Services: SOC 2, ISO 27001, cloud security

Fractional CISO services for startups

Five productized engagements that take you from "we need SOC 2" to audit-ready and beyond. One senior practitioner owns the outcome, on a fixed scope or a monthly retainer.

Founder-led engagements. Fixed scopes, fixed prices. You work with the practitioner, not a bench. All prices in USD.

1

Book a scoping call

A 30-minute call to understand what triggered the need and what a good outcome looks like. You leave with a clear path, not a sales pitch.

2

Get the plan

A fixed-scope, fixed-price assessment turns your gaps into a prioritized roadmap with owners and effort estimates, executable with us or without us.

3

Get a security leader

The monthly retainer puts a senior practitioner in your corner: they run your compliance program, face your auditors, and answer your customers.

Security Questionnaire Rescue

from $1,500

Fast turnaround, fixed scope

A customer sent a security questionnaire and your deal is stalled.

  • Every questionnaire item answered accurately
  • Real gaps flagged plainly, not papered over
  • A short punch list of fixes worth making before the next one

Audit-Readiness Gap Assessment

$6,000 to $9,000

2 to 3 weeks, fixed scope

Teams facing their first SOC 2 or ISO 27001 readiness engagement.

  • Control-by-control gap analysis against your target framework
  • Prioritized remediation roadmap with an owner and effort estimate per item
  • An evidence baseline collected from your actual stack
  • Executive readout for your board or lead investor

SOC 2 Readiness Sprint

$12,000 to $20,000

3 to 4 weeks, fixed scope

Companies committed to SOC 2 who want it run end to end.

  • Scoping across the trust criteria that apply to you
  • Control implementation mapped to your stack
  • Evidence process that proves controls held for the audit window
  • Auditor selection and audit liaison
Most popular

Fractional CISO Retainer

Essentials $4,000/mo, Growth $7,000 to $7,500/mo, Command $10,000 to $12,000/mo

Monthly retainer

Startups that need a security leader, not a full-time hire.

  • A named senior practitioner as your acting security lead
  • Your compliance program run inside the tools you already use
  • Auditor selection and audit liaison, end to end
  • Customer security questionnaires answered for you
  • Board and investor-facing security reporting

Cloud Security Review

$2,500 to $5,000

1 to 2 weeks, standalone or add-on

Teams who want configuration truth before an auditor or customer finds it.

  • Access, networking, logging, and exposure reviewed by hand
  • Prioritized findings with fixes, not just findings
  • A short readout you can hand to your team or board

Why one accountable practitioner beats a tool or a bench.

DIY plus a toolTraditional consultancyXorabyte
Who does the workYour engineers, nights and weekendsTheir bench, at their paceOne senior practitioner, hands on
Cost shapeA tool subscription, plus your team quarterSeveral hundred dollars an hour, meter always runningFlat, fixed scopes and monthly retainers
Who owns the outcomeOn youShared at bestOne accountable owner
New software to learnYou learn and run the toolVariesNone, we work in your tools

Questions founders actually ask.

Do we have to buy new software?

No. We work inside the tools you already use, including a compliance platform such as Vanta or Drata if you have one. The deliverable is the outcome: an audit-ready program, not software.

Which frameworks do you cover?

SOC 2 and ISO 27001 are the core. HIPAA and PCI DSS engagements are scoped case by case, and GDPR or Law 25 readiness can be added to a retainer.

How fast can we be audit-ready?

It depends on your gaps, typically 8 to 16 weeks from gap assessment to audit window. The assessment gives you a dated plan. We do not promise pass guarantees; auditors decide audits.

Who will we actually work with?

The practitioner who scopes your engagement is the one who runs it. Founder-led means exactly that: no handoff to a junior bench after the contract is signed.

Start with a call.

Tell us what triggered the need. You leave the first call with a clear path to audit-ready, not a quote you cannot read.