Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Cross-border practice

Windsor-Detroit
cross-border compliance.

Canadian companies selling into US enterprise get hit with SOC 2 and security asks the moment a Michigan or US buyer runs diligence. We treat the Windsor-Detroit corridor as one market: the SOC 2 that unblocks the US deal, plus dual PIPEDA and US privacy, with direct local presence rather than remote support.

Talk to us

One market, both sides of the river

Windsor sits across the river from Detroit and runs on cross-border manufacturing, automotive supply chain, and a tight-knit local tech scene. Most national consulting firms treat Windsor as remote support. We do not. We treat Windsor and Detroit as a single market, and the cross-border work that comes with it lives here.

01

SOC 2 for US enterprise buyers

The report your Michigan and US customers ask for in diligence, run end to end so the deal stops stalling on security.

02

Dual-jurisdiction privacy

PIPEDA on the Canadian side and US federal and state privacy, including Michigan, built into one control set so you do not build the same evidence twice.

03

Cross-border data and USMCA

Data flows, IP, and vendor arrangements that cross the border, handled with the corridor in mind rather than as an afterthought.

04

Local presence, Toronto-grade bench

Direct Windsor presence with no travel premium, backed by the same senior team and published-researcher depth as our Toronto work, including ongoing fractional CISO coverage once the program is live.

Where to go next

Selling across the border?

Tell us who is asking for SOC 2 and where your data flows, and we will scope the cross-border program against our productized pricing.

Book a Call

Frequently asked questions

Do you actually have a Windsor presence?

Yes. We have direct presence in Windsor and treat the Windsor-Detroit corridor as one market, rather than servicing it remotely from Toronto like most national firms.

We are Canadian but selling into the US. What changes?

The moment a US or Michigan buyer runs vendor diligence, you get SOC 2 and security questionnaires, and you have to handle privacy on both sides of the border. We run the SOC 2 that unblocks the US deal and the dual PIPEDA plus US privacy work together.

Can you handle both PIPEDA and US privacy law?

Yes. Cross-border data, PIPEDA, and US federal and state privacy (including Michigan) are the core of this practice. We build one control set that satisfies both jurisdictions so you are not doing the work twice.

Is this just your Windsor location page?

No. This is a named cross-border practice. The corridor, USMCA, dual-jurisdiction privacy, and US-buyer SOC 2 are a specific wedge we run as a practice, not a templated city page.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.