Security is the thing blocking your next deal
A big customer won't sign without SOC 2 / ISO 27001 and no one owns getting there.
Security questionnaires pile up and eat engineering weeks to answer.
Security is a pile of ad-hoc controls with no policy, no owner, and no evidence.
The board or a recent incident has made risk a top-three concern overnight.
The company handles sensitive data and has no defensible answer to "are we secure?"
What you get
Not hours on a timesheet — decisions made, systems shipped, and a program that works.
SOC 2 path, named
A path to SOC 2 Type II or ISO 27001 with a named owner, realistic timeline, and auditor selection.
Questionnaires as an asset
A maintained answer library so security questionnaires take hours, not weeks — turned into a sales accelerator.
Real risk picture
What matters, what's accepted, what's being fixed — in writing. A risk register that's live and owned.
Incident readiness
A response plan, roles, runbook, and tabletop exercise that exists before it's needed.
Three shapes, one operator
Start where the pain is acute. Scale as trust is established.
Security Posture Assessment
$4,000 fixed fee
A 2-week risk assessment, control gap analysis, and questionnaire audit. You leave with a prioritized plan and auditor recommendation — whether we work together or not. SOC 2 readiness-to-audit can also be scoped as a fixed-fee program ($25K–$60K depending on scope). Credits toward the first month of a retainer.
Your first 90 days
A predictable ramp with clear deliverables at each phase.
Weeks 1–2 — Assess
Risk assessment, control gap analysis, questionnaire audit. Deliver Security Posture Assessment and the plan.
Weeks 3–4 — Foundations
Publish the policy set; stand up the risk register and questionnaire answer library; fix top access and logging gaps.
Weeks 5–8 — Program
Implement priority controls; select auditor and tooling; run the incident response tabletop.
Weeks 9–12 — Readiness
Enter SOC 2 observation window or ISO Stage 1. Deliver the first board security report. Decide: continue through audit as Embedded or step up to Fractional-in-a-box.
Not the right fit?
We are selective about engagements. This may not be right if:
✗
No enterprise motion and no regulated data — you may not need this yet.
✗
Wants a purely check-the-box audit with zero intent to actually reduce risk.
✗
Needs someone available on-demand all day — our model is async by design (with a defined incident escalation path).