FAQ

  • Are you a CMMC 3PAO?

    Not officially, not yet. But while we await the certification, we can offer high expertise at a low cost for readiness assessments as a prudent preparation for your official assessment.

  • Are you a PCI QSA?

    Not yet, it’s on our roadmap. But we can help get you ready beyond what a QSA can do. A QSA is not allowed to design your systems or to help you fix any findings, we can. A QSA is obligated to report all findings to the PCI Council, while we are not. This means our readiness assessments provide your team with an actionable list of pitfalls, and we can help you solve them, before your QSA comes in.

  • Can you help us with our Encryption Strategy?

    Absolutely! We will identify your encryption needs based on your actual business and help your team operationalize it. From Keys & Secrets Management, CI/CD pipelines, Vaulting, Certificate Authorities, High Security Appliances, and Post-Quantum Encryption, we dive deep into all your needs and get after it for you!

  • Do you perform pentesting?

    We have broad experience in pentesting many different tech stacks. We are happy to discuss your needs and come up with a meaningful plan of action for your company. Our initial consultation discussions are free of charge.

  • Can you help us stand up our GRC department?

    Yes, of course! We can provide you with custom policies, technical standards, SSP’s, SOP’s, SAR’s, etc right-sized for your business and your security maturity goals. We can help define processes, tooling, knowledge bases and training materials. We are here to help you make order out of chaos.

  • Can my organization afford your services?

    We will work with you on the budget that provides the best value for you. While we can’t work for free, we believe in building a relationship of trust for your long term success. Our rates are very reasonable and we want you to feel you are receiving good value.