Skip to content

Security & compliance, built in from the first commit.

SOC2, GDPR, HIPAA, ISO 27001, FedRAMP, PCI-DSS — we’ve shipped to all of them. We do the threat modeling, the controls, the evidence, and the audit support. Not a checklist before a deadline — a working security program that survives your first enterprise pilot.

Rate $120 – $150 USD / hour · fixed-fee and retainer available

What you get

Threat model
STRIDE-based, written for your actual architecture, not a template.
Compliance roadmap
SOC2 / GDPR / HIPAA / ISO 27001, mapped to the controls you actually need (not all 200).
IaC security
policy-as-code in your PR pipeline, blocking the common 12 misconfigurations before deploy.
Pentest remediation
we don’t run the pentest, we fix what the pentest found. Triage, fix, retest.
Identity & access
SSO, SCIM, RBAC, just-in-time access, audit logging, offboarding automation.
Audit support
we sit in the auditor calls, write the responses, and chase the evidence.

How we engage

  1. 01

    Compliance gap assessment (1–2 weeks)

    Written report of where you are vs. where you need to be. Cost estimate and timeline to close.

  2. 02

    Compliance build (8–12 weeks)

    Controls implemented, evidence collection automated, training delivered, dry-run audit.

  3. 03

    On-call security retainer

    For the months before and after the audit — answer auditor questions, fix newly-discovered gaps.

Stack we work in

Compliance

Drata, Vanta, Secureframe, Tugboat Logic

IaC scanning

Checkov, tfsec, Snyk IaC, Trivy, Kics

App scanning

Snyk, GitGuardian, Semgrep, CodeQL

Cloud security

AWS Security Hub, GCP SCC, Wiz, Lacework, Orca

Identity

Okta, Auth0, WorkOS, Azure AD, JumpCloud

Pentest

NCC Group, Trail of Bits, Bishop Fox, Cobalt

Reference architectures

Anonymized patterns from real engagements. Client names omitted; details available under NDA.

Healthtech pre-pilot — SOC2 in 90 days

Full IaC rewrite, IAM hardening, evidence pipeline in Drata, BAAs signed with 3 hospital networks. SOC2 Type II issued without critical findings.

Fintech — PCI-DSS scope reduction

Refactored the payment flow to push the card data out of scope. From SAQ-D to SAQ-A. Quarterly scans cleared on the first attempt.

Hardware startup — GDPR + DPDP dual-compliance

Designed a data flow that satisfies both EU and India requirements with one control set. DPIA approved by both DPOs.

Questions we get asked

Do you run pentests?

No — we coordinate with the firm that does, and we fix what they find. Our value is in the remediation, the controls, and the audit support.

How long does SOC2 Type II take?

Type I: 4–8 weeks. Type II: 3–6 months of observation window. We’ve done both in compressed timelines for time-pressed pilots, but never below 90 days — auditors won’t accept less.

Do you help with HIPAA, FedRAMP, ISO 27001?

Yes. We’ve shipped all of them. See the Commercials page for the full list.

Can you do the CISO function for a pre-Series-A startup?

Yes — fractional CISO retainer. 4–8 hours a week, board-ready reporting, auditor-facing.

What does the audit evidence look like?

Automated screenshots, signed access logs, change tickets, IaC diffs — collected in Drata / Vanta in a format your auditor can read. We set up the pipeline; you (or your auditor) just hits download.

Let’s scope it properly.

A 30-minute call. No deck, no pitch — we read your repo or your architecture diagram and tell you what’s realistic.