No two burrows are alike. A guide walks yours with you.

Policy packs give you the documents; consulting helps you take them all the way to the audit. We find the gaps, sequence the work for your team's actual capacity, prepare the evidence the way auditors read it — and stand beside you on audit day. The aim is no surprises.

Consulting engagements open soon. You can tell us what you need now: write to us below and we reply personally.

The engagement

Four forks, one guide

01

Gap analysis

Where you stand versus where the framework needs you — scoped against SOC 2, ISO 27001:2022 or PCI DSS v4.0.1, using the same coverage matrix our packs are verified with.

02

Roadmap

The work, sequenced and sized for your team — what to deploy from the pack, what to build, what to defer, and in which order an auditor will care.

03

Evidence prep

Proof collected and organised the way auditors read it: registers populated, procedures exercised, screenshots and records staged per control.

04

Audit day

A guide at your side when the auditor arrives — walkthrough support, finding triage, and corrective-action follow-through.

Is this for you?

Built for teams doing this the first time

You'll get the most from us if

  • You're heading into your first SOC 2, ISO 27001 or PCI DSS cycle
  • Security is someone's part-time job, not yet a department
  • You want a fixed, sequenced path — not an open-ended retainer
  • You're deploying a MeerLock pack and want it fitted, not just filed

How we work

  • Fixed-scope phases with named deliverables — priced before we start
  • Your team does the work it can; we do the work it can't yet
  • Everything we produce lands in your toolkit registers, not in slideware
  • Remote-first, from Bangkok (UTC+7)

Tell us where you're headed

Consulting engagements open soon. Tell us now what you need: the framework, your deadline and the size of your team.

We read every enquiry and reply personally.

We use your details only to answer you. Privacy notice.