Security leadership, on retainer
vCISO for SaaS
Senior security leadership for growth-stage SaaS teams that need a security programme before a full-time CISO makes sense.
SOC 2 readiness, customer security questionnaires, cloud security review, vendor risk, and board reporting in one engagement instead of three vendors.
Trusted for
One Engagement
Instead of 3 vendors
SOC 2 readiness
Gap analysis through auditor fieldwork
Customer questionnaire
Answered and defended on the buyer call
Cloud security review
IAM, keys, logging, prod controls
Vendor risk
Reviews your buyers will accept
PRICING
Fixed monthly, quoted upfront.
SCOPE FOR SAAS
Security has become a sales problem
Your first enterprise buyer changed what security means to your business. It used to be a risk question. Now it is a revenue question: a deal sits in procurement, a questionnaire lands in your CTO's inbox, and the buyer wants to speak to a CISO you do not have.
Hiring one costs more than most Series A companies will spend on it, and takes months you do not have. A compliance platform gives you a dashboard, not a programme. What is missing is the person who owns the outcome
That’s the role we fit

WHAT WE DO
What we do for SaaS specifically
01
SOC readiness
Gap analysis, policies written against your actual stack, evidence collection, and auditor support through fieldwork. Not template policies you rewrite at the first audit.
02
Customer security questions
We answer the technical questions, defend them on the call with the buyer's security team, and keep your responses current as your controls change. Your CTO goes back to shipping.
03
Cloud security review
IAM, storage exposure, key management, logging and monitoring, secrets handling, and the pre-prod-to-prod controls auditors look at. Prioritised when cloud controls block the audit.
04
Security roadmap tied to pipeline
A 12-month plan ordered by which gaps block which deals, and when to add ISO 27001 or HIPAA as customer demand surfaces them.
05
Board and investor reporting
A quarterly security update your board can read and diligence-grade documentation for your next round.
06
Insident report leadership
Runbooks, tabletop exercises, and someone to call when something happens.
Ready to move faster?
Too much to do,
too important to ignore.
Start with a 30-minute discovery call. If we're not the right fit, we'll tell you and point you in the right direction. If we are, we'll leave the call with a clear plan to get you up and running.
TIMING
When to engage
Your sales motion is blocked on a questionnaire
A buyer's security team sent 180 questions, wants a SOC 2, and asked to speak to your CISO.
Your board asked for a security programme
A platform gives them a percentage. They asked for a roadmap and a narrative.
Your auditor found things you did not know about
You have a report you cannot decode and an attestation slipping by weeks.
You have Type I and now need Type II
Type I closed the deal. Type II is an observation window where evidence has to keep accumulating and controls have to keep operating.
FRAMEWORKS
Frameworks we run for SaaS
SOC 2 Type I & II
The default enterprise procurement requirement in North America. Type I proves design; Type II proves it held over time.
ISO 27001
The international equivalent — usually what European and global enterprise buyers ask for.
HIPAA
Required if you touch protected health information, directly or as a downstream vendor.
HOW WE WORK
How we work together
01
Discovery call (30min)
What is blocking the deal, what you have in place, when you need it.
02
Scoped proposal
Fixed scope, timeline, and price within a few days. No open-ended hours.
03
Kickoff
Assessment first, so you have a ranked roadmap in the first few weeks.
04
Delivery
We write the documentation and work alongside your engineers on the technical fixes. You approve decisions.
05
Ongoing
Type II, surveillance audits, and annual obligations continue. We stay on or hand over documented processes.
The questions that come up on every first call.
-
When does a SaaS company need a vCISO?
Most often at the first enterprise questionnaire the founder or CTO cannot answer in an afternoon. Second, when a SOC 2 audit lands on the calendar. Third, when the board asks for a documented programme.
-
Do you work with our Vanta or Drata account?
Yes. We administer the platform, set up integrations, move evidence collection toward completion, and turn failing checks into remediation work. The platform records the programme; it does not run it.
-
Can you do SOC 2 and ISO 27001 in parallel?
Yes, and most companies with European deals should. One control set, two outcomes, one engagement.
-
How fast can you start?
Most engagements begin within a few weeks of signing. The discovery call sets the level and first priorities so the scope stays tight.
-
What does it cost?
Fixed monthly pricing by engagement level, quoted before work starts. Compare it against a full-time CISO hire and a multi-month recruiting cycle.
Book a discovery call
Thirty minutes on what is blocking the deal, what you have in place, and when you need it. You leave with a recommended engagement level.