Home / Services / Startup Security Program
Advisory · Service

Startup Security Program — Pre-seed → Series A · 90 days

Foundations bundle for pre-seed → Series A startups: policies, basic controls, vendor reviews, and audit-ready posture in 90 days.

Scope this engagement See related tools
NIST CSF 2.0CIS Controls IG1ISO 27001 Annex A (subset)
What's tested

Coverage that goes deep.

Foundations bundle for pre-seed → Series A startups: policies, basic controls, vendor reviews, and audit-ready posture in 90 days.

  • Security policies & procedures
  • Asset & data inventory
  • IAM hardening (Google Workspace / M365)
  • Endpoint security baseline
  • Vendor risk reviews
  • Privacy compliance basics (GDPR/DPDP)
  • Security awareness training
  • Incident response runbook
§ ENGAGEMENT SNAPSHOT
Timeline
90 days
Methodology
NIST CSF 2.0
CIS Controls IG1
ISO 27001 Annex A (subset)
Category
Advisory
Re-test
Included after fixes

Every engagement is led by a CRTO/OSCP-certified senior engineer with named accountability.

Deliverables

What you get back.

A structured deliverable pack you can hand to engineers, auditors and the board.

DELIVERABLE 01

Policy pack (15 documents)

DELIVERABLE 02

Asset inventory

DELIVERABLE 03

Quarterly risk review

DELIVERABLE 04

Audit-prep package

Methodology

How we work.

PHASE 01

Scope

Confidential scoping call. We agree assets, environments, exclusions and timing.

PHASE 02

Test

Active testing per agreed methodology, with daily check-ins on critical findings.

PHASE 03

Report

Executive + technical deliverables. CXO presentation if you want it.

PHASE 04

Retest

Re-test included after your team applies fixes. Certificate issued on pass.

FAQ

Common questions.

Why a 90-day program?
Most Series-A diligence asks the same set of questions. We get you to "yes" on every one.
Scope this engagement

Tell us about your environment.

A 30-minute scoping call — confidential, NDA-protected, complimentary. Our senior security team will respond within 4 business hours.

  • Named senior engineer on every project
  • In-house tools in production · ISO 27001 aligned practices
  • 4-hour breach SLA · 5–10 day delivery