A monthly retainer for teams who want senior security guidance without hiring a full-time security engineer. The right shape for most Series A–B companies.
What’s included
- Fractional CISO. A named senior practitioner who attends your weekly security/eng review and answers Slack.
- Threat modeling. Quarterly half-day sessions to map what you’re shipping against what attackers want.
- Architecture review. Every major system gets a read before it ships.
- SDLC integration. We set up the linters, the dependency scanning, and the secret-detection in your CI, and tune them so they don’t get ignored.
- Incident support. First-response help in the early hours of a declared incident, working alongside your team while you decide on next steps.
How it works
Eight hours/week, billed monthly. We don’t track hours within the month; this isn’t an agency.
You get a single Slack channel, a recurring weekly meeting, and a named lead. The work is not delegated to a junior; your principal is your principal.
When this is the wrong fit
- You’re pre-revenue and don’t have an engineering team yet, so you don’t need us
- You’re a regulated F500 with a CISO already, so we’re a vendor at that scale, not an embedded team
- You’re shopping for a logo to put on the website without real engagement, in which case we’ll be a poor fit for each other
// the practical answer
We typically work alongside an internal security lead at companies between
30 and 300 engineers. If that’s roughly you, let’s talk.