Startup security plans
Security as an ongoing relationship, priced for company stage rather than asset count. Every plan includes a named security lead who knows your environment.
Foundation
FromFor seed-stage teams putting the basics in place for the first time.
- Baseline security assessment
- Core security policy set
- Cloud configuration review
- Vulnerability management
- Quarterly risk review
- Email support
Growth
FromFor Series A teams preparing for their first enterprise customers.
- Everything in Foundation
- SOC 2 readiness support
- Annual penetration test
- Security questionnaire support
- Privacy compliance readiness
- Monthly security reviews
Scale
FromFor Series B and beyond, running security as a continuous function.
- Everything in Growth
- vCISO leadership
- Continuous penetration testing
- AI security assessments
- Vendor risk management
- Incident response readiness
- Board-level reporting
Need something different? Penetration testing, red team engagements, M&A due diligence and AI security assessments are also available as standalone projects.
What every plan includes
A named security lead
One person who learns your architecture and stays with you, rather than a rotating ticket queue.
Findings your engineers can use
Prioritized, reproducible and mapped to your stack — with remediation guidance, not just severity labels.
Reporting you can forward
Documentation written for the audience that asks for it: customers, auditors, investors and your board.
Not sure which plan fits?
A free assessment will tell you which stage you are actually at — which is not always the stage your funding round suggests.