Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Partners

We don't try to do everything ourselves. When a client needs deep specialist work like adversarial security testing, niche compliance audits, or hands-on red-team engagements, we bring in partners who have done it more times than we have. Here is who we work with and how the relationships work.

Testing and delivery partners

We work with a range of penetration testing and delivery partners, some Canadian and some elsewhere in the world, and we put the one that gives you the best value on your engagement. That decision is made per scope rather than by default: what is being tested, where your data and your buyers are, which currency you are paying in, and who is genuinely strong at that particular kind of work.

Audit and certification partners

We do not audit our own work, and no honest firm does. Readiness and attestation are separate jobs for a reason: the value of the report is that somebody independent signed it. So for every framework that ends in a signature, we coordinate with the firms that can actually give you one, and we help you pick between them rather than handing you the first name in our contacts.

SOC 1 · SOC 2 · SOC 3
A licensed CPA firm
ISO 27001 · ISO 42001
An accredited certification body
PCI DSS
A QSA, or self-assessment where you qualify
HIPAA · PIPEDA · Law 25 · GDPR
No certificate exists to buy

Tooling we run in production

These are not formal partnerships in the legal sense. They are the tools we deploy at most engagements because they work. We also resell or refer through several of them, and we disclose that on any engagement where it applies.

Compliance
Vanta · Drata
Cloud
AWS · GCP · Cloudflare
DevOps
GitHub Actions · Terraform
Observability
Datadog · Sentry · Grafana
Identity
Okta · 1Password
MDM
Kandji · Jamf
AppSec
Snyk · Semgrep · GitGuardian
On-call
PagerDuty · incident.io

What we look for in a partner

Most "partner programs" are paid affiliate networks dressed up as strategic relationships. Ours aren't. We have a small set of partners we work with deeply, and we do not chase logos.

The question we answer before any partnership: "If our reputation depends on this firm's work, are we willing to put our name on it?" A firm that cannot clear that bar does not get put in front of a client, whatever it would do for our margin. If you run a security, compliance, or engineering firm and think there's a fit, we will tell you honestly whether there is. Most of the time the answer is no, and that is the point.

If you are looking to send us a deal from your network, that is a different page. See Referrals for our program terms.

Think there is a fit?

Co-delivery partnerships, technology integrations, joint engagements. Tell us what you do and where you think we'd add value. See our pricing and SKUs for how co-delivered engagements are typically scoped.

Get in touch