Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Free · 30 minutes · No obligation

Your buyer wants you secure. Get a straight answer in 30 minutes.

A framework, a questionnaire, a pentest report: something is standing between you and the deal. Tell us what you are being asked for and we give you a rough read on where you stand, straight answers, and a quote. No sales pressure.

SOC 2 ISO 27001 HIPAA PCI DSS

A straight answer, not a pitch

01

A rough read on where you stand

Based on what you tell us, we give you a plain-language sense of how far you are from what is being asked of you, whether that is a framework, a questionnaire, or a security bar nobody has written down. The detailed gap analysis is the first paid step if you decide to go ahead.

02

A realistic timeline

Most clients are audit-ready in 8 to 12 weeks. A pentest or a questionnaire response is faster than that. We give you a timeline specific to your stack and your deadline.

03

A quote

We answer your questions and quote you. Compliance work starts from a fixed-scope gap analysis, then scoped remediation, with the independent auditor fee separate and transparent. Testing work is quoted on scope. Either way you leave knowing the number.

04

Your questions, answered

The call is yours. Ask anything about frameworks, penetration testing, timelines, auditors, or scope. It is led by a published security researcher, not a sales rep.

Prefer to just talk? Grab a time on the calendar directly.

Book your free call

30 minutes. We reply within one business day.

Most people book this after one of these

An enterprise deal stalled

A prospect's security questionnaire or procurement team wants proof before they will move forward. Sometimes that is a SOC 2 report, sometimes a pentest, sometimes forty questions you cannot answer yet. The deal is frozen either way.

Investors or the board asked

Mid-raise or acquisition talk, someone asked what your security posture actually is, and you did not have a clean answer.

A deadline or renewal is looming

A report, a certificate, or an annual test is expiring, last year's provider was slow or expensive, and your internal team is already overloaded.

You finally got the budget

After a near-miss or a few deals lost to security reviews, you got approval to get your act together. You just need a plan you can trust and an order to do things in.

The audit is already booked

You have signed with a CPA firm or a certification body and you are no longer sure the evidence will hold. That is worth an hour now. Engagements that go wrong do not usually produce a bad report, they get paused partway through fieldwork, and by then the fee is spent. If it already has, see audit recovery.

Whatever the trigger, the underlying need is the same: de-risk the revenue or the raise without spending three months figuring out what to do first. That is exactly what this call is for. See how we run compliance readiness and security testing, or read why prep and audit are separate and what actually goes wrong in an audit.

Frequently asked questions

What is the free readiness call?

A free 30-minute call where you tell us your situation and we give you a rough read on where you stand against whatever your buyer or board is asking for, whether that is a named framework, a penetration test, or a security questionnaire. We answer your questions and quote you. The detailed gap analysis is the first paid step. No obligation, no sales pressure.

How long does this take?

For SOC 2, most companies with reasonable hygiene are audit-ready in 8 to 12 weeks for a Type I, then run the Type II observation window on top. ISO 27001 is comparable. A penetration test or a questionnaire response is a matter of weeks, not months. The assessment gives you a timeline specific to your environment.

Are you the auditor?

Not for compliance reports. An independent CPA firm issues a SOC 2; we get you ready to pass it and coordinate that auditor for you. Security testing is different: penetration tests and assessments we run ourselves.

Is it really free?

Yes. The 30-minute call is free and there is no obligation. You leave with a clearer picture and a quote either way.

Get your plan in 30 minutes.

Free 30-minute readiness call. No obligation.

Book my free call

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.