QA Review
An adversarial claim-hygiene and consistency pass across the eleven authored data-room docs, scored against the shared evidence pack.
Confidential · June 2026. This review tests every load-bearing claim against the verified evidence pack. All dollar figures discussed are illustrative placeholders unless sourced. Findings are tagged CRITICAL / HIGH / MEDIUM / LOW.
What was checked
- Over-claim sweep — every mention of the
$121k / 22% shadowfigure, every use of "live," "real," "measured," "connected," "customer result," and any phrasing that implies the platform is further along than built-and-tested-on-synthetic-data. - The Kelly rule — that Kelly / MCG is consistently framed as the first channel / de-risked distribution, never the pitch target or destination.
- Independence framing — that govrn is never self-certified, that build/run is structurally walled from attest, and that this holds inside one company.
- Cross-doc number consistency — market figures (Gartner $492M→$1B+, 75% by 2030, EY 16%→48%, Deloitte 38%, EU AI Act 7%, BCG 40%+ / ISO 42001), team roster, framework list (the six crosswalks).
- Diligence landmines — any sourced claim an investor's analyst would pull the thread on (regulatory citations, the ISO/IEC 17021-1 cooling-off claim, Nexthink $3B, "Meridian Software" PRNG).
- Missing-but-expected content — what a sharp investor would expect in a data room and not find.
Findings
CRITICAL
None. No document calls the synthetic $121k a customer/live result, none claims "measured" before connection, and none claims the connectors have run live. Across all eleven docs the staging discipline is consistently held — modeled until connected, measured only after, and the "Meridian Software is a PRNG seed" caveat is repeated wherever the figure appears (10-aperture, 13-risks, one-pager, 18-buyer). This is the single strongest quality signal in the set.
HIGH
- H1 — ISO/IEC 17021-1 "two-year cooling-off period" is a specific, checkable legal claim (12-trust-firewall). The doc states the principle is "drawn from ISO/IEC 17021-1 … a meaningful cooling-off period (commonly framed as two years) separates anyone from attesting on work they advised." ISO/IEC 17021-1's consulting-independence clause (5.2.5 area) is real, but the specific "two years" number is more precisely associated with ISO/IEC 17021-1's management-system-certification rules and is easy to misattribute. An investor's counsel will check this. Recommend hedging to "commonly framed as roughly two years in conformity-assessment practice" (already partially hedged with "commonly framed") OR dropping the specific number. The conceptual claim is sound; the precise citation is the exposure.
- H2 — Regulatory-landscape doc (17) introduces two regimes (HUD/Fair Housing tenant screening, SR 11-7 model risk) that appear NOWHERE else in the corpus and are NOT in the evidence pack. SR 11-7 and HUD tenant-screening are legitimate and strengthen the thesis, but they are net-new sourced regulatory claims invented at the doc level. SR 11-7 is a Fed/OCC supervisory guidance on model risk management; extending it to "AI" is a defensible-but-arguable framing an investor's risk analyst may push on. Flag: these need a one-line source basis, and the leap from "model risk" to "AI governance" should be stated, not assumed. Currently presented as settled fact.
- H3 — "structurally separate arm" / "its own reporting line" overstates current org reality (12-trust-firewall, 10-aperture, multiple). The evidence pack says the attest arm "stays structurally separate from build/run" as a design principle and a feature that raises value — but govrn is a single pre-entity company with a five-person team where the same people plausibly touch both build and attest. Doc 12 asserts "the attest arm carries its own reporting line and its own judgment." That is aspirational org design stated in present tense. An investor doing reference/team diligence will ask "who, specifically, is walled off from whom today?" and the honest answer is "no one yet — it's five people." Recommend present-tense → intended-structure framing ("govrn is built around…" / "as the team grows, the attest function carries…"). Doc 12's own disclosure blockquote says "describes govrn's intended operating structure," which is good — but the body text repeatedly drops into present-tense assertion that contradicts the blockquote.
MEDIUM
- M1 — Nexthink "$3B" is stated as fact without a hedge (16-nexthink). "Nexthink is a roughly $3B digital-employee-experience (DEX) and usage-monitoring platform." The evidence pack supports a ~$3B figure as the company's valuation context, but the doc phrases it as the platform's size without labeling whether it's valuation, ARR, or market. "Roughly" softens it; still, an investor knows Nexthink's last private valuation context and may catch imprecision. Recommend "~$3B-valued" or "~$3B valuation" for precision.
- M2 — Competitive doc names specific competitors with characterizations that are litigable-adjacent if wrong (07-competitive). Calling Credo AI / OneTrust / ServiceNow "self-certified … the body that documents is the body being documented" and Big-4 advisory "grades its own engagement" are sharp, defensible category characterizations, but the disclosure blockquote ("reflect our current reading of public positioning") is the right shield and is present. Keep that blockquote; do not let any future edit drop it. LOW-to-MEDIUM only because the hedge is correctly in place.
- M3 — "no double-count … The total is a fact, not an approximation" (10-aperture) is a strong determinism claim that lives or dies on the connector layer that has never run live. Internally consistent with "deterministic, no model in path," but an investor will note the engine has only ever reconciled synthetic events it generated itself — "no double-count across overlapping real sources" is unproven until live connectors exist. The doc does say connectors are "built — never run live," so the caveat exists elsewhere, but the "fact, not an approximation" line in the determinism section reads stronger than the synthetic-only reality. Recommend a clause tying the no-double-count guarantee to "on the data shapes tested."
- M4 — Financials margin ranges (40–60%, 70%+) are labeled illustrative but have no basis shown (08-financials). Correctly tagged (illustrative) and the doc is admirably honest ("seeds for a conversation"). An investor will still ask "why 70%?" The doc pre-empts this well; flag only that there is zero unit-economics anchor (no cost-per-record, no CAC). Acceptable for a pre-MVP raise but worth a one-line "derivation to be built with counsel."
- M5 — Doc 14 (BCBS) names a real, identifiable enterprise (Blue Cross Blue Shield of Illinois) tied to a held/parked lead. Honesty is excellent ("intro note sent, nothing sold, held pending Solutions"). Risk: naming a specific named health plan in a circulated data room creates a real-world disclosure footprint — if BCBSIL hasn't agreed to be referenced, this is a relationship/reputational exposure, not a claim error. Recommend confirming permission to name, or anonymize to "a major Blue Cross Blue Shield plan."
LOW
- L1 — Market figures are internally consistent across all docs. Gartner $492M→$1B+, 75% by 2030 (quadrupling), EY 16%→48% Fortune 100, Deloitte 38% #1 barrier, EU AI Act 7%, BCG 40%+/ISO 42001 — every appearance matches the evidence pack verbatim. No drift. (Confirmed across one-pager, 07, 08, 09, 13, 14, 17, 18.)
- L2 — The six-framework list is consistent everywhere (NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP, ATLAS/MITRE ATLAS, CSF 2.0). Doc 11 correctly expands "ATLAS" to "MITRE ATLAS." No framework added or dropped across docs.
- L3 — Team roster is consistent and never over-populated (Richard Taubin, Joe Saba, Chris Bennett, Roberto Lleras, Sean Barlow). No invented people, titles, or bios. The "SME repository incoming / next update identifies the full engine team" hedge is held in one-pager, 08, 13. Good.
- L4 — Kelly rule is held everywhere. Every Kelly mention (one-pager, 09, 13, 14, 16, 18, plus the cross-links) frames it as "first channel / de-risked distribution / not the destination / not the pitch target." Microsoft consistently "the horizon, reachable through the team's senior-Microsoft relationships." Zero violations. This is a notable consistency win given how easy it is to slip.
- L5 — Minor framing nit (09-gtm vs 18-buyer): "Expand" stage in doc 09's land-and-expand table sells "Productivity + proof," but productivity/throughput is explicitly the thing doc 07 says competitors (DX/Jellyfish) own and govrn does NOT do. Selling "Productivity" as an Aperture expand-motion mildly muddies the "we are not a FinOps/productivity tool" positioning in doc 07. Recommend "Attributed usage + proof" to stay clean.
- L6 — "The interface carries evidence, not a verdict" is repeated near-verbatim in 6+ docs. Consistency is good; at data-room scale it reads slightly incantatory. Stylistic only.
Missing-but-expected content
- Cap table / use-of-funds dollar specificity. The ask is
$[ amount ]everywhere. Expected for an illustrative room, but an investor will want at least a range and a runway figure to react to. - Traction / pipeline beyond two held leads. BCBS and Grace Hill are both "held pending Solutions." There is no third signal, no waitlist, no LOI, no design-partner verbal. The room honestly reflects pre-MVP status, but the thinness of demand-side proof is the gap an investor will name first.
- Timeline / milestones with dates. Roadmap is cross-linked (06) but not in this corpus; the docs reference "next build" repeatedly without a single date or sequencing commitment (which connector first, by when). For a "we're funding connection not invention" thesis, the absence of a dated connector milestone is conspicuous.
- Competitive response / why-incumbents-can't-copy beyond "independence." Doc 07's moat rests entirely on independence + accumulated record. A sharp investor will ask why a Credo AI or OneTrust couldn't spin up a structurally-independent attest subsidiary. The docs assert they "cannot replicate independence without conceding it" but don't fully argue why that concession is so costly for them.
- Security/data-handling proof for "pointers not payloads." It's asserted as "forbidden by contract, enforced at the connector layer" but there is no third-party security review, no architecture audit, no SOC posture — and the docs themselves admit auth/RBAC/audit don't exist yet. For a product whose entire pitch is trust, the absence of any external security validation is a notable gap.