Price
Two levels. Answers, or the programme behind them.
Flat monthly, billed in advance. Ninety-day initial term, then cancellable on thirty days' notice. No setup fee. Both levels run on the same system — what changes is whether you are buying answers to the questions, or the documented programme that makes the answers true.
For a company whose deals are stalling on security questionnaires it has nobody to answer.
- Security questionnaires answered, in whatever format your customer sent
- 48-hour turnaround on business days
- Fair use of 8 per month — past that we talk about the right level rather than surprising you with a bill
- Every answer traced to something you can point at
- The AI sections your customers have started adding — training data, model governance, human oversight, who is accountable when a model gets it wrong
- Nothing claimed on your behalf that you could not defend
- Email support, next business day
- Written policy set
- Vendor reviews and gap tracking
For a company that needs to have a security programme, not just answer questions about one. If your questionnaires keep coming back "no", this is why.
- Everything in Questionnaire Response
- Written policy set, authored around your actual stack and size, maintained and reviewed annually
- Vendor security reviews, up to 10 per month
- Ranked gap list, updated monthly, ordered by what is costing you deals
- Quarterly access review pack, with the outcome recorded
- Monthly written update — what changed and what needs a decision
- Email support, next business day
| What is included | Questionnaire Response | Security Program |
|---|---|---|
| Security questionnaires | 8/mo | 8/mo |
| Turnaround | 48h | 48h |
| Every answer traceable to evidence | Yes | Yes |
| AI questionnaire sections | Yes | Yes |
| Email support | Next day | Next day |
| Written policy set | — | Yes |
| Vendor security reviews | — | 10/mo |
| Ranked gap list | — | Monthly |
| Quarterly access review pack | — | Yes |
| Monthly written update | — | Yes |
| Commitment | 90 days, then monthly | 90 days, then monthly |
Priced separately
Quoted before anything starts, and never begun without your written approval of the price.
Attendance on your customers' security calls — $500 per call
When a customer's security team wants to talk to whoever owns security, I will be on that call. Most companies need this once, at the point a large deal is being decided. It is priced per call rather than bundled so it happens when it is worth doing, instead of sitting unused in a retainer you are paying for every month.
Audit and formal assessment support
Evidence collection on a schedule, framework artifacts — SSP, Statement of Applicability, POA&M — and dealing with your auditor through fieldwork.
This is scoped and quoted per engagement rather than sold monthly, because the work runs on the auditor's timetable and not mine. If you have an audit booked, say so on the first call and I will tell you honestly whether the dates work. If they do not, I would rather say that than take the retainer and miss the deadline.
How billing works
- Billed
- Monthly, in advance
- Setup fee
- None
- Notice
- 30 days, in writing
- Initial term
- 90 days
- Fee changes
- At annual review only
- Your documents
- Yours to keep
What no level includes
Stated here rather than discovered later, and identical in both engagement letters.
Penetration testing
Not performed and not currently coordinated. If a customer or framework requires one, you engage a testing firm directly and I will help you read the report.
The audit itself
An auditor has to be independent of whoever prepared the work. I can get you ready for one; I cannot also be one.
Implementing technical fixes
Configuring MFA, deploying tooling and changing infrastructure stay with your engineers. I tell you what to fix and in what order, and I document that it was fixed.
Incident response during a live incident
Preparation, plans and post-incident write-ups, yes. Someone on a bridge call while an incident is running is a different service with a different price, and pretending otherwise would be the wrong kind of promise.
Legal advice and code review
Contract negotiation, regulatory representation, custom security engineering and code review are all outside scope.
Which one
- Questionnaires arriving, policies exist
- Questionnaire Response
- Questionnaires coming back "no"
- Security Program
- Audit or assessment booked
- Ask — quoted separately
- Not sure
- Ask. Moving up is easy; being sold the wrong one for six months is not.
Why the price is where it is
Both levels sit below the threshold where most companies convene a committee, which means one person can decide. That is deliberate.
It is lower than a consultancy because the documentation is generated rather than billed by the hour. What you are paying for is the judgement about what belongs in it — and for the one thing no system does, which is refusing to write down a control you do not actually have.