Services
Two things,
done properly.
We sell what we can deliver. Two service lines are open. The rest of the catalog is published on our roadmap with honest dates rather than aspirational marketing.
01 Security awareness training
What it is
A managed awareness program covering your whole workforce. We design the curriculum, run the phishing simulations, and produce the reporting your carrier, your auditor, or your prime asks for at renewal.
Most programs fail because they are built as a one-time video and forgotten. Ours runs on a quarterly cadence with measurable improvement between cycles.
Who buys it
Small and midsize businesses facing a cyber insurance renewal, a customer security questionnaire, or a flowed-down requirement from a prime contractor.
What you receive
- Annual awareness curriculum mapped to your workforce roles
- Quarterly phishing simulation campaigns
- Completion tracking by department and individual
- Improvement reporting across cycles
- Evidence package suitable for an insurance or audit file
Engagement model
Annual retainer with quarterly delivery. Program design happens once. Simulations and reporting recur.
02 Federal litigation support and eDiscovery
What it is
Certificated paralegal support for federal case teams. Discovery volume routinely outruns the staffing an office has available, and set-aside subcontracting goals need filling. We do both jobs at once.
Our founder holds a paralegal certificate and an advanced civil litigation paralegal certificate. This is not adjacent work we picked up. It is trained practice.
Who buys it
Federal agencies, US Attorney's Offices, and prime contractors staffing litigation support vehicles who need a certified SDVOSB subcontractor.
What you receive
- Discovery indexing and document organization
- ESI processing and load file preparation
- Privilege review and redaction
- Evidentiary exhibit preparation
- Deposition and trial support
Engagement model
Subcontract, task order, or hourly under an existing vehicle. Remote delivery. We work inside your platform and your protocols.
In development
These lines are under active build. We will name a date rather than take an engagement we cannot staff.
HIPAA compliance
Annual security risk assessment, policy set, workforce training, business associate agreement review, and breach response planning for dental, medical, and behavioral health practices.
NIST 800-171 and CMMC readiness
Gap assessment across the 110 requirements, System Security Plan authoring, POA&M construction, SPRS score calculation, and remediation roadmap for defense suppliers.
Privacy compliance
Data mapping, privacy policy, consumer request handling, and state law applicability analysis for businesses operating across state lines.
On CMMC, as of August 2026. DoD suspended CMMC Phase 2 on July 13, 2026. The DFARS rule effective November 10, 2025 was not repealed. Phase 1 self-assessment requirements remain in force, and DoD plans to enforce NIST SP 800-171 Rev 2 through self-assessments during the suspension.
Read the consequence carefully. The requirement stayed. Third-party verification went away. Contractors now sign their own affirmations, and that signature carries False Claims Act exposure. A gap assessment documenting shortfalls did not become less useful. It became more.