artifacts enter the evidence pipeline
Pen test reports, vendor assessments, questionnaire responses, public breach filings, and cloud posture snapshots are normalized into typed evidence objects. No new scanner deployment needed.
Diligence artifact ingestionEvidence gaps are surfaced with assumption impact
Where evidence is missing, the workflow surfaces the assumption used to fill the gap and lowers publication confidence, so the IC can see exactly what additional diligence would replace an inferred input.
Assumption log with gap impactEBITDA exposure arrives with P10 / base / P90
The exposure estimate is bounded by revenue, EBITDA margin, and the evidence available at deal time. Method, confidence, and assumption drivers appear adjacent to the number.
FAIR-inspired model, labeled as decision-supportIC memo section is export-ready with claim state
The IC memo cyber section shows the exposure range, top three findings by materiality, assumption gap list, and the 100-day remediation path, with each claim labeled by evidence state.
Publication-gated IC exportIC cyber memo claims and their evidence requirements.
Each claim in the IC cyber section needs a source, a confidence label, and a freshness date. The matrix shows what can be stated at deal time versus what requires additional diligence to support.
Start the IC cyber section with available evidence, not a blank template.
Valty ingests what exists at deal time and returns a bounded exposure estimate with method and assumption gaps visible. The IC memo section and 100-day plan are workflow outputs, not manual builds.
Valty is in design-partner and early-access stage. All financial figures are illustrative decision-support estimates with method, confidence, and limitation stated adjacent to the claim. No fabricated customers, no published pricing.