Services
Every recurring job in your security program, grouped by family. Each one runs read-only in your environment, an expert reviews every finding, and nothing changes without your approval.
Entry
Two weeks across identity, cloud, and key SaaS apps, with a prioritized plan.
Once, over two weeks
Identity and access
Identity AssuranceFeatured
Access reviews that finish, every quarter.
Monthly or quarterly
Shadow IT and Shadow AI Discovery
Find the apps and AI tools nobody approved.
Monthly
Cloud and application
Misconfigurations and waste, checked monthly.
Monthly
Threats ranked before the code ships.
Per application or major release
Who owes which patch, and since when.
Monthly
WAF and Logging Posture Review
Coverage gaps at your edge and in your logs.
Monthly or quarterly
Threat and resilience
Only the threats that touch your stack.
Weekly or monthly
Plans, runbooks, and tabletops built on your systems.
Annual plan, quarterly tabletops
Governance and risk
Policies that match how you actually operate.
One-time build, then annual review
Vendor reports read, judged, and followed up.
Ongoing, by vendor tier
Rules and an inventory for the AI your team already uses.
One-time setup, then quarterly review
Audit and Questionnaire Support
Evidence organized, answers drafted for your approval.
On demand
People
Phishing tests and lessons drawn from your own findings.
Monthly or quarterly
Bundle
The services you choose, run as one program with a risk register and a monthly leadership brief.
Monthly subscription
Not sure where to start?
The two-week Security Program Assessment shows which services your program needs first. Fixed scope and fixed fee, agreed in writing before we start.