Capability

Compliance is an opinion you can defend.

Regulated products need more than a feature that behaves correctly. They need evidence, and evidence has to be produced deliberately.

The problem

If you operate in health services or payments, a working product is the easy half. The other half is being able to show a regulator, an auditor, or an enterprise security reviewer why your handling of their data is defensible.

That work is different in kind from feature delivery, which is why it is priced differently. Governance, risk and compliance work is never story-point priced. A point measures functional scope. A policy set, a risk register or a Statement of Applicability has none, so a point-based price for advisory work has no unit behind it.

One boundary matters more than any capability claim. Koombea does not issue certificates and neither does any development partner. An ISO/IEC 27001 certificate comes from an accredited certification body. A SOC 2 report comes from a licensed CPA firm. A PCI DSS Report on Compliance comes from a Qualified Security Assessor. You engage that party. We do the gap analysis, build the controls, produce the evidence, and get you ready for the room.

On completion of a build we provide a written attestation covering the agreed security checks and any known critical or high-severity findings identified within that scope. That is a statement we are willing to put in writing, which is the only kind worth having.

  • Security leadership on demand, without a full-time hire
  • A management system built against ISO/IEC 27001:2022, not a folder of documents
  • A prioritized risk treatment plan, not a maturity score
  • Vendor risk caught before it becomes yours
  • Penetration testing you authorize in writing first
  • Gap analysis, audit readiness, and accompaniment through certification

Nine services, three pillars

Governance sets the direction. Risk management finds what can hurt you. Compliance and audit readiness gets you into the audit prepared. These are the service names, and each one is a defined engagement with a defined deliverable.

Virtual CISO (vCISO)

A named security lead for risk decisions, executive reporting, and the control program, without a full-time hire.

Policies and Procedures Development

We write your security documentation and keep it current. It fits how your organization actually works.

ISMS Design and Implementation

We build and deploy an information security management system against ISO/IEC 27001:2022.

Risk Assessment and Treatment

We analyze your posture, name the risks, and order the treatment plan by what matters most.

Third-Party Risk Management

We evaluate and monitor your vendors. You do not inherit their vulnerabilities.

Offensive Security Services

Network penetration testing and vulnerability management. Findings you can act on, not a scanner dump.

Gap Analysis

We measure your environment against the requirement, control by control, and map the path to compliance.

Audit Readiness

Technical and documentary preparation. The audit is not the first time you answer the question.

Certification Support

We prepare the evidence, answer technical findings, and stay with your team through the assessor's review.

Which framework, precisely

A framework claim is the sentence your legal team reads literally. So here is what each one is, where it stands today, and which part of it is ours.

DimensionWhat it isWhere it standsWhat we do
ISO/IEC 27001:2022An auditable information security management system. An accredited body certifies it after a Stage 1 and a Stage 2 audit.The 2022 edition restructured Annex A to 93 controls in four themes. The transition period closed on 31 October 2025, so 2013 certificates no longer hold.ISMS design and implementation, gap analysis, evidence, and accompaniment through both audit stages.
SOC 2An AICPA framework against the Trust Services Criteria. A licensed CPA firm issues the report.Type I covers control design at a point in time. Type II covers operating effectiveness over a period. SOC 2 with no type stated is not a scope.Readiness for the type you are targeting, then support through the Type II observation period.
PCI DSS v4.0.1The card brands' security standard. A Report on Compliance needs a Qualified Security Assessor. A Self-Assessment Questionnaire you complete and attest yourself.The January 2025 SAQ A revision dropped three requirements and replaced them with a site-wide script susceptibility criterion, effective 31 March 2025. A full redirect avoids it. An iframe does not.Scope reduction first, SAQ eligibility determined honestly, then the controls the remaining scope actually requires.
HIPAAA US federal regulation covering the Privacy Rule, the Security Rule and the Breach Notification Rule. The HHS Office for Civil Rights enforces it.No certification scheme exists. Anyone selling you HIPAA certification is selling something that is not real. Business associates and their subcontractors sit directly in scope.Security Rule gap analysis, readiness assessment, business associate obligations, and the evidence behind them.

How a framework gets satisfied

  1. Step 01

    Scope reduction

    The first move is always making the regulated footprint smaller. The cheapest compliance work is the work you engineer your way out of needing, and it is the step most partners skip because it shrinks the engagement.

    First, always

  2. Step 02

    Gap analysis

    Measure the current state against the specific framework, control by control, and produce a list a person can act on rather than a maturity score. Start here. Leading with certification support is buying the end of the process first.

    Fixed fee

  3. Step 03

    Control implementation

    The engineering work: access control, encryption, logging, audit trails, retention and data residency. This part is a build and is priced in points like any other build.

    Delivered by an AI Pod

  4. Step 04

    Evidence production

    Documentation produced while the work happens, not reconstructed afterwards. Reconstructed evidence is how audits go badly.

    Continuous

  5. Step 05

    Audit readiness

    A dry run against the questions your assessor will ask, so the first time you answer them is not in front of the assessor.

    Before the audit

  6. Step 06

    The audit itself

    Run by the independent third party you appoint. We support it and respond to findings. We do not issue the certificate and neither does any development partner.

    Your assessor

How this is priced

Governance work is never story-point priced, because the deliverable is an assessment and an evidence trail rather than a shipped feature. It prices on four bases instead, and the engagement decides which one applies.

The control implementation that comes out of an assessment is a build. An AI Pod delivers that part, pointed like any other build.

When a compliance engagement and a build run together, they are two lines on two bases. We state them separately. Folding advisory work into a build total would quietly convert an opinion into a fixed-bid commitment.

  • A monthly retainer for vCISO, ongoing third-party monitoring, and ISMS maintenance
  • A fixed fee for a defined assessment: gap analysis, risk assessment, an initial vendor evaluation
  • A scoped engagement for penetration testing, priced by target count, scope, test depth, and whether retesting is included
  • A phase or milestone price for ISMS implementation, audit readiness and certification support, tied to audit stages rather than to a delivery calendar

What drives the number

What moves the number is how much regulated data you touch and how much of it you could stop touching. Almost everything else follows from that.

  • How much regulated data is genuinely in scope after reduction, which is often far less than at the start
  • Which framework, and which flavour of it, since SOC 2 Type I and Type II are different engagements on different timelines
  • Your current state: nothing in place, policies but no management system, previously certified and lapsed, or mid-audit
  • Whether evidence exists already, or starts from nothing
  • Number of systems and third parties inside the compliance boundary, each of which needs its own diligence
  • Whether you have appointed an assessor already, and what they have told you
  • Whether the deadline is yours, or a customer contract, procurement gate, regulator or investor set it

If we are already building it

Every regulated build triggers a compliance conversation.

The build creates the trigger and this capability answers it, without anyone having to learn your architecture a second time. Sequencing that works: gap analysis first, because it is small, fixed fee, and produces a roadmap you can defend.

  • A health platform handling protected health information: Security Rule gap analysis, business associate scoping, policies and procedures
  • Payments, or anything touching cardholder data: PCI DSS scope reduction, SAQ eligibility, penetration testing
  • B2B software selling into US enterprise procurement: SOC 2 Type II readiness, then support through the observation period
  • An international or public sector sales motion: an ISMS against ISO/IEC 27001:2022, then certification support
  • Any platform with a real vendor footprint: a third-party risk program, designed and then monitored
  • After launch, any of the above: a vCISO retainer instead of the full-time hire you were about to make

Accessibility is a separate line

WCAG verification sits outside the compliance frameworks above, and we keep it separate on purpose. We deliver it as compliance QA against a stated conformance level, and you get findings you can act on.

A general accessibility claim is worth nothing to the buyer who asks for it. A verified level, with the exceptions named, is worth something.

Governing the AI in the delivery

Every engagement now runs on AI-First delivery, and that raises questions procurement asks before a contract is signed. These are our answers, and they are written down rather than improvised per deal.

Not every client wants AI used on their project, and that is a legitimate position. When a client has not agreed to it, the agreement governs, and the configuration that would make an agent useful stays out of the repository you can see.

  • An AI usage policy that states which client data may enter a prompt and which may not
  • Disclosure and consent recorded per engagement, not assumed from a master agreement
  • Data classification that names what counts as personal, confidential, or restricted before anyone has to judge it live
  • Tool vetting per vendor, including model training opt-out status and data retention terms
  • A distinct identity per agent, scoped to the systems it needs, with no shared credentials across agents or clients
  • An audit trail of agent actions, plus the named boundaries where an agent stops and a person decides

Questions worth asking

Does our data get used to train a model?
Not through us. Vendor selection includes checking training opt-out status and data retention terms before a tool is approved for client work, and a tool that cannot be configured to keep your data out of training does not get approved. Ask for the current approved list and we will send it, naming the setting we rely on for each one.
We have not agreed to AI being used on our project. What changes?
The agreement governs, and we hold to it. Where AI use is not disclosed, the committed configuration that makes agents useful is excluded from your repository, and developer machine setup enforces that rather than relying on anyone remembering. If you would like to revisit the position later, that is a conversation, not a default.
Which agent did what?
Each agent runs under its own identity, scoped to the systems it needs and no others, so the action log answers that question by construction. Credentials are never shared between agents or across clients. Secrets are the exception to all agent access: an agent references a variable name and never sees a value.
Can you make us HIPAA compliant?
No partner can, and be sceptical of one that says otherwise. HIPAA compliance is an organizational state covering your policies, training and business associate agreements, not just your software. There is also no HIPAA certification scheme, so nobody can certify you either. We can make your product's handling of protected health information defensible and give you the evidence for it, which is the part that is ours to do.
Do you issue the certificate?
Never. An ISO/IEC 27001 certificate comes from an accredited certification body, a SOC 2 report from a licensed CPA firm, a PCI DSS Report on Compliance from a Qualified Security Assessor. You engage them. We get you ready and support the process. The same boundary applies inside our own service line: a vCISO who designs and runs your management system cannot then independently assess it.
Is Koombea itself certified?
Ask us directly and we will answer in writing, naming what we hold and what we do not. What we can point to today is a development unit appraised at CMMI-DEV/3 and a written attestation on every build.
What does a vCISO actually do?
Owns the security direction, keeps the roadmap current, sits in the reviews your buyers put you through, and answers the questionnaires that arrive with every enterprise deal. It is the judgment of a security leader on a retainer rather than on a payroll, which is the right shape when you need the decisions more often than you need the seat.
Which SOC report do we need?
Tell us who is asking. US enterprise procurement usually means SOC 2 Type II. Type I proves the controls are designed, Type II proves they operated over a period, and that period is why Type II takes longer to reach. SOC 1 is a financial reporting scope and a different conversation. Naming the type is the first step, because SOC 2 with no type is not a scope.
Which frameworks can you actually evidence?
We will tell you plainly per framework rather than listing everything that exists. Where we have direct delivery experience we say so and show it. Where we do not, we say that too, because a framework claim is the sentence your legal team reads literally.
Where does our data live, and will you sign a BAA?
We work from Barranquilla and Naples, Florida. When an engagement touches protected health information or regulated personal data we state the data residency and subprocessor position up front, with whether a business associate agreement or data processing agreement is required and who signs it. Settle that before the work starts rather than during your vendor review.
Why is this not priced in story points?
Because a story point measures delivered functional scope, and an opinion has no functional surface area. Pretending otherwise would produce a number with no unit behind it, which is a number nobody can defend in a negotiation. The control implementation that follows a gap analysis is a build, and that part is pointed normally.
Is penetration testing included in our build?
No. A build implements security practices and ships with a written attestation covering the agreed security checks and any known critical or high-severity findings within that scope. Formal verification is a separate scoped engagement, priced by target count and test depth, because the value of a test is partly that it is not run by the people who wrote the code. Before anything is committed we agree the target list, the testing window, the rules of engagement and written authorization.
When should we start?
Before the architecture is settled, not after. Retrofitting an audit trail, a retention policy or a data residency constraint into a live system is the single most expensive way to acquire it.

Compliance work in production systems

Fashioned Health was built on HIPAA-ready infrastructure with PCI-compliant payment handling through Stripe. Koombea's development unit is appraised at CMMI-DEV/3.

Our compliance work has been delivered in finance, where the scope is transactions and cardholder data, in healthcare, where it is the privacy and security of patient information, and in technology, where it is infrastructure, intellectual property and operations. Those engagements sit under confidentiality, so we will walk you through them in the Priority Sync rather than name them on a page.

Bring us the backlog.

In 30 minutes, we will show you what a Pod would ship first and how we would price it.