Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →We don't try to do everything ourselves. When a client needs deep specialist work like adversarial security testing, niche compliance audits, or hands-on red-team engagements, we bring in partners who have done it more times than we have. Here is who we work with and how the relationships work.
We work with a range of penetration testing and delivery partners, some Canadian and some elsewhere in the world, and we put the one that gives you the best value on your engagement. That decision is made per scope rather than by default: what is being tested, where your data and your buyers are, which currency you are paying in, and who is genuinely strong at that particular kind of work.
Scoping, compliance alignment, remediation strategy and reporting stay with us. Where an engagement calls for a specialist bench, hands-on testing is delivered by a partner firm we have worked with before and would put our name on. You get one contract, one invoice and one person to call, and we tell you who is doing the work before you sign.
For Canadian clients that usually means a Canadian testing firm: it quotes in CAD with no exchange rate on top, and already knows the privacy regime and the buyers you are answering to. Where the better answer is a firm outside Canada, we will say so, and we will say where they are based and what that costs you.
The same bench feeds our vulnerability management program and stands behind our incident response retainer when a client needs named responders on a contracted SLA.
We do not audit our own work, and no honest firm does. Readiness and attestation are separate jobs for a reason: the value of the report is that somebody independent signed it. So for every framework that ends in a signature, we coordinate with the firms that can actually give you one, and we help you pick between them rather than handing you the first name in our contacts.
We introduce you to more than one, brief them all on the same scope so the quotes are actually comparable, and sit with you while you read them. Auditors price the same engagement very differently, and most of the gap is scope and hours rather than quality, which is invisible until somebody puts the quotes side by side.
What we check on your behalf: that the CPA firm's licence is current and its practice unit is peer reviewed, that a certification body is accredited by a real accreditation body rather than self-declared, what the report or certificate will actually say, and whether the timing works against the observation window you are committed to. The choice is yours, and it stays yours.
Once you have chosen, we run the coordination: the evidence requests, the auditor's questions, the sampling, the exceptions, and the back and forth that otherwise lands on whoever is least able to absorb it. You get one thread to follow instead of two vendors talking past each other. Where any referral arrangement exists, we disclose it on the engagement.
These are not formal partnerships in the legal sense. They are the tools we deploy at most engagements because they work. We also resell or refer through several of them, and we disclose that on any engagement where it applies.
Most "partner programs" are paid affiliate networks dressed up as strategic relationships. Ours aren't. We have a small set of partners we work with deeply, and we do not chase logos.
The question we answer before any partnership: "If our reputation depends on this firm's work, are we willing to put our name on it?" A firm that cannot clear that bar does not get put in front of a client, whatever it would do for our margin. If you run a security, compliance, or engineering firm and think there's a fit, we will tell you honestly whether there is. Most of the time the answer is no, and that is the point.
If you are looking to send us a deal from your network, that is a different page. See Referrals for our program terms.
Co-delivery partnerships, technology integrations, joint engagements. Tell us what you do and where you think we'd add value. See our pricing and SKUs for how co-delivered engagements are typically scoped.
Get in touch