Security & Compliance

The internal audit
your certification body isn't allowed to do.

ISO 27001 requires an internal audit and a management review every single year, and your certification body is barred from performing either. We run them, resolve control drift before it reaches the auditor, and hold your evidence current through surveillance.

12 mo
A SOC 2 report stays useful
3 yrs
ISO 27001 cycle, audited annually
Month 11
When most teams discover the drift
Trusted by 32+ teams shipping remote engineering, today
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Why it matters

Teams sprint to the certificate, then stop. Eleven months later the surveillance audit appears, the access reviews have not been run, half the policies are unversioned and the evidence is stale. The certificate is the start of the obligation, not the end of it — and the body that issued it is not permitted to help you keep it.

Benefits

Why teams choose us.

Mandatory, And Structurally Yours

ISO 27001 requires an internal audit and management review annually. Your certification body cannot perform them without losing its impartiality. Somebody has to, and it is not them.

Drift Resolved, Not Reported

We do not just flag that the quarterly access review slipped. We run it, evidence it, and put it back on a cadence that survives your next headcount change.

Contracted On The Surveillance Cycle

The risk is not the first audit — it is the second. We contract around the surveillance date, so the work is done before the auditor asks, not after.

Advisory, Explicitly

We track and advise. You retain all decision and risk-acceptance authority in writing. This is not a vCISO service and we do not pretend it is.

What we offer

The full menu.

Internal Audit & Management Review

  • Annual internal audit against the standard
  • Management review pack and minutes
  • Nonconformity log and corrective actions
  • Evidence your certification body cannot produce for you

Control Drift Management

  • Access reviews run on cadence
  • Control operation evidenced continuously
  • Failing controls resolved, not just logged
  • Change and exception tracking

Policy Lifecycle

  • Scheduled review and versioning
  • Exception register with owners and expiry
  • Approval trail that survives fieldwork
  • Updates on standard revisions

Audit Liaison

  • Evidence defence during fieldwork
  • Auditor questions answered directly
  • Surveillance readiness check pre-audit
  • Findings closed before the next cycle
How it works

Our process.

01

Baseline

We inherit your certified ISMS or SOC 2 programme, verify what is actually operating, and mark the drift that has already accumulated.

02

Cadence

Access reviews, evidence refresh, policy reviews and risk reassessment placed on a calendar that maps to your surveillance date.

03

Internal Audit

Full internal audit against the standard, plus the management review pack — the two artefacts your certification body is not allowed to produce.

04

Surveillance

Readiness check before fieldwork, then evidence defence during it. Findings close inside the cycle, not the next one.

Tech stack

What we build with.

Standards
ISO/IEC 27001:2022ISO/IEC 27002SOC 2 Trust Services Criteria
Platforms
VantaDrataSprintoJiraConfluence
By jurisdiction

The one service with no jurisdictional constraint

An internal audit and management review are first-party activities. The ISO/IEC 17021 independence bar applies to the certification body, not to the firm running your internal audit — so this sells identically everywhere.

United StatesDeliverable

Full scope for ISO 27001 internal audit, and for SOC 2 programme maintenance across the reporting cycle. A SOC 2 report is useful for roughly twelve months.

United KingdomDeliverable

Full scope for private-sector clients. Contracted as advisory, which is what it is: we track and advise, and you retain all decision and risk-acceptance authority in writing.

European UnionDeliverable

Full scope. Because the artefacts are documents rather than production access, the engagement can be scoped to zero personal data, which removes the transfer problem that constrains our other services here.

UAE & GCCDeliverable

Full scope. It maps cleanly onto DESC ISR v3, which extends rather than replaces ISO 27001:2022, and onto the recurring assessment cadence NESA expects.

Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.

Right fit?

Choose this if...

You are certified or attested and nobody owns keeping it true
Your surveillance audit or Type II renewal is inside twelve months
Your compliance lead left and the programme went with them
You want the internal audit run by someone other than the body that certified you
Right fit?

Honest about who this is for.

Pick us if

This will be a fit.

  • You already hold ISO 27001 certification or a SOC 2 report
  • You want the mandatory internal audit and management review run properly
  • You want control drift found in month three, not month eleven
  • You accept that decision and risk-acceptance authority stays with you
Skip us if

Honestly — not our zone.

  • You want a vCISO or a named security leader — that is a different purchase and we do not sell it
  • You want monitoring, detection or a response SLA. This retainer carries none
  • You are not yet certified. Start with a Compliance Readiness Assessment instead
  • You want us to accept the residual risk. We track and advise; we never ensure
FAQ

Common questions, straight answers.

Why can't our certification body just do the internal audit?

Impartiality rules. Under ISO/IEC 17021 a certification body may not consult on the management system it certifies, and the internal audit is part of that system. It is a mandatory annual requirement that the people auditing you are structurally forbidden to perform for you.

When is the right time to start?

At certification, not at kickoff. The failure mode is universal: teams sprint to the certificate, disband, and rediscover the programme in month eleven when the surveillance audit appears. Contract on the surveillance cycle and the work is already done when the auditor arrives.

Is this a vCISO service?

No, and the distinction matters. A vCISO is a seniority-and-trust purchase with a named security leader attached. This is programme maintenance and the mandatory internal audit. If you need a CISO, hire one — we will help you find them.

Who runs the internal audit?

A named GRC lead, working to the ISO 19011 auditing guidelines, with the working papers and the nonconformity log handed to you. You see who did the work and what they looked at — not a summary.

Are your certification body's fees included?

No. Their fees are separate and quoted by them, and we will tell you roughly what they are before you sign with us. We take no fee, commission or rebate from any auditor or certification body.

What is not included?

It is advisory. We track and advise, we never ensure or maintain on your behalf, and you retain all decision and risk-acceptance authority in writing. No monitoring, no detection, no incident response, no availability or response SLA.

From $3,500/mo· The internal audit your certification body can't do

Ready to start?

Book a free 25-minute call. We'll scope the work, share examples, and send a plan within a week.

What else we do

One contract covers any of these.

Everything below runs on the same agreement, the same invoice and the same account team as Compliance Programme Retainer.

Security & Compliance

Compliance Readiness Assessment

A fixed-fee assessment of where you actually stand against SOC 2 or ISO 27001:2022, ending in a costed, sequenced remediation plan and a warm introduction to an auditor. We are not your auditor and legally cannot be — which is exactly why we can do this work.

From $12,500
Security & Compliance

Compliance Remediation Pod

Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.

From $15,000/mo
Tech & Dev

Agentic AI Development

Custom AI agents, LLM integrations, RAG pipelines, and intelligent automation built into your product. On the Secure Build tier, every agent ships with a threat model, tool-permission scoping, guardrails, and an adversarial eval suite running in your CI.

From $5,000/mo
Talent

Direct Hire

We source, vet, and shortlist senior engineers from a 100,000+ pool. You interview, offer, and own the employment.

$1,499 / hire
Marketing

Managed Growth

The whole digital operation for a business people physically visit — website built and maintained, SEO, AEO, GEO, Google Ads, email, campaigns, lead gen, and the automations behind them. One team, one fee, and ad spend passed through to the platforms at cost.

From $5,000/mo
Design

Graphic & Design Services

Brand systems, marketing collateral, and design-on-demand for product, social, and sales.

From $2,500/mo
All 18 services
WhatsApp us