Healthtech pre-pilot — SOC2 in 90 days
Full IaC rewrite, IAM hardening, evidence pipeline in Drata, BAAs signed with 3 hospital networks. SOC2 Type II issued without critical findings.
SOC2, GDPR, HIPAA, ISO 27001, FedRAMP, PCI-DSS — we’ve shipped to all of them. We do the threat modeling, the controls, the evidence, and the audit support. Not a checklist before a deadline — a working security program that survives your first enterprise pilot.
Rate $120 – $150 USD / hour · fixed-fee and retainer available
Compliance gap assessment (1–2 weeks)
Written report of where you are vs. where you need to be. Cost estimate and timeline to close.
Compliance build (8–12 weeks)
Controls implemented, evidence collection automated, training delivered, dry-run audit.
On-call security retainer
For the months before and after the audit — answer auditor questions, fix newly-discovered gaps.
Compliance
Drata, Vanta, Secureframe, Tugboat Logic
IaC scanning
Checkov, tfsec, Snyk IaC, Trivy, Kics
App scanning
Snyk, GitGuardian, Semgrep, CodeQL
Cloud security
AWS Security Hub, GCP SCC, Wiz, Lacework, Orca
Identity
Okta, Auth0, WorkOS, Azure AD, JumpCloud
Pentest
NCC Group, Trail of Bits, Bishop Fox, Cobalt
Anonymized patterns from real engagements. Client names omitted; details available under NDA.
Full IaC rewrite, IAM hardening, evidence pipeline in Drata, BAAs signed with 3 hospital networks. SOC2 Type II issued without critical findings.
Refactored the payment flow to push the card data out of scope. From SAQ-D to SAQ-A. Quarterly scans cleared on the first attempt.
Designed a data flow that satisfies both EU and India requirements with one control set. DPIA approved by both DPOs.
No — we coordinate with the firm that does, and we fix what they find. Our value is in the remediation, the controls, and the audit support.
Type I: 4–8 weeks. Type II: 3–6 months of observation window. We’ve done both in compressed timelines for time-pressed pilots, but never below 90 days — auditors won’t accept less.
Yes. We’ve shipped all of them. See the Commercials page for the full list.
Yes — fractional CISO retainer. 4–8 hours a week, board-ready reporting, auditor-facing.
Automated screenshots, signed access logs, change tickets, IaC diffs — collected in Drata / Vanta in a format your auditor can read. We set up the pipeline; you (or your auditor) just hits download.
A 30-minute call. No deck, no pitch — we read your repo or your architecture diagram and tell you what’s realistic.