Home Who We Work With Engagements Methodology Contact
Who We Work With

Teams building software that depends on the outside world

Our engagements work well when an organization already understands that third-party dependencies carry risk, and wants a structured process for understanding that risk specifically.

SaaS Product Companies

Products built on layers of open-source packages and cloud service integrations accumulate supply chain complexity quickly. The dependency tree that was manageable at launch looks quite different after two years of feature development.

For SaaS teams, the audit typically focuses on the npm, PyPI, or Maven dependency graph alongside the API integrations handling payments, authentication, and data processing.

Enterprise Engineering Organizations

Large organizations often have significant technical debt in their dependency landscape. Systems that have grown through acquisition, team changes, and platform migrations accumulate third-party components that no one has reviewed in years.

Enterprise engagements frequently involve multiple codebases, heterogeneous technology stacks, and the challenge of producing a coherent picture across all of them.

Growth-Stage Startups

Startups approaching enterprise sales, fundraising, or security certification often face questions about their supply chain posture for the first time. Understanding what you're running is a prerequisite for answering those questions accurately.

Early-stage teams benefit from engagements that establish a baseline and identify the highest-priority items before they become blockers.

Security and Compliance Teams

Information security professionals and compliance officers working toward frameworks like ISO 27001, SOC 2, or industry-specific standards often need external validation of their software supply chain practices.

We support those teams with structured documentation, SBOM generation, and findings that map to the requirements of the relevant framework.

CTO and lead engineer in consultation session reviewing technical documentation together
What We Hear Most

The situations that typically prompt an engagement

Teams come to us from a range of starting points. Some have had a security incident and want to understand their broader exposure. Others are preparing for a compliance audit. Some simply want the clarity that comes from having looked at everything systematically, even if nothing has gone wrong.

Post-incident review

After a supply chain incident, understanding the full scope of exposure becomes urgent.

Compliance preparation

Frameworks increasingly ask for documented evidence of supply chain due diligence.

Enterprise sales requirement

Large customers routinely ask security questionnaires that require this kind of visibility.

Periodic review cycle

Teams that have audited once and want to maintain an ongoing understanding of their posture.

Not the Right Fit

When a supply chain audit may not apply

Teams building entirely self-contained systems with no external packages or integrations — a rare scenario, but these engagements would not produce meaningful findings.

Organizations looking for a penetration test or application-layer security assessment. Our scope is the supply chain specifically, not the application security surface in general.

Teams that need real-time vulnerability scanning tooling deployed and managed. We provide audit services and advisory, not managed security tooling.