Services & Pricing
From Free Audit to Documented, Defensible Compliance
Your free scan shows where you stand. These packages fix what it finds and keep you in Safe Harbor year-round. Pricing is a starting point — every engagement is scoped to your domain and headcount.
The Compliance Ladder
Each step builds on the last. Most clients start with the audit, fix the gaps with a Remediation Sprint, then move to a Managed Compliance retainer to stay defensible.
Free Domain Audit
See your email and web security score in seconds.
- SPF, DKIM & DMARC spoofing check
- TLS / transport security review
- Website security-header scan
- Zero-knowledge — we don't store your results
Remediation Sprint
We fix everything the audit flagged, then re-scan to prove it.
- SPF / DKIM / DMARC configured to enforcement
- MTA-STS & transport hardening
- Microsoft 365 / Google Workspace anti-phishing setup
- Before-and-after audit score report
Compliance Package
The documented program regulators and your insurer ask for.
- Written Information Security Program (WISP)
- Mapped to SB 2610, FTC Safeguards, HIPAA or IRS Pub 4557
- Risk assessment & policy templates
- Dated compliance attestation you can hand to auditors
Managed Compliance
Stay in Safe Harbor without thinking about it.
- DMARC-as-a-Service monitoring & reports
- Quarterly re-audits + annual program review
- Security-awareness training & phishing tests
- vCISO guidance and incident-response readiness
À la carte services
Email Authentication (SPF/DKIM/DMARC)
Stop attackers spoofing your domain. We configure and validate full email authentication and move you to a reject policy safely.
DMARC-as-a-Service
Ongoing monitoring of who is sending as your domain, with monthly reports and progressive enforcement — the recurring backbone of email security.
Microsoft 365 / Google Workspace Hardening
MFA, conditional access, anti-phishing and safe-links policies, and audit logging turned on and tuned for small teams.
WISP & Policy Documentation
Productized written security policies mapped to the framework your industry is regulated under, so 'document everything' becomes a deliverable.
Security-Awareness Training
Recurring phishing simulations and short training for your staff — the control most compliance frameworks explicitly require.
BEC & Wire-Fraud Protection
Layered controls for firms that move client money — title, real estate and finance — where a single spoofed email is a six-figure loss.
Not sure where you stand?
Start with the free audit. It takes seconds and shows you exactly which gaps to close first.
Run a Free Audit