Services

Full-spectrum security,
one accountable partner.

Offense, defense, and governance that work together — instead of a stack of vendors who don't talk to each other.

01

Application Penetration Testing

Deep, manual testing of your web, mobile, and API surfaces — auth flows, business logic, injection, access control, and supply-chain risk. We chain findings into real exploit paths and hand you a prioritized, reproducible fix list mapped to OWASP.

Request this service
02

Network Penetration Testing

External perimeter and internal/Active Directory testing that mirrors an intruder's kill chain — from initial foothold to lateral movement and domain compromise. You get a clear map of what's exposed, how far it goes, and exactly how to close it.

Request this service
03

Compliance as Code

We turn frameworks into automated, testable controls with NOMARCH, our compliance platform. ISO 27001, NIST 800-53, SOC 2 and more become hardened checks that run continuously across your fleet, self-heal on drift, and produce audit-ready evidence — no spreadsheets, no guesswork.

Request this service
04

SOC & Managed Detection

Round-the-clock monitoring across endpoints, identity, and cloud, run by analysts — not just tooling. Tuned detections cut alert fatigue, and every real threat is triaged, escalated, and contained in minutes. Continuous threat hunting keeps you ahead of what's next.

Request this service
05

Incident Response

When something breaks, our responders take point: scoping, digital forensics, containment, eradication, and a board-ready post-incident report. Response retainers keep our team one call away, so dwell time — and cost — stays low.

Request this service
06

Security Product Engineering

Our engineers design and ship security products end to end: agents, detection engines, guardrailed AI, and multi-tenant platforms. NOMARCH is our flagship. We also partner with teams to architect and build custom security tooling that stands up to real-world threat models.

Request this service
How we work

A clear path from risk to resilience

  1. 01

    Scope

    We map your assets, threat model, and objectives in a focused kickoff.

  2. 02

    Assess

    Our operators test, monitor, or architect — depending on the engagement.

  3. 03

    Report

    Prioritized findings with reproducible steps and clear remediation.

  4. 04

    Harden

    We verify fixes and stand up controls so the gap stays closed.

Consulting engagements

Ways to work with our team

Pick a delivery model for our services. Looking for our compliance SaaS instead? Jump to NOMARCH pricing ↓

Project

Fixed scope

A defined assessment with a clear deliverable and timeline.

  • Point-in-time testing
  • Executive + technical report
  • Remediation retest
Get started
Most popular

Retainer

Always-on

Continuous monitoring and a response team on standby.

  • 24/7 SOC coverage
  • Priority incident response
  • Quarterly red-team
  • Dedicated lead
Get started

Advisory

Fractional

A virtual CISO to steer strategy, compliance, and architecture.

  • Program roadmap
  • Board reporting
  • Compliance guidance
Get started
NOMARCH · SaaS platform

Compliance pricing that scales with your fleet

One lightweight agent per Windows host. Pay only for the hosts you protect — 14-day free trial, cancel anytime, and two months free when you bill annually.

Estimate your plan
1250500+

One NOMARCH agent runs per host. Drag to match your fleet size.

Recommended plan
Business
Per month$300
Per year (2 months free)$3,000
$6/host · 50 hosts
Start free trial

Starter

$9/host / mo
Up to 25 hosts

For small teams getting their first fleet to continuous compliance.

  • 1 organization
  • All 10 built-in frameworks
  • Self-healing remediation
  • Live agent + dashboard
  • Email support
Start free trial
Most popular

Business

$6/host / mo
26 – 250 hosts

For growing security teams and MSPs running multiple tenants.

  • Up to 5 organizations
  • Custom & cloned baselines
  • API + webhook access
  • Priority support & onboarding
  • Volume pricing per host
Start free trial

Enterprise

Custom
250+ hosts

For regulated enterprises and air-gapped or on-prem deployments.

  • Unlimited organizations
  • SSO / SAML + audit exports
  • On-prem / air-gapped option
  • Dedicated engineer + SLA
  • Custom frameworks & integrations
Contact sales

Prices in USD, billed per active host. Nonprofit and education discounts available. Need an exact quote? Talk to us.

Ready when they are

Find your weak points before attackers do.

Book a scoping call and get a threat-model of your environment within 48 hours — no obligation, no jargon.