Skip to content

AI-assisted security testing · ISO 27001 · SOC 2

Get audit-ready.
Then prove it holds.

innsecs takes SaaS companies from no ISMS to audit-ready for ISO 27001, then tests the product like an attacker would, so the certificate you earn reflects something real. One team, both halves.

Fixed price · Retesting included · We’ll tell you if you don’t need us

ISO 27001
Full certification programme
SOC 2
Type I & II readiness
Pentest
Web, API, cloud, retest included
vCISO
Security leadership on retainer

Cloud environments we test

  • Azure

The innsecs difference

Compliance and security are sold separately. That is the bug.

A compliance platform produces evidence. A testing vendor produces a PDF. Neither one makes your product safer, and neither one talks to the other.

We run both. The penetration test feeds your Annex A 8.8 and 8.29 evidence. The threat model populates your risk register. Remediation closes findings and control gaps at once, because they were always the same gaps.

innsecs, engagement
$ innsecs run --programme iso-27001 --with-testing
isms scope defined & signed off
93 annex a controls assessed
risk register populated from real threat model
authorization & tenant isolation tested
cloud exposure validated across environments
internal audit complete · management review logged
evidence: mapped control-by-control
findings: retested and verified closed
outcome: stage 2 ready

AI-first security testing

AI for coverage. Humans for the verdict.

Machines are better at enumerating a large attack surface, reading an entire repository and reconciling tools that disagree. People are better at judging what is genuinely exploitable. We built the practice around that split.

01

Attack surface mapping at machine speed

Subdomains, endpoints, parameters, undocumented API routes, forgotten staging hosts and third-party assets, enumerated continuously rather than once at kickoff. A human tester working alone covers what fits in the engagement window; this covers what exists.

02

Whole-repository code and IaC review

Language models read every route handler, policy file and Terraform module looking for the patterns that matter in SaaS: missing tenancy filters, authorization checks that depend on client input, over-permissive IAM, secrets in history. Every candidate goes to a consultant, never to your report.

03

Correlation across every source

SAST, dependency scanning, cloud posture, DAST and manual testing produce overlapping, contradictory output. We reconcile them into one ranked list, collapse duplicates, and suppress the classes we have already proven are noise in your environment.

No finding reaches your report until a consultant has reproduced it. AI proposes; a named person proves or discards. That verification step is why our reports are short, our false positive rate is near zero, and our pricing sits at roughly half the market rate.

Regulatory compliance

Not every rule waits to be asked about.

ISO 27001 and SOC 2 are chosen, a customer asks and you comply. GDPR, HIPAA, COPPA and PCI DSS apply by law from the day you touch the data. We cover both kinds.

GDPR

By law

EU & UK

Applies ifYou have any users, customers or staff in the EU or UK.

Full guide

HIPAA

By law

United States

Applies ifYou touch protected health information for a US covered entity.

Full guide

COPPA

By law

United States

Applies ifYour service is directed at under-13s, or you know they use it.

Full guide

CCPA / CPRA

By law

California, US

Applies ifYou do business with California residents above the revenue or data thresholds.

Full guide

PCI DSS

By law

Global

Applies ifYou store, process or transmit cardholder data, including via an embedded payment form.

Full guide

FERPA

By law

United States

Applies ifYou handle student education records for US schools or districts.

Full guide

NIS2

By law

European Union

Applies ifYou are an EU cloud, managed service or other in-scope essential entity.

Full guide

Cloud security testing

We test where you actually run.

Every platform below gets a real configuration and architecture review, IAM chains, exposure, secrets, logging and workloads. Not a scanner export with a compliance percentage on it.

Amazon Web Services

The deepest surface we test. IAM is where AWS environments quietly go wrong, and it is almost never a single bad policy. It is a chain.

Full AWS assessment guide

What we find most often

A CI role assumable from an unrestricted GitHub OIDC condition, chaining into production admin.

Assessed surfaces

  • IAM roles, policies, trust relationships & privilege escalation paths
  • S3 bucket policies, ACLs, Block Public Access & pre-signed URL handling
  • VPC design, security groups, NACLs & internet-facing exposure
  • KMS key policies, Secrets Manager, SSM Parameter Store
  • CloudTrail coverage, GuardDuty, log integrity & retention
  • EKS RBAC, ECS task roles, Lambda execution permissions
  • CodeBuild / CodePipeline permissions & OIDC trust from CI

Free tool · No signup for your score

Most teams find their gaps during a failed audit.

There is a cheaper way to find out. 12 questions, each mapped to a named ISO 27001:2022 control, across 6 domains. You get a readiness score, your gaps ranked by what they would actually cost you, and an honest timeline.

Takes about four minutes. Your score and top three gaps are free and ungated.

What you get back

  • A readiness score out of 100With the band that matches it, and what that band actually means for an audit.
  • Your gaps, rankedOrdered by what they cost you in an audit and in a real incident, not by how easy they are to fix.
  • Control-by-control mappingEvery gap tied to the specific ISO 27001:2022 Annex A control it fails.
  • A realistic timelineHow long from where you are to audit-ready. Including when the answer is 'not yet'.

How we work

Clear scope. Deep testing. Fixes that get verified.

Built around engineering reality: understand the system, test what matters, prove the impact, then help your team close it properly.

Step 01

Scope

We map your product, environments, team and buyer requirements, then define exactly what the engagement covers, and what it does not.

Step 02

Assess

Gap analysis against the standard, and manual security testing against the running product. Both against the same system, by the same team.

Step 03

Remediate

We build the ISMS, write the policies, and work alongside your engineers to close the technical findings. A working relationship, not a handover.

Step 04

Certify & verify

Internal audit, management review, Stage 1 and Stage 2 support, plus a retest proving every finding is actually closed.

Honest comparison

A consultancy, a platform, or a large audit firm.

All three get sold into the same problem, and they solve genuinely different parts of it. Here is where each one actually wins.

Scopes your ISMS and writes the Statement of Applicability

innsecs
Yes
Compliance platform
No
Large audit firm
Yes

Runs a defensible risk assessment on your actual architecture

innsecs
Yes
Compliance platform
Partial
Large audit firm
Yes

Policies written for your business, not templates

innsecs
Yes
Compliance platform
No
Large audit firm
Partial

Manual penetration testing included in the same engagement

innsecs
Yes
Compliance platform
No
Large audit firm
No

Findings retested and verified closed, at no extra cost

innsecs
Yes
Compliance platform
No
Large audit firm
No

Named senior consultant for the whole engagement

innsecs
Yes
Compliance platform
No
Large audit firm
No

Reads your Terraform and reviews your pull requests

innsecs
Yes
Compliance platform
No
Large audit firm
No

Continuous evidence collection and drift monitoring

innsecs
Partial
Compliance platform
Yes
Large audit firm
No

Fixed price, held for the engagement

innsecs
Yes
Compliance platform
Yes
Large audit firm
No

Can issue your certificate

innsecs
No
Compliance platform
No
Large audit firm
No

The last row is not a typo. No consultancy, platform or audit firm can issue your ISO 27001 certificate, only an accredited certification body can, and it must be independent of whoever built your controls. Anyone claiming otherwise is misrepresenting how the standard works.

Our commitments

Four promises, including one that costs us money.

01

Fixed price, held

The figure in your proposal is the figure you pay. Anything genuinely outside scope gets quoted separately, never invoiced quietly.

02

Retesting included

Every finding is retested and the report reissued with verified fix status. A finding isn't closed because it was reported.

03

We'll tell you not to buy

If certification is premature for your stage, or your timeline isn't achievable, we say so before the contract, not after Stage 1.

04

The people you met do the work

You get the consultant you scoped with. No junior handoff after kickoff, no rotating bench mid-engagement.

Common questions

The things everyone asks first.

More on the about page, or ask us directly.

No. Certificates are issued by accredited certification bodies, which must be independent of whoever implemented your controls. We build the ISMS, run the internal audit, and support you through Stage 1 and Stage 2, and we help you select the certification body.

The standard does not name one outright, but Annex A 8.8 and 8.29 are very difficult to evidence convincingly without independent security testing. Auditors expect it. We include it in the programme rather than leaving you to source it separately.

For a SaaS company of 10–100 people with reasonable engineering hygiene, 12–20 weeks to audit-ready is realistic, plus the certification body's own scheduling for Stage 1 and Stage 2.

They solve different problems. A tool collects and monitors evidence. It does not scope your ISMS, run a defensible risk assessment, write policies that match your business, conduct your internal audit, or defend a control decision to an auditor. We work alongside whichever platform you use.

Yes, GDPR, HIPAA, COPPA, CCPA/CPRA, PCI DSS, FERPA, NIS2 and ISO 27701. These differ from ISO 27001 and SOC 2 in an important way: they apply by law because of the data you hold, not because a customer asked. We start by establishing which genuinely bind you, which is often fewer than a vendor questionnaire implies.

AWS, Microsoft Azure, Google Cloud, DigitalOcean, Linode / Akamai Cloud and Vultr, plus on-premise and hybrid estates. We assess IAM and privilege escalation paths, internet-facing exposure, secrets handling, logging coverage and workload security on each.

Know exactly what an auditor, and an attacker, would find.

Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.