Skip to content

Security and compliance

Owned software still has to pass the auditor.

Threat modelling, secure SDLC, SOC 2 and ISO 27001 control mapping onto the systems we build, evidence automation, and penetration test remediation. We tell you plainly where a vendor attestation is still the cheaper answer.

The premise

Owning the software does not exempt you from the auditor — it moves the obligation from a vendor attestation onto your own controls. That is a real cost, it is knowable in advance, and it belongs in the arithmetic before you decide to replace anything. It is also the area where we most often tell clients to keep paying a vendor.

Reference implementations

Attest is the compliance evidence reference implementation, and Keyring covers privileged access.

What you get

  • A threat model for the systems we build, in a form your security team can maintain, with the accepted risks written down and signed.
  • Secure SDLC in the pipeline rather than in a policy document: dependency scanning, static analysis, secrets detection, signed artefacts and a documented exception path.
  • A control mapping from SOC 2 or ISO 27001 to the specific technical controls in the running system, so an auditor question has one answer rather than a meeting.
  • Evidence automation: the artefacts a control requires, produced by the system on a schedule, stored where the auditor can be given access.
  • Penetration test coordination and remediation, with fixes landing as code and the retest arranged.
  • An incident response runbook rehearsed at least once, including the parts about who tells the customer.
  • A written statement of what an owned system does not give you compared with the vendor attestation you are giving up. That document is part of the deliverable, not a caveat.

How it runs

5 phases, each with a date attached.

Durations below are what this shape of work typically takes with a team of two to four. They move with scope, and the assessment is where they stop being typical and start being yours.

  1. 01

    Scoping and gap analysis

    2 to 3 weeks

    Which framework binds you, what evidence you produce today, and what changes when a system moves in-house. Ends with a gap list ordered by audit risk rather than by ease.

  2. 02

    Control design and mapping

    2 to 4 weeks

    Each control mapped to a technical implementation and an evidence source. Where a control cannot be satisfied without a vendor attestation, that is recorded as a finding, in writing, with our recommendation.

  3. 03

    Implementation

    4 to 6 weeks

    Pipeline controls, evidence automation, hardening and the threat model work, delivered as code alongside the system rather than bolted on after it.

  4. 04

    Test and remediate

    3 to 4 weeks including third-party testing

    Penetration test by an independent firm you choose, remediation as code, retest. We coordinate; we do not mark our own homework.

  5. 05

    Audit support

    Through the audit window

    We sit with your auditor, walk the evidence, and answer the technical questions. Where a finding lands against something we built, we fix it under the engagement.

What it costs

No rate card on this page, on purpose.

Priced per phase, and normally bought alongside a replacement rather than as a standalone programme. The gap analysis is worth buying on its own and frequently ends with us recommending you do not proceed.

The cost is driven by the framework, the scope boundary and whether you are certifying for the first time or extending an existing certification to cover a new system. Extending an existing ISO 27001 scope to one additional in-house application is modest. A first SOC 2 Type II for an organisation with no existing control environment is a programme, not a project, and the audit fee, the auditor and the observation window are yours and are not small.

We do not sell a compliance platform, we do not take a fee from an auditor, and we have no incentive to tell you that a control is satisfiable in code when it is not.

A published day rate would be a number we could not stand behind for your specific situation, and every firm that publishes one quotes something different in the room. What we will commit to before you sign is the phase scope, the phase price and the team shape. Use the calculator for the replacement arithmetic against your own seat count.

Normally bought inside

01

Guide

You have a dev team. We hand them the blueprint.

Fixed monthly. 3-month minimum.

03

Deliver

We take it end to end and hand over the keys.

Fixed price per phase. Run priced separately.

All three commercial models in full →

When not to buy this

3 reasons to walk away.

Every library entry has rows where the honest answer is no. Every service page has this section for the same reason: the cases below are ones we have seen go badly, and we would rather lose the work than deliver into them.

The attestation is what you are buying

If the reason you pay the vendor is that their SOC 2 report satisfies your customers, replacing them transfers that obligation to you. Sometimes that is right. Often it is not, and we will do the arithmetic on the control cost before you decide.

You need certification in under six months

A Type II needs an observation window that cannot be compressed. If a customer contract depends on a report by a fixed date, changing the underlying systems now is the wrong sequence.

You want a policy pack

We do the technical controls and the evidence they produce. If what you need is the document set and the questionnaire responses, a compliance firm will do it faster and cheaper than we will.

Pick one contract. We will show you the replacement.

A two-week assessment: we take your single most expensive SaaS line item, establish what you actually use, and come back with a parity matrix, an architecture for AWS and Azure, a cost model and a delivery plan. Fixed price. If the answer is keep buying it, we will tell you that.