GuardVest · October 2, 2026
The right service depends on the problem in front of you. Do you need a security plan, a source-code review, a working foundation, continued leadership support or help with one assignment? Start with that decision, then choose the smallest scope that solves it.
Choose by what you need now
| Situation | Start here | What you get |
|---|---|---|
| “I have a specific security question.” | Ask GuardVest | A prepaid, one-hour minimum expert consultation to work through a decision. A written report or project work is separate. |
| “I need one defined task completed.” | Single-Purpose Engagement | A scoped work product using prepaid hours, such as a questionnaire, vendor review, policy or tabletop. |
| “I do not know our biggest gaps.” | Security Assessment | A four-week review, documented findings, a prioritized 90-day roadmap and leadership readout. |
| “I need to know what is vulnerable in our code.” | GuardVest ClearSight | A one-time, NDA-protected source-code assessment with analyst-reviewed findings and specific fixes. No ongoing subscription. |
| “We need a security foundation, not just a plan.” | Security Readiness Program | The Assessment plus ClearSight, tailored documents, an incident tabletop and external service recommendations over 90 days. |
| “We need continued senior security support.” | GuardVest 360 | The Readiness foundation plus advisory support, scorecards and leadership reporting during a six-month engagement. |
| “A customer needs a SOC 2 report.” | SOC 2 Readiness | Controls, evidence and remediation planning for Type I or Type II examination preparation. |
| “Our defense contract calls for CMMC.” | CMMC Self-Attestation Readiness | Boundary definition, safeguards review, documentation and evidence supporting self-assessment and leadership affirmation. |
| “We want federal agencies to use our cloud product.” | FedRAMP Readiness | Class A–D pathway planning, gap assessment and evidence preparation, including applicable agency overlays. |
What each engagement actually covers
Security Assessment: understand and prioritize
Eight one-hour sessions cover 100 core questions about your security practices and business needs. You receive an assessment report, response appendix, a 90-day action roadmap and a leadership presentation. Choose it when the main gap is clarity. Implementation is a separate scope.
GuardVest ClearSight: examine the code
ClearSight reviews an agreed source-code snapshot and repository history for exposed secrets, vulnerable components, code weaknesses and configuration risks. Multiple analysis methods and analyst review lead to a prioritized technical report with remediation guidance. It can be scoped as a one-time assessment or is included in Readiness and GuardVest 360. See an illustrative report.
Security Readiness Program: build the foundation
Over 90 days, Readiness includes the Security Assessment and ClearSight, plus 17 tailored security operating documents, a 60-minute incident tabletop and external service recommendations. Choose it when you need both the plan and the core materials to operate it. It includes the Assessment, so you do not buy that package again.
GuardVest 360: keep senior support close
The six-month program includes the full Readiness foundation in Months 1–3. Months 4–6 add up to 20 advisory hours per month for calls, written advice, agreed work and reporting, plus monthly scorecards, two board reports and a live board or investor briefing. Choose it when you expect ongoing decisions after the foundation is built. Unused monthly hours do not roll over.
Ask GuardVest and Single-Purpose: start with a focused need
Ask GuardVest is a prepaid live expert consultation for one question or decision. A Single-Purpose Engagement is for a defined deliverable: for example, completing a customer questionnaire, reviewing a vendor or drafting a policy. Its prepaid hours can be used across agreed assignments and do not expire.
SOC 2, CMMC and FedRAMP: prepare for the next requirement
For a defined customer or government requirement, explore SOC 2 Readiness for Type I and Type II preparation, CMMC Self-Attestation Readiness for defense-contracting safeguards and affirmation, or FedRAMP Readiness for cloud offerings serving federal agencies.
Each readiness engagement connects the required controls to evidence, accountable owners and a practical action plan. FedRAMP work can include Classes A–D, the applicable 20x or Rev5 path, DoD requirements, IRS Publication 1075 and other agency overlays.
A defined scope for your next milestone
We start with the actual customer request, your current environment and the outcome you need. Your engagement sets out the deliverables, responsibilities and milestones, including coordination with assessment partners where applicable.
A straightforward starting point
If you have no plan, begin with the Security Assessment. If you already know you need policies, a rehearsal and code review, choose Readiness. If you also need continuing senior support, choose GuardVest 360. For a narrow code question, choose ClearSight; for one task or decision, use the focused options.
Book a free 30-minute scoping call if you want GuardVest to help choose an appropriate scope before you commit.
Starting from zero? Read the founder’s first security plan.