A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Free interactive tools to help you assess your security posture, plan your infrastructure, and make smarter hiring decisions.
Answer 10 questions mapped to the OWASP LLM Top 10 and get a risk score with the specific security gaps in your AI application.
Assess your AI riskWalk a short decision flow to classify your AI system as unacceptable, high, limited, or minimal risk under the EU AI Act, and see the obligations that follow.
Classify your systemRate your AI governance maturity across ISO 42001 and NIST AI RMF themes and get a score with your priority gaps.
Check your maturityFind out how exposed you are to unmanaged AI tool use across your team, and the controls that close the gaps.
Check your exposureAnswer a few questions and generate a clean, copyable starter AI acceptable use policy for your company.
Generate a policyBuilt your app with an AI coding tool? Check secrets, Supabase RLS or Firebase rules, auth, access control and webhooks, and get a risk score with the fixes to make first.
Check your appSafe test cases for your own AI feature, grouped by OWASP LLM Top 10 category: direct and indirect injection, hidden context, excessive agency, leaks and output handling.
Get your test packSelf-rate against the four ISO 27001:2022 Annex A themes and get a maturity score with your biggest gaps before certification.
Find your gapsSpread ISO 27001 or ISO 42001 clauses 4 to 10 and every Annex A theme across a multi-year internal audit cycle, and get a plan table.
Plan your auditsCheck each CAN/DGSI 104 requirement at Level 1 and Level 2, plus CPCSC Level 1, and see your status by clause group and the gaps to close.
Check your levelRate your maturity across the six NIST CSF 2.0 Functions and see your tier and weakest areas.
Rate your postureNo framework yet? Score your programme across ten areas, rolled up to the NIST CSF 2.0 functions, and get a suggested next step.
Score your programmeAnswer a few questions about how you handle card data and find the exact PCI DSS SAQ type that applies to you.
Find your SAQTell us where your users are and find which privacy laws apply to you (GDPR, PIPEDA, Quebec Law 25, CPRA) and their headline obligations.
Find your lawsSee which Quebec Law 25 and PIPEDA privacy officer obligations you meet: designation, published contact, policies, access requests, incident register and PIAs.
Check your obligationsAnswer structured questions about a processing activity and generate a DPIA draft aligned to GDPR Art. 35 and Quebec Law 25.
Build a DPIAGenerate copyable starter Information Security, Access Control, and Acceptable Use policies tailored to how your company operates.
Generate policiesTrack the evidence artifacts a SOC 2 audit needs, grouped by Trust Services Criteria, with a live completion score.
Track your evidenceA 12-month calendar of the recurring activities SOC 2, ISO 27001, CyberSecure Canada, PCI DSS and HIPAA expect: access reviews, scans, training, tabletops and more.
Build your calendarWhat each framework requires for staff training, how often, and the evidence to keep, combined into one programme.
Find your requirementsPick your risk areas and build a security questionnaire you can send to your own vendors.
Build a questionnaireWhat an audit really costs three ways: your own staff hours, a compliance platform, or a firm. Every assumption is on screen and editable.
Compare the three routesCompare the cost of a full-time CISO against a fractional arrangement with transparent, editable math.
Run the numbersFor MSPs and consultancies: your margin per engagement and annual gross profit reselling security and compliance work at a wholesale discount.
Model your marginAnswer 10 questions on IAM, logging, encryption, and exposure to get a cloud security posture score and your top gaps.
Check your postureEstimate what your AWS, GCP or Azure setup should cost, and see where the gap between that and your bill usually hides.
Estimate your spendSee the evidence requests your auditor will send, mark what you could produce this week, and get the gap list before fieldwork starts.
Rehearse the auditMark what you can publish today, see how much buyer diligence a trust page would answer up front, and copy the outline.
Build the outlineSee whether you have the controls underwriters ask about (MFA, EDR, backups, IR plan) before you apply for cyber insurance.
Check readinessAdd your risks and build a prioritized security risk register with likelihood × impact ratings you can export.
Build a registerScore assets, threats and vulnerabilities 1 to 5 using the Harmonized TRA structure, see risk banded very low to very high, and export the register.
Start a worksheetAnswer 10 questions about your current security practices and get a readiness score with actionable recommendations to prepare for your SOC 2 audit.
Take the assessmentCheck off 12 essential security practices and see where your startup stands. Get specific recommendations for every gap in your security posture.
Calculate your scoreGenerate a tailored incident response plan based on your industry, company size, and data types. Copy it and start using it today.
Generate your planFourteen questions on your plan, contacts, testing, backups, insurance, breach counsel, logging and MFA, with a score by area and the gaps to close.
Score your readinessAnswer 8 questions about your business and find out which compliance frameworks you need: SOC 2, HIPAA, GDPR, PCI-DSS, or ISO 27001.
Find your frameworkEstimate what a breach could cost your company from your record count, sector, and current controls. See a range with the assumptions stated, not a single scary number.
Estimate the costAnswer 10 questions about your backups, segmentation, and recovery to get a readiness score and a prioritized list of the gaps to close first.
Score your readinessRate a third-party vendor's risk from data access, certifications, and criticality. Get a live risk tier and the right level of due diligence to apply.
Rate a vendorOntario health data, assessed against the statute rather than a security framework: custodian, agent or electronic service provider, safeguards, logging, consent, breach and IPC duties.
Assess your PHIPA positionWork through the HIPAA Security Rule safeguards across administrative, physical, and technical controls. Track a completion score and export a summary.
Check your safeguardsSelect the enterprise security questions you were asked and get a suggested answer framework and evidence list for each. Adapt them to what you actually do.
Build your answersFor startups preparing to raise and investors screening a target: red, amber or green on architecture, code, security, compliance, team and key-person risk.
Get your ratingWork backwards from the date your buyer needs the SOC 2 report and get the last day every control has to be live and producing dated evidence.
Plan your windowEstimate the effort in tester-days and a price range for a penetration test from your app type, scale, authentication, and environments before a scoping call.
Scope a testThat result is worth keeping. A free Workspace stores it against the control it evidences, alongside the rest of the framework, so the next assessment starts where this one finished.
See what the Workspace does →Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.