What we document
Controls that satisfy insurers, clients, and auditors.
Cyber insurance application support
Insurers are asking harder questions and denying more claims on technicalities. We help you document your actual controls accurately, avoid gaps that invalidate coverage, and understand what you are agreeing to.
Vendor and client security questionnaires
Clients and partners increasingly require you to prove your security posture before signing contracts. We help you complete these accurately and build the documentation behind your answers.
Security policy documentation
Acceptable use policy, password policy, onboarding and offboarding procedures, incident response plan. Written in plain language, appropriate for your size, actually used rather than filed away.
Security baseline documentation
A documented record of your controls: what is in place, what version, when last reviewed. Required for most cyber insurance renewals and increasingly for client contracts.
Risk assessment and gap analysis
An honest look at where your risk is concentrated, what the business impact would be, and what you need to do to close the gaps that matter most for compliance and insurance.
Evidence collection for audits
If you are facing an audit or renewal and need to pull together evidence of controls, we help you collect, organize, and present it in the format that actually satisfies reviewers.
When compliance gaps become expensive
Most problems are fixable. Most are also preventable.
Your cyber insurance renewal is asking for MFA, EDR, and backups
If you cannot confirm these controls, your premium goes up or your claim gets denied. We document what you have and close what is missing.
A client wants you to complete a security questionnaire before contract signing
Most small businesses cannot answer these confidently. We build the documentation and controls so you can say yes honestly.
You had a security incident and your insurer is investigating your controls at time of loss
If you cannot prove the controls you claimed to have, the claim is denied. Documentation that existed before the incident is the only documentation that counts.
You have never written a security policy
Insurers, clients, and auditors all ask for them. We write policies that are appropriate for your size and actually reflect how you operate.

From the founder
“When you reach out, I read it personally and respond within one business day. Not a ticket system. Not a junior rep. Me.”
Otto Mand
Founder & Lead Engineer, EagleOnyx