Skip to content

The layer above the platform.

Vanta collects the evidence. Someone still has to decide what you can honestly claim, and what you can sign.

An engraving of a narrow passage between two headlands
  1. 1

    The questionnaire runs 214 questions. Three of them are actually legal representations to a counterparty with a much bigger legal department than yours.

  2. 2

    The deal wants SOC 2 Type II. You have Type I and a roadmap. What do you tell them, and what are you willing to put in writing?

  3. 3

    The insurer's renewal asks whether MFA is enforced "on all systems." It mostly is.

Questionnaires and representations

Keep your compliance platform. Vanta, Drata, and Secureframe all do evidence collection well, and replacing them isn't the job. What none of them do is decide whether you can stand behind a given answer, whether to accept the customer's audit-rights clause, or which security-exhibit term will hurt most on the day you have a breach. Those calls get made with you, under deal pressure, in writing.

The SOC 2 sequence, honestly

Type I is a snapshot. Type II is a season, because the report doesn't exist until months of observation window have run. A recent pen test is a de facto requirement that no standard formally imposes, which surprises people every time. Deals still close while the audit runs: there is a defensible way to show your posture mid-stream, using a trust page, your policies, and a gap letter, without overstating where you actually are. ISO 42001 is now arriving in enterprise AI RFPs, and we'll tell you when it's worth the build. We won't put a certification date in writing, because that date isn't ours to give.

Incidents, before and during

Arranging incident counsel before you need it beats emergency rates and a cold introduction at eleven at night. So we wire the plan up in advance: who gets called and in what order, what stays privileged, and which of the thirty-plus state notice clocks start when. If the day comes, we run the legal side while your team runs the technical one.

Your insurance is also a contract

What you write on a cyber application becomes a warranty, which is how an optimistic answer about MFA turns into a denied claim. Sublimits surprise people at exactly the wrong time. We read the application, the exclusions, and the new AI endorsements before you sign. The briefing has the details.

Briefing: What your cyber policy actually excludes

The lane we stay in

We don't audit, we don't pen test, we don't certify, and we don't sell software. Our lane is legal judgment on what you represent, what you accept, and what you sign, and we stay in it.

Fifteen minutes. No pitch.

You talk, we diagnose. You leave with the two or three exposures worth addressing first, along with a straight answer on whether you need counsel now, including "not yet."