What the engagement produces
- SOC 2, ISO 27001, or CyberSecure Canada certification
- Legal, insurance, or audit opinions
- Running your governance function - we prepare the evidence and right-sized habits
This replaces the old catch-all GRC pitch with a narrower promise: make the answers true and defensible for a small office.
Questions owners actually ask
Is this GRC?
Only in the practical small-business sense. We help with policies, evidence, security-questionnaire answers, and readiness habits. We are not your auditor, privacy counsel, or enterprise governance department.
Can you help with SOC 2 or ISO 27001?
We can help you understand the readiness gap and coordinate named specialist partners for formal framework work. We do not pretend that a small training firm is your audit advisory practice.
What if the honest answer is no?
Then we say no and write the remediation plan. A truthful no with a dated plan is safer than an invented yes that fails due diligence.
More on the full FAQ page - including “why should we trust you with our office?”, answered honestly.