Skip to content

We get your failing tests passing before the audit

Your compliance tool shows red tests and the auditor has questions. We sort the tests, draft your replies and put the missing controls in place.

The first call is free. Services start from $1,500, and we agree a fixed price before any work starts.

An example of the one-page summary you forward, from our fictional sample report.Read the whole sample report

When you need it

Usually one of these, often with a date attached.

  • Your compliance tool shows failing tests and the audit is coming up.
  • The auditor has raised exceptions you can’t close alone.
  • You’ve just bought the tool and want the controls in place before you switch it on.
  • You have no security engineer on staff.

What you get

We agree a fixed price after the free call, once we know what’s in scope. Services start from $1,500.

Request a free call
  • Your failing tests, sorted by how much they matter to the audit.
  • A draft reply to each of the auditor’s questions.
  • A plan that fits your audit date.
  • A one-page status summary for your auditor.

Not included: changes to your app’s code (your developers make them, with our help), the audit, certificate or pentest itself, software licences, insurer or broker fees, and incident response.

Before we touch anything

Nothing starts without your written OK
You name the systems, the accounts and the dates first.
We work from a named account you create
It has only the rights the work needs, and you can see everything it does.
You take the access back when we’re done
We delete or return our working data, and you remove the account.

All six ground rules

How it works

Three steps. You agree the price before each one starts. Services start from $1,500.

  1. A free call

    Tell us who’s asking and when they need an answer. We’ll say what we’d check, then send you a fixed price.

    30 minutesFree

  2. We check what they asked about

    We check your product and setup against their questions, and test where it matters. You get the answers with evidence, a plan and a one-page summary to send them.

    About two weeksPriced after the call

  3. We fix what’s missing

    We fix your cloud and account setup ourselves. Your developers make the code changes, with our help. Then we check every fix, at no extra cost.

    Usually sign-in security, cloud alerts, tested backups and laptop security. What each fix does.

    1 to 8 weeks a fixPriced after the assessment

Before you enquire

What people ask us most. Anything else, ask on the call.

Do you run the audit?

No. Your auditor does. We get the controls and the evidence ready, and draft your side of each exception.

Which failing tests can you fix?

The infrastructure ones, as fixed-price fixes: MFA, logging, backups, device management. Tests about your application code go to your developers with our pattern, and we check the result.

Our audit is months away. Is it too early?

No. It’s the same assessment, done before your compliance tool is switched on, so its tests pass from the start.

Which compliance tools do you work with?

Vanta, Drata, Secureframe, Sprinto, Scrut, or a spreadsheet.

Can you help again next year?

Yes. We can rerun the assessment before each year’s audit.

What do you need from us?

The form, questionnaire or report, and a call with whoever runs your cloud and your workspace. For a fix, a named admin account for the systems it changes, set up the way we describe on the call.

How do you handle our admin access?

You create a named account for us with only the rights the fix needs, and you can see everything it does. We never use shared logins. Each fix lists its changes, when they happen and how to roll them back, and you remove the account when the fix is done.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Tell us your audit date

Which framework, which tool, and how many tests are red. On the call we’ll say what fits before the date.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

We only use it to follow up on your enquiry.

When does whoever’s asking need an answer?

Please leave out passwords and customer data.

We only use your details to reply to your enquiry. How we handle enquiry information.

Or email contact@unmesha.io directly.