Skip to content
Built by industry veterans

Your buyers already have a security team.
Now they're asking about yours.

Nighthawk is a fractional CISO practice for companies where data and AI are the product. We set direction, build the program around how you actually work, and give your team a straight answer when a customer asks if your AI is safe.

How this helps you

Five situations we get called into. None of them start on your schedule: a customer asks, and the clock is already running. The sooner it's handled, the cheaper it is.

If this is you

A customer just asked for your SOC 2.

You probably don't need the full thing yet. We find out what the buyer actually requires, scope the shortest credible path, and run it. You get a security answer that keeps the deal moving, not a nine-month audit project.

Unblock a deal
If this is you

You ship AI and buyers want to know it's safe.

We build the governance that holds up under questioning: what models and data you use, what controls sit around them, mapped to NIST AI RMF or ISO 42001 where a customer will look. Then we turn it into something your sales team can say out loud.

Build a program
If this is you

One engineer is doing security at 11pm.

We take the direction off their plate. Priorities, vendor decisions, the board slide, the tooling, and the hiring plan when it's time for a full-time hire. They go back to shipping.

Build a program
If this is you

An enterprise deal is stuck on a questionnaire.

We answer it, fix the two things that were actually wrong, and build the evidence set so the next one takes an afternoon instead of a week of engineering time.

Unblock a deal
If this is you

Your agents can already do things you can't undo.

They have credentials and merge rights, and nobody has written down what they're allowed to do without a person watching. We draw that line, enforce it at the gate instead of in a policy document, scope each agent's identity so it isn't holding standing access, and leave an audit trail that answers what happened afterward.

Build a program
How we run ours

Our own agents work under exactly these rules. Each one gets credentials scoped to the task in front of it, the line it can't cross without a person is written down, and the log will tell you what any of them did on a given Tuesday. Ask on a call and we'll walk you through the setup.

Compliance is table stakes.
Security is the game.

A certificate gets you past procurement. A real program is what lets you sell to the customers everyone else can't.

  • Zero to SOC 2 Type II and ISO 27001Built from nothing at a company whose product is data.
  • An international security organizationEngineering, operations and architecture for a multi-tenant ML platform.
  • Five to seven million in pipelineFrom security reviews and briefings that moved real deals.
Operators, not auditors

Most vCISO shops came up through audit. We came up through running security and IT at multiple companies where data was part of the product, selling into the Fortune 500, and leading global cyber defense for one of its multinationals across four continents. We've been on the receiving end of the questionnaire.

Data, security, AI

Very few security leaders have worked at the point where these three meet. It's a narrow specialty and it's the only one we practice. If your product is a data product with AI in it, you don't have to explain what you do before we can help.

Built for the sales call

Every control we put in place has to survive a customer asking "so what does that mean for us." Security should be the reason a deal closes, not a line item finance tolerates.

Judgment is the job

Security teams got big because most of the job repeated itself. Someone had to pull the evidence, keep the control map current, answer the same questionnaire a fourth time. Software does that work now. We build and run it ourselves, instead of buying a platform and handing you the login. What software can't tell you is which finding matters, or when to tell a customer their checklist is wrong. That still takes a person who has been through it. So the program stays small.

Tell us what's going on.

A stalled enterprise deal costs more than the program that unsticks it. A short note is enough. We reply within two business days with an honest read on fit and what we'd do first.

Start a conversation