Founder & Principal Consultant
ISO 27001 Lead Implementer
Owns certification programmes end to end, scoping, risk assessment, internal audit and Stage 2 support.
About innsecs
innsecs exists because SaaS companies keep being sold two halves of the same problem, a compliance platform that produces paperwork, and a testing vendor that produces a PDF. Neither one makes the product safer. We do both, in one programme, and we stay until the certificate is on the wall and the findings are actually fixed.
Why innsecs exists
The story is not glamorous. It is a pattern we saw enough times to build a company around fixing.
Every SaaS founder eventually hits the same wall. A large customer sends a security questionnaire, or procurement asks for an ISO 27001 certificate, and a deal that took nine months to build stalls behind a document nobody in the company knows how to produce.
The market's answer is to sell them a compliance automation tool. Tools are useful. They collect evidence and they monitor drift. But a tool cannot scope your ISMS, run a defensible risk assessment, write policies that match how your team actually works, conduct your internal audit, or sit across from an auditor and justify why a control was excluded.
So the founder buys the tool, spends a quarter filling in checkboxes, and still fails Stage 1.
Meanwhile, the security testing runs on a separate track with a separate vendor. A report arrives, a severity table is skimmed, a few criticals get fixed, and the rest of the findings quietly age out. Nobody retests. The next year the same classes of bug come back.
That report was also the strongest evidence available for ISO 27001 Annex A 8.8 and 8.29, technical vulnerability management and security testing in development. It sat in a folder while the compliance workstream wrote a policy claiming testing happens.
Splitting the two is how you end up certified and insecure at the same time.
innsecs runs certification and security testing as one engagement, with one team. The pentest is scheduled to feed the audit. The threat model informs the risk register. The remediation work closes findings and control gaps at the same time, because they were the same gaps.
We are deliberately built for SaaS. Not banks, not manufacturing, not a template written for a 5,000-person enterprise and shrunk. Multi-tenancy, cloud infrastructure, CI/CD, fast release cadence, small teams. That is the shape of the problem we solve.
What's different
None of these are novel ideas. They are just uncommon in combination, and we hold to them when it would be cheaper not to.
The people writing your Statement of Applicability are talking to the people testing your API. Evidence lands where it is needed instead of being re-created by a second vendor.
Multi-tenancy, cloud-first architecture, CI/CD, SSO and SCIM, rapid release cadence. We are not adapting an enterprise playbook downward.
Engagements are quoted as a defined scope with a defined price. No hourly drift, no surprise change orders halfway through the audit prep.
Machine analysis maps your attack surface, reads the whole repository and reconciles every tool. A consultant proves each finding before it reaches your report, so nothing unverified ever ships.
We read your code, your Terraform and your pipelines. Recommendations arrive as pull requests and IaC changes, not as console click-paths that drift back within a quarter.
You get the consultant you scoped with. No junior handoff after the kickoff call, no rotating roster mid-engagement.
If a scope will not achieve what you need, or if the timeline you want is not realistic, we say so before the contract rather than after Stage 1.
Our principles
Including the ones that occasionally cost us the work.
Passing an audit is a milestone, not an outcome. We design programmes that leave you measurably harder to attack, and we say so plainly when a control exists only to satisfy an auditor.
We do not pad reports. An inflated finding count makes an engagement look thorough and makes remediation impossible to prioritize. Every finding we raise is one we would defend in a room with your engineers.
Reproduction steps someone on your team can walk through. Remediation specific to your stack. Severity justified by exploitability and business impact, not a raw CVSS score copied from a scanner.
A finding is not closed because it was reported. Retesting is included in every testing engagement. If it is not verified fixed, we do not call it fixed.
A 25-person SaaS company does not need a bank's ISMS. We scope tightly, write policies you can actually follow, and refuse to hand over a 200-page document set nobody will ever open.
We will never claim to issue a certificate or an attestation. ISO 27001 certificates come from accredited certification bodies; SOC 2 reports come from licensed CPA firms. We prepare you, and we tell you exactly where our role ends.
Where we are
innsecs is young. We would rather say that plainly than imply a decade of history we do not have.
Started with a single conviction: certification support and offensive security should never have been sold separately.
End-to-end certification programmes built specifically for SaaS companies, with penetration testing included rather than subcontracted.
Manual-first application, API and cloud testing, with retesting included in every engagement as standard.
Retained programmes that maintain certification, run recurring testing, and keep a named security lead accountable year-round.
The team
You work with the consultant you scoped with. No junior handoff after the kickoff call.
ISO 27001 Lead Implementer
Owns certification programmes end to end, scoping, risk assessment, internal audit and Stage 2 support.
Application & API Testing
Manual-first testing across web, API and mobile surfaces, with a focus on authorization and tenant isolation.
AWS · Azure · GCP
Configuration and architecture review, attack-path analysis, and infrastructure-as-code remediation.
Evidence & Audit Support
Keeps evidence collection on rails and manages the auditor request list through fieldwork.
Hiring: we are always interested in consultants who can hold both halves of this work. Say hello.
Independence
innsecs is a consultancy, not a certification body and not an audit firm. We are not accredited to issue ISO 27001 certificates, and we are not a licensed CPA firm able to issue a SOC 2 report. Any consultancy that tells you otherwise is misrepresenting how these frameworks work.
What we do is build the management system, run the internal audit, perform the security testing, and prepare you for the external audit, then help you select and engage the independent body that certifies or attests.
Combining implementation with penetration testing under one consultancy is standard practice and explicitly permitted; our testing is an input to your evidence, which the certification body assesses independently. Combining implementation with certification is not permitted, and we never do it.
Questions
If your question is not here, ask it on a scoping call. They are free and we do not run a sales sequence off them.
No. innsecs is a consultancy. ISO 27001 certificates are issued by accredited certification bodies, and SOC 2 reports by licensed CPA firms, both of which must be independent of the party that implemented the controls. We build your programme, run the internal audit, and support you through the external audit. We will help you select and engage the certification body.
It would be if we were issuing the opinion, which is exactly why we do not. Our penetration testing is an input to your evidence, assessed independently by your certification body or CPA firm. Combining implementation and testing under one consultancy is common practice and explicitly permitted; combining implementation and certification is not, and we never do it.
Most of our work is with SaaS companies between roughly 10 and 250 people. Below that, certification is often premature and we will tell you so. Above that, you likely need in-house security leadership, and we are happy to help you hire it.
Yes. Engagements run remotely by default, which is how most SaaS companies operate anyway. Where an audit requires on-site attendance we will travel, and we work across North American, European and APAC time zones.
Engagements are fixed-scope and fixed-price rather than hourly. Pricing depends on your headcount, environment count, product complexity and starting maturity. A scoping call and a written proposal cost nothing, and we would rather tell you the number early than discover it together halfway through.
Tell us where you are: no ISMS at all, an audit date already booked, or a security questionnaire you cannot answer. We will tell you what it actually takes.
No sales sequence. A scoping call and a written proposal cost nothing.