Engagements
An assessment that ends in a plan, not a score
Every engagement starts the same way: find out what is actually in place, write down what a customer could verify, and put the rest in an order you can afford. The measure of success is a shorter security review on your next deal — not a thicker binder.
The core engagement
Security assessment and roadmap
A fixed-fee, fixed-length engagement. Interviews with the people who actually run things, a documented review of what exists, and five deliverables you own outright.
-
D1
Gap analysis and control register
Every control assessed and scored, with the evidence — or its absence — recorded against it. The register is a working document your team maintains after we leave, not a report that goes in a drawer.
-
D2
Prioritized roadmap
What to fix, in what order, with effort and sequence. Certification decisions appear here as timed choices with their cost attached, never as a foregone conclusion.
-
D3
Phase-one plan
The first tranche of work broken down to the level an engineer can pick up on Monday, so the roadmap starts moving before the momentum goes.
-
D4
Executive readout
The findings in the register put in terms a CEO, a CFO and a board can act on. Management presents its own security narrative; we are available to attend and answer.
-
D5
A one-page customer-facing security summary
The deliverable that pays for the engagement. One page your sales team can attach to an RFP response the week after we finish, saying only what is true.
Every control, crosswalked
- SOC 2 Trust Services Criteria
- ISO/IEC 27001:2022 Annex A
- NIST CSF 2.0
- NIST SP 800-53 Rev. 5
- PCI DSS
- FTC Safeguards § 314.4
- ISO/IEC 42001 Annex A
One register, seven frames. Answer a question once and it answers in every framework a customer asks in — which is where most of the sales-cycle time goes back. Which frame leads depends on who buys from you: SOC 2 and ISO/IEC 27001 for most enterprise software buyers; PCI DSS wherever you store, process or transmit cardholder data; FTC Safeguards § 314.4 where your customers are dealers or others covered by the Rule; ISO/IEC 42001 when AI or machine learning is part of the product. If a regime specific to your market applies, we scope it in at kickoff rather than pretending the generic answer covers it.
Follow-on work
The projects the roadmap names
Scoped and priced separately, commissioned individually, in whatever order the roadmap says they earn their keep. None of them is a condition of the assessment.
SOC 2 Type II readiness
Control design, evidence discipline and the operating period, up to the point an auditor is engaged. We never perform the examination.
PCI DSS scope reduction
Establish which self-assessment questionnaire actually applies, then shrink the environment that drives it. Scope is the single biggest lever on what PCI costs you.
Email authentication
SPF, DKIM and DMARC advanced to enforcement without breaking the mail that pays your bills.
Vulnerability disclosure
A published route for a researcher to reach you, with the triage and response commitments behind it that make publishing it safe.
Public trust page
The page a prospect finds before they send the questionnaire. Written from the register, so every claim on it is one you can evidence.
Customer contract terms
A review of the security and data obligations in the agreements you have already signed, so you know which ones you are currently missing.
Questionnaire answer bank
A control-keyed set of answers your sales engineer can work from, so the same questions stop being answered from scratch every time a new questionnaire arrives.
How we work
Seven commitments
- Fixed fee, scoped before it starts. You know the number and the end date before you sign. No hourly meter, no discovery phase that discovers a bigger project.
- We never audit what we build. Level Four does not perform SOC 2 examinations or issue certifications. Your auditor is independent of us by design, and we will say so in writing to anyone who asks.
- We do not sell certifications. The roadmap says when an attestation is worth its cost and when it is not. Sometimes the honest answer is a trust page and a year of operating history.
- Senior people, start to finish. Nobody learns the work on your engagement, and nothing is handed down to junior staff once the contract is signed. Specialists are brought in only when the work needs them, under equivalent written confidentiality obligations, and we remain responsible for their work as for our own.
- Priced to be affordable, not to be maximal. We scope to your size and your risk. If the right answer is smaller than what we would like to sell you, the right answer is what you get — and we would rather have the next engagement than the biggest first one.
- An unavailable document is a finding. If a policy cannot be produced during the engagement, that is recorded as a result rather than treated as a scheduling problem.
- You own the output. The register, the roadmap and the templates are yours to maintain and reuse without re-engaging us.
Start with a scoping call
Thirty minutes, no charge. Bring the last security questionnaire a customer sent you and we will tell you honestly what it would take to answer it well.