Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Productized engagements Fixed price · Fixed scope

Know the price
before you call us.

Every engagement below has a fixed price, a defined scope, and a stated timeline. You can work out what you need and roughly what it costs without booking anything, and you can put a real number in front of whoever approves your budget.

Why we publish prices

Most security firms quote after a discovery call, which means you cannot compare two of them without sitting through two sales processes. Published prices let you compare like for like, get internal sign-off in days rather than months, and start with a deliverable instead of an open-ended retainer. If your situation does not fit a fixed scope, we will tell you that on the call rather than stretching one to fit.

Seven ways to start

EngagementPrice (CAD)Time to deliverWhat it gets you
Free 30-min Discovery Call$030 minA straight read on where you stand and what it would cost
Cloud Cost Audit AWS · GCP · AzureFrom $2,0001 weekA costed list of what to change, and what it saves
Technical Due Diligence LightFrom $4,5005 business daysA diligence-ready technical report your investors can read
Penetration Testing & Security AssessmentFrom $1,000ScopedFindings with severities, plus the retest that proves they are fixed
AI/LLM Security AssessmentFrom $4,0001 weekWhere your AI features are exposed, and how to close it
SOC 2 in 75 DaysFrom $3,000 (gap)75 daysAudit-ready in 75 days, with the evidence already collected
SOC 2 Type I in 10 WeeksFrom $2,000 (gap)10 weeksA Type I report to unblock the deal, and a clean run at Type II
ISO 27001 Readiness in 16 WeeksFrom $3,000 (gap)16 weeksAn ISMS that survives Stage 1 and Stage 2
Quebec Law 25 Readiness Sprint NewFrom $6,0004 weeksLaw 25 obligations met, with a named privacy officer in place
Incident Response TabletopFrom $1,0001 dayA tested incident plan, and a team that has run it once
Fractional / Virtual CISOFrom $3,000/moOngoingSomeone senior accountable for security, without a full-time hire

Free 30-Minute Discovery Call

No commitmentFixed scope
$030 minutes
FormatVideo call
OutcomeHonest read on fit
Next stepScoped proposal or referral out

Tell us where you are, what’s on fire, and what you’ve already tried. We’ll tell you whether we’re the right team, point you at a fixed-price engagement if one fits, or refer you out if we’re not. No pitch deck.

Cloud Cost Audit - AWS, GCP, Azure

ProductizedROI in month 1
From $2,000CAD · 1 week
Avg. cloud waste~30 to 32%
Time to deliver5 business days
Engagement modelRead-only access + readout

According to the FinOps Foundation’s 2026 State of FinOps and Gartner, organizations waste an average of 30 to 32% of their cloud budget on idle resources, oversized instances, and architectural inefficiency. Whichever platform you run (AWS, Google Cloud, Azure, or a mix), we find it, quantify it, and hand you a prioritized remediation list ranked by dollars saved per hour of engineering time.

Deliverables
  • Billing & usage export ingestion (AWS CUR, GCP Billing export, or Azure Cost Management) and tag-hygiene review
  • Top-20 waste findings with annualized $ impact
  • Commitment modelling: Reserved Instances / Savings Plans (AWS), Committed Use Discounts (GCP), Reservations (Azure)
  • Right-sizing across compute, managed databases, storage, idle resources, and data egress
  • 30 / 60 / 90-day remediation roadmap
  • Executive readout deck

Technical Due Diligence Light

Pre-Series AVC-ready
From $4,500CAD · 5 business days
ScopeArchitecture & risk
Compares toFull TDD: $25k to $40k
AudienceVC partners & founders

Full Series A technical due diligence runs $25,000 to $40,000 and takes weeks. Most pre-Series A founders don’t need that. They need a credible 5-day “dipstick” covering architecture, code quality, scalability, and security gaps that a partner would actually flag. That’s what this is.

VCs see this report before the term sheet conversation. Founders use it to pre-empt diligence kill-shots and build a credible remediation plan.

Deliverables
  • Architecture review and dependency map
  • Code quality and test coverage assessment (read-only)
  • Scalability and reliability red flags
  • Security and compliance gap snapshot
  • Team structure and bus-factor assessment
  • VC-formatted executive summary + technical appendix

SOC 2 Type I in 10 Weeks

Point-in-time proof, fast
From $2,000gap analysis
TypeSOC 2 Type I
Time to deliver~10 weeks
Best whenA buyer needs proof now

What you pay us here is a fixed-scope gap analysis. Remediation, control implementation, and audit coordination are scoped as Phase 2 once the gap shows what you actually need, and the CPA auditor fee is separate. When a deal needs evidence quickly, a Type I report proves your controls are designed correctly at a point in time. We get you there in about 10 weeks, then you run the Type II observation window in parallel so you are never paying for two disconnected projects. See the full playbook in SOC 2 for Canadian SaaS.

Deliverables
  • Trust Services Criteria scoping and gap assessment
  • Policies, procedures, and evidence repository
  • Control implementation across IAM, change management, vendor risk, and IR
  • Auditor introduction and audit coordination
  • Audit-ready evidence package for the CPA firm's Type I attestation report

ISO 27001 Readiness in 16 Weeks

Global standard
From $3,000gap analysis
StandardISO/IEC 27001
Time to deliver~16 weeks to Stage 1
Best whenYou sell globally or into Europe

What you pay us here is a fixed-scope gap analysis. Remediation, control implementation, and audit coordination are scoped as Phase 2 once the gap shows what you actually need, and the CPA auditor fee is separate. We build the information security management system, the Statement of Applicability, the risk treatment plan, and the internal audit, and get you ready for the Stage 1 and Stage 2 certification audits in about 16 weeks. If you also need SOC 2, we scope both so the evidence is built once. See the full ISO 27001 implementation guide.

Deliverables
  • ISMS scope and Statement of Applicability
  • Risk assessment and risk treatment plan
  • Annex A control implementation
  • Internal audit and management review
  • Registrar introduction and Stage 1 and Stage 2 coordination

Incident Response Tabletop

Board-friendlyInsurance-ready
From $1,000CAD · 1 day
FormatHalf-day facilitated exercise
ParticipantsExec, eng, legal, comms
OutputAfter-action report

Cheap insurance the board loves. We facilitate a realistic scenario (ransomware, third-party breach, insider threat, or a custom one tied to your stack), walk your team through detection, containment, comms, and recovery, then deliver an after-action report your insurer and your board can both read.

Deliverables
  • Custom scenario tied to your threat model
  • Facilitated 3 to 4 hour exercise
  • Real-time injects and decision points
  • After-action report with prioritized gaps
  • 30-day remediation checklist

Fractional / Virtual CISO

Month-to-monthUnblocks enterprise deals
From $3,000CAD · per month
ModelFractional, scoped to need
OwnsYour security program
Led byA published security researcher

Executive security leadership without the $300K salary line. Your vCISO owns the security program, answers buyer and bank security questionnaires, sits in on customer security calls, and steers the compliance roadmap. Scoped to what you actually need, from a few hours a week to heavy involvement during an audit or a deal cycle. See the full Fractional CISO service.

Deliverables
  • Security strategy and 12-month roadmap
  • Security questionnaire and buyer-review response
  • Policy, risk register, and vendor-risk management
  • Board and investor security reporting
  • Compliance oversight across SOC 2, ISO 27001, and more

Compliance & AI readiness sprints

Done-for-you readiness for whatever framework your buyers or regulators ask for. Each starts with a fixed-scope gap analysis; remediation and audit coordination are scoped afterward, and any third-party auditor fee is separate. Every one is a door-opener into an ongoing program.

Readiness sprintPrice (CAD)Prepares you for
ISO 27001 ReadinessFrom $3,000 (gap)ISO 27001 certification audit
ISO 42001 (AI) Readiness NewFrom $3,000 (gap)ISO 42001 AI management system
AI GovernanceFrom $3,000 (gap)ISO 42001 / NIST AI RMF foundation
HIPAA ReadinessFrom $3,000 (gap)US health-data (PHI) obligations
PCI DSS ReadinessFrom $3,000 (gap)PCI DSS v4.0.1 assessment
NIST CSF AssessmentFrom $2,500 (gap)NIST CSF 2.0 posture & roadmap
GDPR ReadinessFrom $3,000 (gap)EU GDPR obligations
PIPEDA ReadinessFrom $2,500 (gap)Canadian federal privacy (PIPEDA)
CPCSC Level 1 & 2 ReadinessFrom $3,000 (gap)Government of Canada defence contracts
EU AI Act Readiness DeadlineFrom $3,000 (gap)EU AI Act high-risk obligations
Cyber Insurance ReadinessFrom $2,500 (gap)Cyber-insurance underwriting controls

Estimated CAD ranges live on each framework’s cost page (e.g. ISO 27001 cost, HIPAA cost, PCI DSS cost). Browse all services & offers or the framework guides.

Security & advisory services

Ongoing and project-based security work, each scoped to your environment. Testing and hands-on offensive work bring in our partner Lorikeet Security when an engagement calls for it.

ServicePrice (CAD)What it is
Vulnerability ManagementFrom $1,000/moContinuous scanning, triage, and remediation tracking
Threat & Risk Assessment (TRA)From $3,000Formal TRA for procurement and vendor reviews
Vibe-Coding QA & ReviewFrom $2,000Security review and testing of AI-built code
Incident Response RetainerFrom $500/moNamed responders and a contracted SLA
Cloud Security ReviewFrom $1,000AWS, GCP, and Azure posture and hardening
Auditor Management & AdvocacyFrom $2,000We manage the auditor relationship for you
Security Questionnaire CompletionFrom $1,000We complete SIG, CAIQ, VSA, and custom questionnaires
Trust Center SetupFrom $1,500A public trust page that speeds buyer diligence
Third-Party / Vendor RiskFrom $2,500Assess and monitor the vendors you rely on
AI Vendor Risk AssessmentFrom $2,000Assess third-party AI tools before you adopt them

All floors are starting points; every engagement is scoped to your environment. Browse all services & offers.

What you are actually buying

Most security firms sell you hours and tell you the total afterwards. Here the deliverable, the timeline, and the price are all agreed before anything starts.

01

You know the number before you commit

Defined scope, defined price, defined timeline. You can take it to your finance lead without a discovery call first, and procurement has something concrete to review instead of a statement of work that takes a quarter to negotiate.

02

The advice comes from having done the work

By the time an engagement finishes we know your stack, your team, and where you are actually exposed. If you want ongoing help after that, it is grounded in your environment rather than a generic maturity model. If you do not, you still keep the deliverable.

03

We will tell you when it does not fit

If your situation does not match a fixed scope, we say so on the call and quote it properly. We do not stretch a $4,500 engagement into a $40,000 statement of work, and we will tell you when you do not need us yet.

Pick one, or start with a call

Not sure which fits? Book the free 30 minutes and we will point you at the right one, or tell you it is not us.

Book a call

Frequently asked questions

Are your prices fixed or do they change per project?

The engagements listed with a price have defined scope and fixed pricing, so you know what you are buying. Broader advisory and ongoing work is scoped to your situation. We are clear up front about which is which before any work starts.

Do I just get a report at the end?

No. Every engagement produces a deliverable, and we walk you through what it means for your risk, your roadmap, and the buyers asking you for it. A report with no context is the thing you can already buy elsewhere for less.

Why fixed prices instead of hourly consulting?

Because an hourly meter makes the total unknowable until it is too late to plan around. A fixed scope means you know the deliverable, the timeline, and the cost before you commit. Where work genuinely cannot be fixed-scoped, we scope it openly rather than forcing it into a package.

Do you offer ongoing or retainer pricing?

Yes. Fractional CISO, fractional CTO, and incident response retainers are ongoing engagements scoped to your needs and cadence. We agree on scope up front and adjust as your requirements change, without locking you in for the sake of it.

How do I get an exact quote?

Book a call and tell us your situation, deadline, and what you are selling into. For anything listed with a price we can confirm scope quickly. For broader work we scope it and come back with a written proposal. No invented numbers and no pressure.