A self-serve diligence checklist, five tracks (Legal · Financial · Technical · Security · Compliance) each with an honest LIVE / PARTIAL / TARGET label. Every green check links to the document or proof in this room.
Legal
- Delaware C-CorpEntity03.5 C-Corp Conversion Note · post-conversion Delaware C-Corp incorporation (conversion complete) → 03.5
- Bylaws + Stockholders Agreement templates → 08.1, 08.2
- IP Assignment + Option Plan templates → 08.3, 08.4
- 83(b) elections within 30 days of share issuance → founder critical-path
- ToS, Privacy, DPA, MSA, BAA templates → 08 Legal
- Diligence Notice + sub-processor flow-down → 08.11, 08.12
Financial
Technical
Security
- Security posture overview → 06.1
- STRIDEThreat model framework06.9 Threat Model (STRIDE) · spoofing / tampering / repudiation / info-disclosure / DoS / elevation threat model → 06.9
- Incident response runbook → 06.10
- Sub-processor registry → 06.11
- SOC 2 program in progress with Drata; not SOC 2 certified, and certification claims require the issued report
- SOC 2 Type II target Q3 2027
- External pentest scheduled Q4 2026
Compliance
- HIPAA posture memo (designed for HIPAA-governed workflowsHIPAA posture06.2 HIPAA Posture Memo · canonical procurement-safe phrasing (not 'compliant' / not 'certified') · BAA path subject to counsel and executionBAA posture06.4 Vendor BAA Matrix · customer BAA template at 08.9) → 06.2
- Cloud vendor BAA posture → 06.4
- Investor-room AI: Google Cloud Vertex AI, Gemini 2.5 Flash, grounded in the hash-pinned generation 8 canon
- Sub-processor BAAs (Persona, Checkr, WorkOS)
- AI Doctrine + governance memo → 04.4
- Data flow diagram → 06.6
- NCQA CVO trajectory (alignment in progress, not filed) → 06.8
- SOC 2 plan → 06.3
Procurement-safe phrasing reminder
Say: HIPAA-aligned, BAA available. Never say: HIPAA compliant, HIPAA certified, SOC 2 certified, or NCQA-certified, until each is true and granted. The customer carries its own accreditation; Rōvn supplies the receipt-backed verification evidence.