Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Canadian companies selling into US enterprise get hit with SOC 2 and security asks the moment a Michigan or US buyer runs diligence. We treat the Windsor-Detroit corridor as one market: the SOC 2 that unblocks the US deal, plus dual PIPEDA and US privacy, with direct local presence rather than remote support.
Talk to usWindsor sits across the river from Detroit and runs on cross-border manufacturing, automotive supply chain, and a tight-knit local tech scene. Most national consulting firms treat Windsor as remote support. We do not. We treat Windsor and Detroit as a single market, and the cross-border work that comes with it lives here.
The report your Michigan and US customers ask for in diligence, run end to end so the deal stops stalling on security.
PIPEDA on the Canadian side and US federal and state privacy, including Michigan, built into one control set so you do not build the same evidence twice.
Data flows, IP, and vendor arrangements that cross the border, handled with the corridor in mind rather than as an afterthought.
Direct Windsor presence with no travel premium, backed by the same senior team and published-researcher depth as our Toronto work, including ongoing fractional CISO coverage once the program is live.
Tell us who is asking for SOC 2 and where your data flows, and we will scope the cross-border program against our productized pricing.
Book a CallYes. We have direct presence in Windsor and treat the Windsor-Detroit corridor as one market, rather than servicing it remotely from Toronto like most national firms.
The moment a US or Michigan buyer runs vendor diligence, you get SOC 2 and security questionnaires, and you have to handle privacy on both sides of the border. We run the SOC 2 that unblocks the US deal and the dual PIPEDA plus US privacy work together.
Yes. Cross-border data, PIPEDA, and US federal and state privacy (including Michigan) are the core of this practice. We build one control set that satisfies both jurisdictions so you are not doing the work twice.
No. This is a named cross-border practice. The corridor, USMCA, dual-jurisdiction privacy, and US-buyer SOC 2 are a specific wedge we run as a practice, not a templated city page.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.