Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Startup toolkit.

Free interactive tools to help you assess your security posture, plan your infrastructure, and make smarter hiring decisions.

AI/LLM Security Risk Assessment

Answer 10 questions mapped to the OWASP LLM Top 10 and get a risk score with the specific security gaps in your AI application.

Assess your AI risk

EU AI Act Risk Classifier

Walk a short decision flow to classify your AI system as unacceptable, high, limited, or minimal risk under the EU AI Act, and see the obligations that follow.

Classify your system

AI Governance Readiness

Rate your AI governance maturity across ISO 42001 and NIST AI RMF themes and get a score with your priority gaps.

Check your maturity

Shadow AI Exposure Check

Find out how exposed you are to unmanaged AI tool use across your team, and the controls that close the gaps.

Check your exposure

AI Acceptable Use Policy Generator

Answer a few questions and generate a clean, copyable starter AI acceptable use policy for your company.

Generate a policy

Vibe-Coded App Launch Checklist

Built your app with an AI coding tool? Check secrets, Supabase RLS or Firebase rules, auth, access control and webhooks, and get a risk score with the fixes to make first.

Check your app

LLM Prompt Injection Test Pack

Safe test cases for your own AI feature, grouped by OWASP LLM Top 10 category: direct and indirect injection, hidden context, excessive agency, leaks and output handling.

Get your test pack

ISO 27001 Gap Assessment

Self-rate against the four ISO 27001:2022 Annex A themes and get a maturity score with your biggest gaps before certification.

Find your gaps

Internal Audit Programme Planner

Spread ISO 27001 or ISO 42001 clauses 4 to 10 and every Annex A theme across a multi-year internal audit cycle, and get a plan table.

Plan your audits

CyberSecure Canada Readiness Checker

Check each CAN/DGSI 104 requirement at Level 1 and Level 2, plus CPCSC Level 1, and see your status by clause group and the gaps to close.

Check your level

NIST CSF 2.0 Self-Assessment

Rate your maturity across the six NIST CSF 2.0 Functions and see your tier and weakest areas.

Rate your posture

Security Program Scorecard

No framework yet? Score your programme across ten areas, rolled up to the NIST CSF 2.0 functions, and get a suggested next step.

Score your programme

PCI DSS SAQ Finder

Answer a few questions about how you handle card data and find the exact PCI DSS SAQ type that applies to you.

Find your SAQ

Privacy Law Finder

Tell us where your users are and find which privacy laws apply to you (GDPR, PIPEDA, Quebec Law 25, CPRA) and their headline obligations.

Find your laws

Law 25 Privacy Officer Checker

See which Quebec Law 25 and PIPEDA privacy officer obligations you meet: designation, published contact, policies, access requests, incident register and PIAs.

Check your obligations

DPIA / Privacy Impact Assessment Builder

Answer structured questions about a processing activity and generate a DPIA draft aligned to GDPR Art. 35 and Quebec Law 25.

Build a DPIA

Security Policy Generator

Generate copyable starter Information Security, Access Control, and Acceptable Use policies tailored to how your company operates.

Generate policies

SOC 2 Evidence Tracker

Track the evidence artifacts a SOC 2 audit needs, grouped by Trust Services Criteria, with a live completion score.

Track your evidence

Compliance Calendar Builder

A 12-month calendar of the recurring activities SOC 2, ISO 27001, CyberSecure Canada, PCI DSS and HIPAA expect: access reviews, scans, training, tabletops and more.

Build your calendar

Security Training Requirement Finder

What each framework requires for staff training, how often, and the evidence to keep, combined into one programme.

Find your requirements

Vendor Security Questionnaire Builder

Pick your risk areas and build a security questionnaire you can send to your own vendors.

Build a questionnaire

Compliance Cost Estimator

What an audit really costs three ways: your own staff hours, a compliance platform, or a firm. Every assumption is on screen and editable.

Compare the three routes

vCISO ROI Calculator

Compare the cost of a full-time CISO against a fractional arrangement with transparent, editable math.

Run the numbers

MSP Partner Margin Calculator

For MSPs and consultancies: your margin per engagement and annual gross profit reselling security and compliance work at a wholesale discount.

Model your margin

Cloud Security Posture Check

Answer 10 questions on IAM, logging, encryption, and exposure to get a cloud security posture score and your top gaps.

Check your posture

Cloud Cost Estimator

Estimate what your AWS, GCP or Azure setup should cost, and see where the gap between that and your bill usually hides.

Estimate your spend

Auditor Evidence Request Simulator

See the evidence requests your auditor will send, mark what you could produce this week, and get the gap list before fieldwork starts.

Rehearse the audit

Trust Center Builder

Mark what you can publish today, see how much buyer diligence a trust page would answer up front, and copy the outline.

Build the outline

Cyber Insurance Readiness Check

See whether you have the controls underwriters ask about (MFA, EDR, backups, IR plan) before you apply for cyber insurance.

Check readiness

Security Risk Register Builder

Add your risks and build a prioritized security risk register with likelihood × impact ratings you can export.

Build a register

TRA Worksheet

Score assets, threats and vulnerabilities 1 to 5 using the Harmonized TRA structure, see risk banded very low to very high, and export the register.

Start a worksheet

SOC 2 Readiness Assessment

Answer 10 questions about your current security practices and get a readiness score with actionable recommendations to prepare for your SOC 2 audit.

Take the assessment

Startup Security Score Calculator

Check off 12 essential security practices and see where your startup stands. Get specific recommendations for every gap in your security posture.

Calculate your score

Incident Response Plan Generator

Generate a tailored incident response plan based on your industry, company size, and data types. Copy it and start using it today.

Generate your plan

Incident Response Readiness Score

Fourteen questions on your plan, contacts, testing, backups, insurance, breach counsel, logging and MFA, with a score by area and the gaps to close.

Score your readiness

Compliance Framework Finder

Answer 8 questions about your business and find out which compliance frameworks you need: SOC 2, HIPAA, GDPR, PCI-DSS, or ISO 27001.

Find your framework

Data Breach Cost Calculator

Estimate what a breach could cost your company from your record count, sector, and current controls. See a range with the assumptions stated, not a single scary number.

Estimate the cost

Ransomware Readiness Scorecard

Answer 10 questions about your backups, segmentation, and recovery to get a readiness score and a prioritized list of the gaps to close first.

Score your readiness

Vendor Risk Calculator

Rate a third-party vendor's risk from data access, certifications, and criticality. Get a live risk tier and the right level of due diligence to apply.

Rate a vendor

PHIPA Readiness Self-Assessment

Ontario health data, assessed against the statute rather than a security framework: custodian, agent or electronic service provider, safeguards, logging, consent, breach and IPC duties.

Assess your PHIPA position

HIPAA Readiness Checklist

Work through the HIPAA Security Rule safeguards across administrative, physical, and technical controls. Track a completion score and export a summary.

Check your safeguards

Security Questionnaire Helper

Select the enterprise security questions you were asked and get a suggested answer framework and evidence list for each. Adapt them to what you actually do.

Build your answers

Due Diligence Readiness Scorecard

For startups preparing to raise and investors screening a target: red, amber or green on architecture, code, security, compliance, team and key-person risk.

Get your rating

Observation Window Planner

Work backwards from the date your buyer needs the SOC 2 report and get the last day every control has to be live and producing dated evidence.

Plan your window

Pen Test Scoping Calculator

Estimate the effort in tester-days and a price range for a penetration test from your app type, scale, authentication, and environments before a scoping call.

Scope a test

Need help with any of this?

We help startups run SOC 2 readiness, hire a Fractional CISO, and close the rest of their compliance gaps. Let's talk.

Book a free consultation

That result is worth keeping. A free Workspace stores it against the control it evidences, alongside the rest of the framework, so the next assessment starts where this one finished.

See what the Workspace does →

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.