A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Plain-language definitions of the security and compliance terms that show up in audits, sales questionnaires, and board decks. Written to be accurate and quotable, by the team that delivers SOC 2, penetration testing, AI/LLM security, and fractional CISO work.
Protecting LLM and AI agent applications from threats like prompt injection and data leakage.
AI SecurityThe internal rules for which AI tools staff may use and what data they may enter.
AI SecurityThe policies, roles, and processes for overseeing how AI is built, bought, and used responsibly.
ComplianceAlberta's private-sector privacy law, deemed substantially similar to PIPEDA, with mandatory breach reporting.
OffensiveThe full set of points where an attacker could try to enter or extract data from a system.
ComplianceThe conclusion a CPA firm writes into a SOC 2 report. No pass or fail stamp, but two of the four are outcomes you cannot use.
The controls a SOC 2 assumes its customers will operate for the provider's controls to hold up.
ComplianceThe entry tier of Canada's defence supply-chain cyber certification programme, its answer to CMMC.
VulnerabilitiesA unique public identifier assigned to a specific, publicly disclosed security vulnerability.
VulnerabilitiesAn open framework for rating the severity of a vulnerability from 0.0 to 10.0.
OperationsMeeting the controls an insurer requires to issue a policy and that a claim depends on.
ComplianceA federal certification against baseline cyber security controls aimed at small and medium organizations.
Testing a running application from the outside to find runtime vulnerabilities.
ComplianceWhich country your data is stored and processed in, distinct from whose laws can reach it.
ComplianceA structured assessment of a project's privacy risk, required by the GDPR and by Quebec Law 25 in defined cases.
The organized process for detecting, containing, and recovering from a security incident.
ComplianceAn international standard for an Information Security Management System (ISMS).
AI SecurityThe international standard for a certifiable AI management system, the ISO 27001 of artificial intelligence.
Security requirements for any organization that handles payment card data.
OffensiveThe difference between automated breadth (scan) and manual depth (pen test).
OffensiveAn authorized, manual assessment where testers actively exploit weaknesses like a real attacker.
ComplianceCanada's federal private-sector privacy law, built on ten Fair Information Principles and overseen by the Privacy Commissioner.
ComplianceThe tracked list of requirements not yet met, each with an owner and a date.
AI SecurityAn attack where crafted input makes an LLM ignore its instructions and follow the attacker's.
Analyzing source code for security flaws without running the program.
OperationsOngoing staff training against phishing and social engineering that frameworks expect on a cadence.
ComplianceThe structured questions an enterprise buyer sends to assess a vendor's security posture.
AI SecurityUnsanctioned use of AI tools by staff, where sensitive data leaves your control without any record.
OperationsA system that collects and correlates log data across systems to detect threats.
ComplianceAn AICPA auditing standard reporting on how a service organization manages customer data.
ComplianceA management letter covering the gap between a SOC 2 report's period end and a later date.
ComplianceDesign at a point in time (Type I) vs operating effectiveness over a period (Type II).
ComplianceThe mandatory ISO 27001 document that justifies which Annex A controls apply and which are excluded.
ComplianceWhich of your vendors your customers must be told about, and why the test is data flow rather than spend.
ComplianceA vendor whose own controls matter to a SOC 2 report, usually handled by the carve-out method.
The technology and security assessment an investor or acquirer runs before a round or a deal.
ComplianceThe ongoing programme for assessing and monitoring the risk that vendors and suppliers introduce.
ComplianceA formal document naming the threats to your systems, rating each risk, and documenting mitigations.
OffensiveA structured process for identifying threats and mitigations early in system design.
ComplianceA public page that publishes your security posture so buyers self-serve before sending a questionnaire.
ComplianceThe five categories a SOC 2 can be built on; Security is mandatory and the other four are scoped in.
A security executive who runs your security program on a part-time or contract basis.
VulnerabilitiesA systematic review that identifies and prioritizes known security weaknesses.
VulnerabilitiesThe continuous loop around scanning: triage, remediation within an SLA, and verification, with owners.
SOC 2 readiness, penetration testing, AI/LLM security, and fractional CISO leadership, backed by real published research.
Book a strategy call