Service 03
Compliance and Risk
Controls that get you through procurement, security reviews, and formal audits.

Overview
Enterprise clients do not buy from vendors they cannot audit. We design and implement the controls that get you through procurement, security reviews, and formal audits, and we prepare you to pass them the first time.
In scope
- SOC 2 readiness: control design, gap assessments, and audit preparation.
- ISO 27001 readiness and information security management.
- Privacy compliance programs for PIPEDA and Alberta's PIPA.
- Vendor risk and security questionnaire response programs.
- Policy libraries, evidence collection, and continuous compliance monitoring.
Our point of view
Somewhere right now, your largest prospect's security team is writing the questionnaire that decides whether you can be their vendor. Compliance is treated as a cost until the deal that requires it shows up, and by then the timeline is someone else's. We prepare mid-market companies to clear procurement, security reviews, and formal audits before the deal depends on it. Readiness is a revenue position.
Who this is for
You will recognize yourself in at least one of these:
A big contract just asked for SOC 2, and you have eleven months and no controls.
Security questionnaires keep arriving and each one eats a week of founder time.
You handle client data and know, privately, that your controls would not survive a serious look.
Enterprise deals keep stalling in procurement and nobody can tell you exactly why.
What we deliver
The Gap Assessment
Your current state mapped against SOC 2 Trust Services Criteria or ISO 27001, with a sized remediation plan.
The Control Matrix
Every control designed, assigned to an owner, and wired into how work actually happens.
The Policy Library
Security, privacy, access, vendor, and incident policies your team will actually follow.
The Evidence Engine
Automated evidence collection so audit season is an export.
The Questionnaire Playbook
A maintained answer bank that turns week-long security questionnaires into a half-day task.
The first 30 days
Scoping: which framework, which systems, which client obligations drive the timeline.
Gap assessment across people, process, and technology controls.
Remediation plan sequenced by deal impact: what unblocks revenue first goes first.
Control build begins. Policy library drafted, owners assigned, evidence collection switched on.
What we measure
Every initiative carries a metric agreed before we build:
An illustrative system
The readiness engine
The readiness engine
Illustrative workflowHonest edges
Where this service stops:
- Only a licensed CPA firm can issue a SOC 2 report, and only an accredited body can certify ISO 27001. We design, implement, and prepare. The audit itself stays independent, which is exactly how it should be.
- We will not paper over gaps to hit a date. A failed audit costs more than an honest timeline.
- Compliance tooling is useful but it is not the work. We implement the controls; the platform just collects the evidence.
Questions we get
How long until we are audit-ready?
It depends on your starting point, which is what the gap assessment establishes in week two. What we can promise is a sequenced plan where the controls that unblock revenue come first.
SOC 2 Type I or Type II?
Usually Type I to satisfy the immediate deal, then straight into the observation window for Type II. We plan both from day one so nothing is built twice.
Can you also handle privacy law?
Yes. PIPEDA and Alberta's PIPA are built into every control set we design, because your compliance position and your privacy position are the same conversation in Canada.
Latest thinking


