Four ways in.
One program out.
Every company we work with gets a program shaped to how it operates, sells, and ships. These are the doors people usually walk in through. Where you end up depends on what we find.
Fractional CISO
One engineer is doing security at 11pm, or nobody is. What you need is someone who owns the direction, not another tool.
Good fit: Series A to C, no security leader, engineering-led.
Read moreProject, then ongoingAI trust program
You ship AI and a buyer has started asking whether it is safe. You need an answer that survives their security review.
Good fit: AI is in the product and enterprise buyers are starting to ask hard questions about it.
Read moreProjectFirst security program
A customer asked for something you do not have, and there is a date on it. Nothing is written down yet.
Good fit: First enterprise customer, first diligence, first time someone said "send us your security documentation."
Read moreProjectDeal support
Deals do not die in a no. They die in a long pause. Sales is waiting on security and nobody owns it.
Good fit: A questionnaire, a diligence request, or a procurement review is blocking revenue.
Read moreHow an engagement runs
We keep it short and honest. If we're not the right fit, we'll say so in the first conversation and point you somewhere better.
- Scoping call
Thirty minutes. What prompted this, what you sell, what's already in place. You leave with an opinion, whether or not you hire us.
- Assessment
One to three weeks depending on size. We look at the real thing: infrastructure, data flows, how AI is used, what customers are asking, what a diligence reviewer would find. Output is a prioritized plan, not a hundred-page report.
- Build
We do the work alongside your team. Policies, controls, tooling, evidence, training. You'll see every change in the tools you already use.
- Run or hand off
Either we stay on as your fractional CISO, or we hand a working program to the person you hire. Both are fine. We'll tell you which one we'd pick for you.
Things we don't do
Worth saying, because it's how we stay good at the things we do.
- Audits
We get you ready and sit with you through it. We don't issue the report, because you should never hire the same firm to build and to grade.
- Managed SOC or 24/7 monitoring
We'll help you choose a vendor and hold them to what they sold you. Watching screens is their job. If something gets through, we're the ones running the incident, making the calls that can't be unmade, and sitting across from the customer when it's over.
- Templates with your logo on them
If a policy doesn't describe how your company actually works, it's a liability in a diligence review, not an asset.