Security & Compliance

Keep your Vanta. Keep your auditor.
We ship the fixes.

Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.

$40k–$70k
Of a year-one programme no auditor may touch
2–3
Engineers per pod
0
Audits we perform
Trusted by 32+ teams shipping remote engineering, today
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Why it matters

A SOC 2 Type II observation window cannot start until controls are actually operating. Every week of unremediated findings pushes the report — and the enterprise contract waiting on it — a week further out. The platform generates the ticket, the auditor is barred from closing it, and the work lands on a product team already behind on roadmap.

Benefits

Why teams choose us.

Engineers, Not Advisors

We write the Terraform, wire the SSO, stand up the log retention and ship the CI gates. You get commits, not a recommendations deck.

Your Change Process

We write the change; your named approver merges it, inside your change window, with a documented rollback. Nothing lands in production on our authority.

Evidence In Their Format

Every fix is written back to your compliance platform as evidence, and we take the auditor's questions directly during fieldwork.

Month-To-Month

No annual lock-in. A typical programme runs four months, and the pod converts to permanent headcount whenever you want to own it.

What we offer

The full menu.

Identity & Access

  • SSO and SCIM rollout
  • MFA enforcement across the estate
  • Least-privilege IAM refactor
  • Quarterly access reviews, automated

Logging, Encryption & Retention

  • Centralised logging with retention policy
  • Encryption at rest and key management
  • Backup and restore testing, evidenced
  • Delivered as infrastructure-as-code

Secure SDLC & CI/CD

  • Security gates in the pipeline
  • Secret scanning and rotation
  • SAST/SCA with a triage owner
  • Dependency and base-image policy

Contractor & Offboarding Controls

  • Asset retrieval process, documented
  • Same-day access revocation on exit
  • Joiner-mover-leaver runbook
  • The 2022 SOC 2 points of focus, closed

Audit Liaison

  • Evidence written back to your platform
  • Auditor questions answered directly
  • Fieldwork support during the window
  • Weekly progress your auditor can read
How it works

Our process.

01

Backlog Triage

Your findings — ours, your platform's, or your auditor's — land in your tracker, deduplicated, owned and sequenced by what blocks the observation window.

02

Pod Starts

Two or three engineers plus a named principal for the auditor-facing conversation. Weekly demo, weekly written progress, your sprint cadence.

03

Ship & Evidence

Each control closed, evidenced, and written back to your platform. We do not mark a control done until the evidence would survive fieldwork.

04

Hand Over Or Keep

At the end you either take the runbooks in-house, or convert the pod to permanent managed headcount at EOR rates.

Tech stack

What we build with.

Infrastructure
TerraformAWS IAMGCPAzureKubernetes
Code & Pipeline
SemgrepSnykTrivyGitHub ActionsGitLab CI
Compliance
VantaDrataCIS BenchmarksSOC 2 TSCISO 27001:2022
Comparison

Who does what in a compliance programme

Platform
Auditor
withRemote
Flags the failing control
Platform: Yes
Auditor: Yes
withRemote: Yes
Generates remediation guidance
Platform: Yes
Auditor: No
withRemote: Yes
Writes the Terraform
Platform: No
Auditor: Legally barred
withRemote: Yes
Rolls out SSO / SCIM / MFA
Platform: No
Auditor: Legally barred
withRemote: Yes
Issues the report
Platform: No
Auditor: Yes — only them
withRemote: Never
By jurisdiction

Where a pod can operate

This is the service with the most production-data contact, so it carries the most jurisdictional constraint. We would rather set that out here than in a diligence call.

United StatesDeliverable

The best fit anywhere. Fourteen of our sixteen core services are unconstrained here, rates are the highest in the portfolio's addressable set, and no US privacy regime imposes data localisation.

Closed: US federal, ITAR/EAR and CUI environments — those restrictions are structural, not procedural. Healthcare is scoped no-PHI-in-scope, which usually removes most of the value, so we will normally decline rather than sell you something thin.

United KingdomConstrained

Deliverable for private-sector clients, contracted as fixed-scope, change-controlled projects — never as ongoing administration.

That wording is deliberate. The Cyber Security and Resilience Bill defines a relevant managed service provider to include firms providing ongoing support, maintenance, monitoring or active administration of a customer's systems accessed remotely, with 24-hour incident reporting and fines to £17m or 4% of global turnover. Project framing keeps the engagement outside that definition.

European UnionConstrained

Possible as a fixed-scope engineering project from our US entity, with no managed-service framing and no ongoing administration.

Every EU deal carries a per-deal legal cost no other market imposes: an Article 28 processor agreement, SCC Module 2 or 3, a documented Transfer Impact Assessment and supplementary measures, because India has no EU adequacy decision and the published timeline puts a possible decision no earlier than 2028–29. Expect us to say the CRA product-readiness engagement is the better first step.

UAE & GCCConstrained

Deliverable for mainland commercial clients. This is our second-priority market and the Dubai office fronts delivery.

Closed outright where hard localisation applies: health data may not be processed or transferred outside the UAE, financial-services customer data must stay in-country, and DESC ISR v3 requires in-country processing for Dubai government data and regulated-sector pipelines.

Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.

Right fit?

Choose this if...

You have a findings backlog nobody on the team has time to close
Your Type II observation window cannot start until controls operate
Your engineers are the bottleneck, not your budget
You want to keep your existing platform and auditor exactly as they are
Right fit?

Honest about who this is for.

Pick us if

This will be a fit.

  • You have a compliance platform and an auditor already, and just need the work done
  • You want commits and evidence, not a recommendations deck
  • You are comfortable with your own approver merging every production change
  • You would consider converting the pod to permanent headcount later
Skip us if

Honestly — not our zone.

  • You want us to sign off on control adequacy or guarantee an audit outcome — we do not and cannot
  • You want monitoring, detection or incident response. We sell none of those and carry no response SLA
  • You want penetration testing under our name — that is referred to a named CREST-accredited partner
  • You need production changes made without a named approver on your side
FAQ

Common questions, straight answers.

Do you replace our compliance platform or our auditor?

Neither. Keep both. We are the layer nobody else occupies: the engineering that closes what the platform flags and the auditor is legally forbidden to touch. We work alongside Vanta, Drata, Sprinto and any CPA firm or certification body you have chosen.

Who merges changes to our production environment?

You do. We write the change; your named approver merges it, inside a change window you control, with a documented rollback. Our liability for business interruption arising from changes you approved is excluded — and we say that up front because the dominant risk on this work is an outage, not a breach.

Do you do penetration testing?

Not under our own name. We hold no CREST or CHECK accreditation and will not imply otherwise. Where your auditor expects a test, we refer a named CREST-accredited partner and disclose the subcontract to you in writing. We handle the scoping and every fix that comes out of it.

Will you guarantee we pass the audit?

No. Nobody honest will. We close the controls, evidence them in the format the auditor asked for, and take their questions during fieldwork. The opinion is theirs to issue and the residual risk is yours to accept.

How long does a programme run?

Typically four months at $15,000/mo for a two-engineer pod, or $21,000/mo for three. That lands squarely inside the $40k–$70k of a year-one compliance programme that no accredited firm is permitted to deliver.

What happens at the end?

You take the runbooks and infrastructure-as-code in-house, or convert the pod to permanent managed engineers at EOR rates. Most clients keep at least one seat — the controls need an owner after the certificate lands.

From $15,000/mo· Keep your Vanta. Keep your auditor. We ship the fixes.

Ready to start?

Book a free 30-minute call. We'll scope the work, share examples, and send a plan within a week.

Related

More from this category

Compliance Readiness Assessment
The honest gap list, costed in engineer-days
Agent Security & AI Governance Review
Answer the AI questionnaire, fix what it exposes
Cyber Essentials Readiness (UK)
Pass Danzell first time, or find out why now