A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A framework, a questionnaire, a pentest report: something is standing between you and the deal. Tell us what you are being asked for and we give you a rough read on where you stand, straight answers, and a quote. No sales pressure.
Based on what you tell us, we give you a plain-language sense of how far you are from what is being asked of you, whether that is a framework, a questionnaire, or a security bar nobody has written down. The detailed gap analysis is the first paid step if you decide to go ahead.
What drives your timeline: the gaps found, any observation period, and the auditor's schedule. We give you a timeline specific to your stack and your deadline.
We answer your questions and quote you. Compliance work starts from a fixed-scope gap analysis, then scoped remediation, with the independent auditor fee separate and transparent. Testing work is quoted on scope. Either way you leave knowing the number.
The call is yours. Ask anything about frameworks, penetration testing, timelines, auditors, or scope. It is led by a published security researcher, not a sales rep.
Prefer to just talk? Grab a time on the calendar directly.
A prospect's security questionnaire or procurement team wants proof before they will move forward. Sometimes that is a SOC 2 report, sometimes a pentest, sometimes forty questions you cannot answer yet. The deal is frozen either way.
Mid-raise or acquisition talk, someone asked what your security posture actually is, and you did not have a clean answer.
A report, a certificate, or an annual test is expiring, last year's provider was slow or expensive, and your internal team is already overloaded.
After a near-miss or a few deals lost to security reviews, you got approval to get your act together. You just need a plan you can trust and an order to do things in.
You have signed with a CPA firm or a certification body and you are no longer sure the evidence will hold. That is worth an hour now. Engagements that go wrong do not usually produce a bad report, they get paused partway through fieldwork, and by then the fee is spent. If it already has, see audit recovery.
Whatever the trigger, the underlying need is the same: de-risk the revenue or the raise without spending three months figuring out what to do first. That is exactly what this call is for. See how we run compliance readiness and security testing, or read why prep and audit are separate and what actually goes wrong in an audit.
A free 30-minute call where you tell us your situation and we give you a rough read on where you stand against whatever your buyer or board is asking for, whether that is a named framework, a penetration test, or a security questionnaire. We answer your questions and quote you. The detailed gap analysis is the first paid step. No obligation, no sales pressure.
SOC 2 Type I is commonly a few months from start to report, and Type II adds a 3, 6 or 12 month observation window. ISO 27001 certification commonly takes several months including the Stage 1 and Stage 2 audits. What drives it is the gaps found, the observation period and the auditor's or certification body's schedule. For a penetration test, the testing window is agreed at scoping. The call gives you a timeline specific to your environment.
Not for compliance reports. An independent CPA firm issues a SOC 2; we get you ready to pass it and coordinate that auditor for you. Security testing is different: penetration tests and assessments we run ourselves.
Yes. The 30-minute call is free and there is no obligation. You leave with a clearer picture and a quote either way.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.