GUARDVEST / CYBERSECURITY ADVISORY
Good questions.
Clear answers.
Find the right service, understand your deliverables, and know how support and payment work.
Choosing the right service
What does GuardVest actually do?
We help growing businesses understand security risks, create practical security policies and response materials, and get expert help with security decisions and assignments. You can choose an assessment, a readiness program, ongoing advisory support, a consultation, or a focused project.
Do I need to already have a security team?
No. Our services are designed for businesses that may not have a dedicated security leader. If you already have technical or security staff, our findings, documents and guidance give them a practical basis for deciding what to do next.
Which service should I start with?
Choose Security Assessment if you need to understand your gaps and priorities. Choose Security Readiness Program if you also need tailored documents, a source-code scan, a response rehearsal and service recommendations. Choose GuardVest 360 if you want that foundation plus continuing support. For one question, choose Ask GuardVest; for a defined work product, choose a Single-Purpose Engagement.
Do I have to buy the Assessment before Readiness or GuardVest 360?
No. The Security Readiness Program already includes the Security Assessment. GuardVest 360 includes the full Readiness foundation in its first three months. You do not need to purchase those included services separately.
Can I start smaller and expand later?
Yes. You can begin with a smaller engagement and discuss a larger scope as your needs develop. Before you upgrade, we confirm the work already completed, the additional deliverables and the applicable upgrade price.
Is the free scoping call the same as Ask GuardVest?
No. The free 30-minute scoping call helps us understand your priorities and identify an appropriate engagement. Ask GuardVest is a paid, one-hour minimum consultation for working through a specific security question or decision with an expert.
What you receive
What do I receive from the Security Assessment?
You receive an assessment report with documented findings and a response appendix, a prioritized 90-day action roadmap, and a leadership presentation and readout. The four-week engagement includes eight one-hour sessions covering 100 core questions about your business and security practices.
Does the Assessment include fixing the issues you find?
The Assessment identifies gaps and recommends actions; it does not include implementing every recommendation. Readiness adds specific deliverables such as tailored documents and a tabletop. Additional implementation or security assignments need to be included in your agreed scope.
Is the code scan a penetration test or continuous monitoring?
No. It is a one-time vulnerability scan of an agreed source-code snapshot. You receive a vulnerability report and executive findings presentation covering evidence, priority, impact and recommended fixes for your engineers. It does not provide continuous monitoring or a broad penetration test of your live systems; rescans require separate scope.
How is your source code protected during the vulnerability scan?
We sign a mutual NDA covering the confidential information shared for the engagement, including your source code. The scan uses an agreed snapshot of your code, rather than ongoing repository access. We use our proprietary vulnerability scanners solely to identify weaknesses and prepare your agreed findings. We do not use the code for unrelated purposes, modify your source code or deploy changes to your systems. The NDA sets out our confidentiality and permitted-use obligations; it does not mean the scan guarantees that every vulnerability will be found.
Are the 17 security documents templates we have to complete ourselves?
Our experts create the policies, procedures and response materials for your organization, tailored to your business. They are delivered as PDFs with one revision round. The full document list appears on the Readiness and GuardVest 360 pages. Editable source files are not included.
What is an incident tabletop, and what do we get from it?
It is a 60-minute facilitated rehearsal of a hypothetical security incident. Your team discusses how it would respond, communicate and make decisions. You receive a written exercise summary and action log. It is a rehearsal, rather than a live attack or an investigation into an actual incident.
Are the service recommendations a list of more GuardVest services to buy?
No. We assess what additional external security services your business may need and categorize them as needed now, able to wait, or not currently needed. You receive prioritized recommendations and a management report explaining the rationale. Purchasing or operating those services is separate from receiving the recommendations.
Will this make us certified, guarantee funding, or prevent every breach?
No. These services support better security decisions and preparation. They do not provide an independent certification or guarantee compliance, funding, customer acceptance, or the absence of vulnerabilities. Any required independent audit or certification is a separate process.
How GuardVest 360 support works
What happens during the six-month GuardVest 360 engagement?
Month 1 is the Security Assessment. Month 2 adds the one-time source-code scan, 17 tailored documents and incident tabletop. Month 3 covers external security service recommendations. Months 4–6 provide up to 60 additional support hours, allocated as 20 hours per month, for advice, agreed assignments and reporting.
Do the 60 support hours start in Month 1?
No. The additional 60-hour allowance applies to Months 4, 5 and 6, at 20 hours per month. The foundation deliverables in Months 1–3 are separate. Two one-hour calls each month and written advice between calls are included throughout the six-month engagement.
Are calls and written answers extra hours on top of the monthly allowance?
In Months 4–6, the two monthly one-hour calls, written advice, agreed security work and reporting all share the 20-hour monthly allowance. Written advice means you can send security questions between scheduled calls; the initial written response is within two business days, which is not a promise that every question will be fully resolved in that time.
Can we use the support for priorities that come up along the way?
Yes. We agree on assignments around your business needs and available capacity. Examples include customer questionnaires, policy updates, vendor reviews and custom security reports. These are examples, not a complete list. Work needs to fit the agreed scope and monthly allowance; additional work requires a separate agreement.
Do unused GuardVest 360 hours roll over?
No. Unused hours from each 20-hour allocation in Months 4–6 do not roll over. This differs from Single-Purpose Engagements, where unused prepaid hours never expire.
How will we see our progress?
GuardVest 360 includes six monthly scorecards, board reports in Months 3 and 6, and one live board or investor briefing during Months 4–6. These help leadership understand progress, remaining risks and the decisions that need attention.
Consultations, projects and payment
What is the difference between Ask GuardVest and a Single-Purpose Engagement?
Ask GuardVest is live expert advice at $250 per hour, prepaid, with a one-hour minimum. A Single-Purpose Engagement is scoped work that produces an agreed deliverable, using prepaid hours with pricing confirmed for your engagement. If you need us to complete a questionnaire or write a policy, choose a scoped project rather than assuming that work comes with a consultation.
Does Ask GuardVest include a written report or hands-on project work?
Ask GuardVest provides a live consultation to discuss your situation, evaluate options and clarify next steps. A separate written report, investigation or completed work product is not included in the consultation; those can be discussed as a Single-Purpose Engagement.
Does the Single-Purpose prepaid balance cover any project?
The initial prepaid balance provides 10 hours. It is a prepaid balance, not a flat price for any size of project. We agree on the assignment and deliverable before starting, and actual time worked draws down the balance. Additional time requires additional funding.
Can I use Single-Purpose hours for several assignments, and do they expire?
Yes. You can use the balance for one assignment or several scoped assignments. Unused prepaid Single-Purpose hours never expire. The examples on the service page are illustrative; we can discuss other security work your business needs.
When do I pay, and does payment alone start a project?
Ask GuardVest requires payment to confirm the consultation booking. For other engagements, confirm the scope and agreement with GuardVest before paying. Work begins after the required advance payment has cleared, unless we agree otherwise with you in writing. Making a payment alone does not define a project’s scope or start date.
Build boldly.
Grow securely.
Let’s talk about what your business needs. In a 30-minute scoping call, we discuss your priorities and recommend the right scope of support.
info@guardvest.co