A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →You know a founder who needs SOC 2 readiness, a penetration test, an incident response retainer, or an AI security assessment. Send them our way. If they sign and pay, we pay you. Clear terms, no exclusivity, fast payouts.
Most referral programs are vague on purpose. Ours isn't. Here is exactly what you get and when.
Wondering what the engagement itself looks like once a lead signs? See our published starting prices for how these deals are typically scoped.
Fill out the form below. We need the referred company's name and the best way to reach them. Either make a warm intro yourself, or confirm the contact has agreed to hear from us. We'll reach out with you cc'd. We don't accept cold lists, scraped contacts, or companies you have registered speculatively without a real relationship.
If the lead fits our ICP (startup, technical work in security, compliance, or security leadership), we confirm with you and start the conversation. If it doesn't fit, we tell you why so you don't waste future referrals on bad-fit leads.
If the referred company signs an engagement, you receive 20% of each first-year payment we receive from them, excluding taxes, paid to you after the client's payment reaches us. We issue tax slips where required. No clawbacks if the client churns after.
The fee applies to first-year revenue only. If a referred client expands or renews into year two, that is on us, not on you. We will still tell you about it because most referrers want to know how their leads turned out.
The leads that close fastest and pay best fees share a few traits, especially a startup without a security leader in place that could use a fractional CISO. If you know a startup hitting any of these, send them over.
Tell us who you're sending and we'll take it from there. Replies within 48 hours. Prefer to talk it through first? Book a call.
A few things worth knowing up front: