Small engagements. Clear scopes. Real deliverables.
Every offering below has a basic and an advanced depth. Prices are ranges, not quotes — the real number lands after we scope it on a call.
Offerings
Managed deception infrastructure. Every interaction is a high-fidelity signal — because nothing legitimate should ever touch them. Live examples run on this site; custom builds mimic your stack.
[opencanary][t-pot][custom decoys][activity feed]
basic $150 – $400 / mo
a managed sensor on your edge, my dashboards, alerts piped to your channel.
advanced $500 – $2k / mo
custom decoys that imitate your real services, threat-intel enrichment, monthly written report.
Who this is for
- small teams that want enterprise-grade tripwires without running them
- environments where alert fatigue has killed every other detection
- pre-incident posture work — you want to know before, not after
MCP Servers & Data Enrichment
[beta] Private MCP servers that bolt onto your stack: email and domain enrichment, model-cycling, and workflow automation. Proofpoint-grade signal and EDR enrichment for pennies on the license dollar.
[mcp][email/domain enrichment][model routing][self-hosted]
basic $1k – $3k build
one MCP server stood up against your tools — email enrichment or model routing — self-hosted, yours to keep.
advanced $3k – $8k build · $100 – $500 / mo
multi-source enrichment pipeline + model-cycling backend, wired into your SOC/EDR. fraction of a per-seat license.
Who this is for
- teams paying enterprise prices for email security signal they could own
- analysts who want enrichment in their existing tools, not another portal
- shops that want AI workflows without locking into one model vendor
Light Pentesting
[available] Scoped external and web app assessments. Clear, reproducible reports. No boilerplate, no vuln-scanner cut-and-paste.
[manual review][burp / caido][nuclei][custom tooling]
basic $2.5k – $5k
one scoped target — external surface or a single web app. reproducible report.
advanced $6k – $15k
external + web + identity, with a free retest of fixed findings.
Who this is for
- a fresh perspective before a soc2 / iso renewal
- pre-launch reviews for a new product surface
- targeted reviews when something feels off but you can't name it
Compliance Audit
[available] Gap analysis against SOC 2, HIPAA, CMMC, ISO 27001 — focused on what actually moves the needle, not just the checklist.
[soc2][hipaa][cmmc][iso 27001][nist 800-53]
basic $3k – $6k
single-framework gap analysis with a prioritized remediation list.
advanced $8k – $18k
multi-framework mapping, evidence prep, and auditor liaison through the audit.
Who this is for
- teams who got a control framework dropped on them and don't know where to start
- companies preparing for first audit — i'll tell you what real auditors look at
- organizations who want a sanity check before paying for the real one
Cloud Security Review
[available] Azure, AWS, or M365 posture review. Policy-as-code remediation paths, not PDF reports that die in a SharePoint.
[azure][aws][m365][terraform][policy-as-code]
basic $2.5k – $5k
single-cloud posture review, top findings delivered as code.
advanced $6k – $14k
multi-cloud + identity deep-dive with policy-as-code remediation you can merge.
Who this is for
- rapid growth led to a cloud estate nobody fully owns
- identity and access bloated past the point of being auditable
- cost guardrails and security guardrails fighting each other
Principles
How I work, regardless of engagement.
- · No boilerplate — Every report is written for your environment. Zero recycled paragraphs.
- · No scanner-output dumps — A screenshot of Nessus is not a deliverable.
- · Fixable findings — Every issue ships with a working remediation path. Preferably as code.
- · Safe harbor first — We agree on scope, blast radius, and out-of-band channels before anyone runs anything.
- · Post-engagement transfer — You walk away able to verify what I fixed without calling me back.
Engagement
1. Intro call (30 min). Free. We figure out if I'm the right fit.
2. Scope doc. One page. Signed. Covers rules of engagement, blast
radius, and what "done" looks like.
3. Engagement. Async-first. Weekly written check-ins. No surprise PDFs.
4. Deliverable. Plain markdown + a working remediation path.
5. 30-day Q&A window. You read it, you have questions, I answer.