managed deception infrastructure. every interaction is a high-fidelity signal — because nothing legitimate should ever touch them.
[t-pot][opencanary][custom decoys]
- small teams that want enterprise-grade tripwires without running them
- environments where alert fatigue has killed every other detection
- pre-incident posture work — you want to know before, not after
$ light pentesting
[available] scoped external and web app assessments. clear, reproducible reports. no boilerplate, no vuln-scanner cut-and-paste.
[manual review][burp / caido][nuclei][custom tooling]
- a fresh perspective before a soc2 / iso renewal
- pre-launch reviews for a new product surface
- targeted reviews when something feels off but you can't name it
$ compliance audit
[available] gap analysis against soc2, hipaa, cmmc, iso 27001 — focused on what actually moves the needle, not just the checklist.
[soc2][hipaa][cmmc][iso 27001][nist 800-53]
- teams who got a control framework dropped on them and don't know where to start
- companies preparing for first audit — i'll tell you what real auditors look at
- organizations who want a sanity check before paying for the real one
$ cloud security review
[available] azure, aws, or m365 posture review. policy-as-code remediation paths, not pdf reports that die in a sharepoint.
[azure][aws][m365][terraform][policy-as-code]
- rapid growth led to a cloud estate nobody fully owns
- identity and access bloated past the point of being auditable
- cost guardrails and security guardrails fighting each other
- · no boilerplate — every report is written for your environment. zero recycled paragraphs.
- · no scanner-output dumps — a screenshot of nessus is not a deliverable.
- · fixable findings — every issue ships with a working remediation path. preferably as code.
- · safe harbor first — we agree on scope, blast radius, and out-of-band channels before anyone runs anything.
- · post-engagement transfer — you walk away able to verify what i fixed without calling me back.
1. intro call (30 min). free. we figure out if i'm the right fit.
2. scope doc. one page. signed. covers rules of engagement, blast
radius, and what "done" looks like.
3. engagement. async-first. weekly written check-ins. no surprise pdfs.
4. deliverable. plain markdown + a working remediation path.
5. 30-day q&a window. you read it, you have questions, i answer.
────────────────────────────────────────────────────────────────