Services & Pricing

Fixed scope. Fixed price. Senior delivery.

Four ways to engage — each stands alone, each starts with a one-page proposal and delivers value inside the first ten days. No open-ended hourly billing, no surprise invoices.

Flagship engagement

AI Security Readiness Assessment

A defensible, board-ready answer to “are we safe to deploy AI?” — delivered in three weeks.

What you get

  • AI usage inventory — sanctioned tools, shadow AI, and the data each one touches
  • Threat model of your highest-stakes deployments: prompt injection, data leakage, agent misuse
  • Gap assessment against NIST AI RMF — the framework your board and auditors recognize
  • Governance policy pack, ready to adopt: AI acceptable use, vendor AI review, deployment standards
  • Prioritized remediation roadmap + an executive readout and board one-pager
For CISOs, CTOs, and VPs of Engineering at 200–2,000-person companies deploying copilots or shipping AI features.
$7,500–12,000
fixed · 2–3 weeks
Extended tier adds whole-company scope, an AI-incident tabletop, and a 30-day follow-up.
Start with a free walkthrough
Ongoing leadership

Fractional Security Leader (vCISO)

Senior security leadership on retainer — the function without the full-time headcount.

What you get

  • Ownership of your security roadmap and quarterly priorities
  • SOC 2 / ISO audit shepherding — policies, evidence, auditor management
  • Customer security questionnaires answered fast — unblock enterprise deals
  • Vendor and tooling decisions from someone who has operated them at scale
  • An escalation point when something breaks; board-level reporting every month
For funded startups (Series A–C) with no security hire, companies between security leaders, and MSPs needing CISO-tier depth.
From $4,000/mo
advisory · 3-month minimum
Begins with a paid 30-day baseline: risk snapshot, quick wins, and a 12-month roadmap. Active tier ($8,000/mo) for audit season or program stand-up.
Book a call
Fast diagnostic

Shadow IT & OAuth Risk Audit

Know exactly what has access to your data — in one week, for a fixed fee.

What you get

  • Inventory of every third-party app with OAuth access — publisher, scopes, users, last use
  • Risk classification of each app with plain-English rationale
  • The revoke-first list your IT admin can execute in an afternoon
  • Findings mapped to SOC 2 / HIPAA controls — the page your auditor asks for
  • A 60-minute findings readout with your team
For any company on Google Workspace or Microsoft 365 — especially pre-SOC 2 or post-offboarding.
$2,500
fixed · one week
Both tenants (hybrid Google + Microsoft): $3,500. $500 credits toward continuous monitoring within 30 days.
Book a call
Continuous assurance

Roust — Continuous Monitoring

The audit, always on. A snapshot ages the day it’s delivered; Roust keeps the answer current.

What you get

  • Scheduled scans of your tenant for new third-party access
  • Alerts on unverified publishers, broad scopes, and ex-employee tokens
  • Audit-ready monthly report for your compliance file
  • On-demand offboarding checks: “did anything of theirs survive?”
Read-only scopes · encrypted storage · 90-day retention · kill switch in your control. Learn more about Roust →
$1,000/mo
founding customers: $500/mo
First five customers lock $500/mo for 12 months. White-label available for MSP partners.
Learn about Roust
Not sure which fits?

Start with a 30-minute call.

Tell me what’s driving this — a board question, an audit, a customer demand — and I’ll point you to the right engagement, or tell you honestly if it isn’t one I should take.