No two burrows are alike. A guide walks yours with you.
Policy packs give you the documents; consulting helps you take them all the way to the audit. We find the gaps, sequence the work for your team's actual capacity, prepare the evidence the way auditors read it — and stand beside you on audit day. The aim is no surprises.
Consulting engagements open soon. You can tell us what you need now: write to us below and we reply personally.
Four forks, one guide
Gap analysis
Where you stand versus where the framework needs you — scoped against SOC 2, ISO 27001:2022 or PCI DSS v4.0.1, using the same coverage matrix our packs are verified with.
Roadmap
The work, sequenced and sized for your team — what to deploy from the pack, what to build, what to defer, and in which order an auditor will care.
Evidence prep
Proof collected and organised the way auditors read it: registers populated, procedures exercised, screenshots and records staged per control.
Audit day
A guide at your side when the auditor arrives — walkthrough support, finding triage, and corrective-action follow-through.
Built for teams doing this the first time
You'll get the most from us if
- You're heading into your first SOC 2, ISO 27001 or PCI DSS cycle
- Security is someone's part-time job, not yet a department
- You want a fixed, sequenced path — not an open-ended retainer
- You're deploying a MeerLock pack and want it fitted, not just filed
How we work
- Fixed-scope phases with named deliverables — priced before we start
- Your team does the work it can; we do the work it can't yet
- Everything we produce lands in your toolkit registers, not in slideware
- Remote-first, from Bangkok (UTC+7)
Tell us where you're headed
Consulting engagements open soon. Tell us now what you need: the framework, your deadline and the size of your team.
