Security & Compliance

The honest gap list.
Costed in engineer-days.

A fixed-fee assessment of where you actually stand against SOC 2 or ISO 27001:2022 — ending in a costed, sequenced remediation plan and a warm introduction to an auditor. We are not your auditor and legally cannot be, which is exactly why we can do this work.

$12,500
Fixed fee, single framework
2 weeks
Assessment to costed plan
$0
We take from any auditor
Trusted by 32+ teams shipping remote engineering, today
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Why it matters

Under ISO/IEC 17021 and the AICPA independence code, the body that certifies you is barred from having consulted you. That wall is permanent — and it means the readiness, implementation and remediation half of your compliance spend is work your auditor is legally forbidden to touch. We live on that side of the wall.

Benefits

Why teams choose us.

Fixed Fee, Fixed Scope

$12,500 for a single framework up to 150 people. You know the number before we start, and it does not move because we found more work.

Every Gap Priced

Findings without effort estimates are just anxiety. Each one comes back with engineer-days attached so you can fund it, sequence it, or decide it can wait.

Credited Against The Fix

The full assessment fee is credited against any remediation engagement. If you'd rather fix it yourself or use your incumbent, the register is yours to take.

No Auditor Kickbacks

We take no fee, commission or rebate from any auditor or certification body we introduce you to, and we confirm that in writing to you and to them.

What we offer

The full menu.

Control-By-Control Gap Register

  • Every control assessed, not sampled
  • Evidence pointers, not assertions
  • Severity and audit-blocking flags
  • Machine-readable export, yours to keep

Costed Remediation Plan

  • Every gap priced in engineer-days
  • Sequenced by audit-blocking impact
  • Build-vs-buy called on each item
  • Fundable as a budget line

Documentation Set

  • Statement of Applicability draft (ISO 27001)
  • System description draft (SOC 2)
  • Risk treatment plan
  • Scope boundary and asset inventory

Platform Configuration

  • Vanta or Drata configured to your scope
  • Policies mapped to controls
  • Integrations wired to real evidence
  • Dashboard that reflects reality, not defaults

Auditor Introduction

  • Shortlist matched to your buyer's expectations
  • Scope and fee pre-negotiated
  • Timeline aligned to your deal calendar
  • We brief them; you sign with them directly
How it works

Our process.

01

Scope & Evidence Request

We agree the framework, the system boundary and the trust criteria in a 60-minute call, then send one consolidated evidence request. No drip-feed.

02

Control Assessment

Control-by-control review against the actual standard text, with your cloud configuration, IAM, logging and SDLC inspected rather than surveyed.

03

Costing & Sequencing

Every gap sized in engineer-days and ordered by what blocks the audit. You get the plan you can take to your board or your investor.

04

Walkthrough & Handover

Sixty-minute walkthrough, the register in machine-readable form, and warm introductions to two auditors with scope and fee already agreed.

Tech stack

What we build with.

Frameworks
SOC 2 Trust Services CriteriaISO/IEC 27001:2022ISO/IEC 27002CIS Benchmarks
Platforms
VantaDrataSprintoScrut
Infrastructure
AWSGCPAzureTerraformGitHub Actions
Comparison

What sits on each side of the independence wall

Your auditor
withRemote
Issues the report or certificate
Your auditor: Yes — only they can
withRemote: Never. Legally barred
Designs and implements controls
Your auditor: Legally forbidden
withRemote: Yes — this is the work
Writes your policies
Your auditor: Cannot without losing independence
withRemote: Yes
Configures your cloud and CI
Your auditor: No
withRemote: Yes
Accepts residual risk
Your auditor: No
withRemote: No — that stays with you
By jurisdiction

Which framework applies where

A readiness assessment is artefact delivery — the output is a document, and it can be scoped to touch no personal data at all.

United StatesDeliverable

The best fit for this service anywhere. SOC 2 is a binary sales gate, 15,000–20,000 reports are issued a year, and California's CPPA cybersecurity audit and risk-assessment regulations took effect 1 January 2026 — with pre-2026 risk assessments due 31 December 2027 and the first audit certifications 1 April 2028.

The CPPA regime carries the same independence structure as SOC 2: the auditor cannot perform the remediation. NYDFS Part 500 fully phased in November 2025.

United KingdomDeliverable

ISO 27001:2022 is the usual target, and the 2013 certificates expired on 31 October 2025 — which has pushed a re-certification wave through 2026. Cyber Essentials readiness is a separate service, because the Danzell question set is a different scope.

We are not an IASME-licensed certification body and cannot issue a Cyber Essentials certificate. We do not take UK public-sector work: it requires contractual UK data residency, SC clearance and CE Plus under G-Cloud 15, none of which offshore delivery can satisfy.

European UnionConstrained

NIS2 has no certification and no accredited auditor, so ISO 27001 is the de facto evidence artefact — and there is no independence barrier on any of the work.

Twenty-seven national regimes, fragmented: the Commission referred Ireland, Spain, France and the Netherlands to the CJEU on 8 July 2026 for failure to transpose. We deliver in English only, and NIS2 buying often happens in German, French, Italian, Dutch or Spanish.

UAE & GCCDeliverable

Full scope on the mainland. NESA / UAE IA runs to 188 controls — 60 management, 128 technical — and DESC ISR v3 adds thirteen domains on top of ISO 27001:2022.

Where the client is a DIFC or ADGM entity, the free zones are as strict as the EU on transfers and neither lists India as adequate. Saudi Arabia we take only as pull-through from a UAE client, under the UAE contract — NCA ECC-2 effectively requires an in-Kingdom presence.

Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.

Right fit?

Choose this if...

You have lost or delayed a deal on a security review
An enterprise buyer, investor or renewal has put a date on it
You are re-certifying against ISO 27001:2022 after the 2013 certificates expired
You want the gap list before you commit to a platform subscription and an audit fee
Right fit?

Honest about who this is for.

Pick us if

This will be a fit.

  • You want to know the real number before you commit a budget
  • You want to hear 'this control is fine, skip it' where it is true
  • You have a date attached — an audit window, a renewal, a board deadline
  • You want the findings register in a form you can take anywhere
Skip us if

Honestly — not our zone.

  • You want us to be your auditor — we cannot be, and neither can any firm that helps you implement
  • You want a certificate at the end of this. This produces a plan, not a certificate
  • There is no deadline and no budget yet — the assessment will sit on a shelf
  • You are a healthcare company needing us inside the PHI estate. We currently scope those engagements as no-PHI-in-scope, which usually removes most of the value
FAQ

Common questions, straight answers.

Are you our auditor?

No, and we legally cannot be. Only a licensed CPA firm can attest SOC 2, and only a UKAS- or ANAB-accredited body can certify ISO 27001 — and that body is barred from certifying anyone it consulted. That independence wall is precisely why the readiness and implementation work is available to us at all.

Do you get paid by the auditors you introduce?

No. We receive no fee, commission, rebate or other consideration from any auditor or certification body we refer you to, and we confirm that in writing to both you and them. You contract with them directly.

You sell the fix. Won't you inflate the finding count?

That is the fair objection, and the answer is built into the terms: the assessment fee is credited in full against any remediation work, and the findings register is yours in machine-readable form to take to any provider, including your incumbent. We'll hand it over and brief them at no charge.

We already have Vanta. Do we still need this?

Vanta tells you a control is failing and generates guidance. It does not tell you what it costs to fix, in what order, or which findings actually block your audit. If your dashboard is red and nobody on your team knows what to do about it, that gap is what this closes.

Is withRemote certified?

Not yet. We are working toward ISO 27001 certification of withRemote itself, and we publish the scope statement, certification body and stage dates as they land. You will find it here before you find it in a vendor questionnaire.

What does this not include?

It is not an audit, an attestation, a certificate or an assurance opinion, and those words appear nowhere in the deliverable. We design and hand over controls; we do not operate them, sign them off, or accept the residual risk. Penetration testing, where an auditor expects one, is referred to a named CREST-accredited partner and disclosed as a subcontract.

From $12,500· The honest gap list, costed in engineer-days

Ready to start?

Book a free 25-minute call. We'll scope the work, share examples, and send a plan within a week.

What else we do

One contract covers any of these.

Everything below runs on the same agreement, the same invoice and the same account team as Compliance Readiness Assessment.

Security & Compliance

Compliance Remediation Pod

Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.

From $15,000/mo
Security & Compliance

Agent Security & AI Governance Review

A fixed-scope review of a production agent or RAG system: what it can reach, how it gets abused, and how to rebuild it so the finding stops recurring. It ends with the AI-governance evidence pack your enterprise buyer is asking for, and the remediation shipped as pull requests.

From $18,000
Tech & Dev

Agentic AI Development

Custom AI agents, LLM integrations, RAG pipelines, and intelligent automation built into your product. On the Secure Build tier, every agent ships with a threat model, tool-permission scoping, guardrails, and an adversarial eval suite running in your CI.

From $5,000/mo
Talent

Direct Hire

We source, vet, and shortlist senior engineers from a 100,000+ pool. You interview, offer, and own the employment.

$1,499 / hire
Marketing

Managed Growth

The whole digital operation for a business people physically visit — website built and maintained, SEO, AEO, GEO, Google Ads, email, campaigns, lead gen, and the automations behind them. One team, one fee, and ad spend passed through to the platforms at cost.

From $5,000/mo
Design

Graphic & Design Services

Brand systems, marketing collateral, and design-on-demand for product, social, and sales.

From $2,500/mo
All 18 services
WhatsApp us