Skip to content

About innsecs

Compliance and security, run by the same people.

innsecs exists because SaaS companies keep being sold two halves of the same problem, a compliance platform that produces paperwork, and a testing vendor that produces a PDF. Neither one makes the product safer. We do both, in one programme, and we stay until the certificate is on the wall and the findings are actually fixed.

93
Annex A controls covered
ISO 27001:2022, end to end
12–20
Weeks to audit-ready
Typical SaaS engagement
100%
Human-verified findings
AI widens coverage, people confirm exploitability
0
Findings left unverified
Retesting is included, never billed extra

Why innsecs exists

We got tired of watching good companies do this the expensive way.

The story is not glamorous. It is a pattern we saw enough times to build a company around fixing.

01

The problem we kept watching

Every SaaS founder eventually hits the same wall. A large customer sends a security questionnaire, or procurement asks for an ISO 27001 certificate, and a deal that took nine months to build stalls behind a document nobody in the company knows how to produce.

The market's answer is to sell them a compliance automation tool. Tools are useful. They collect evidence and they monitor drift. But a tool cannot scope your ISMS, run a defensible risk assessment, write policies that match how your team actually works, conduct your internal audit, or sit across from an auditor and justify why a control was excluded.

So the founder buys the tool, spends a quarter filling in checkboxes, and still fails Stage 1.

02

The other half nobody joins up

Meanwhile, the security testing runs on a separate track with a separate vendor. A report arrives, a severity table is skimmed, a few criticals get fixed, and the rest of the findings quietly age out. Nobody retests. The next year the same classes of bug come back.

That report was also the strongest evidence available for ISO 27001 Annex A 8.8 and 8.29, technical vulnerability management and security testing in development. It sat in a folder while the compliance workstream wrote a policy claiming testing happens.

Splitting the two is how you end up certified and insecure at the same time.

03

What we built instead

innsecs runs certification and security testing as one engagement, with one team. The pentest is scheduled to feed the audit. The threat model informs the risk register. The remediation work closes findings and control gaps at the same time, because they were the same gaps.

We are deliberately built for SaaS. Not banks, not manufacturing, not a template written for a 5,000-person enterprise and shrunk. Multi-tenancy, cloud infrastructure, CI/CD, fast release cadence, small teams. That is the shape of the problem we solve.

What's different

7 reasons teams pick us over a platform or a big-four proposal.

None of these are novel ideas. They are just uncommon in combination, and we hold to them when it would be cheaper not to.

One team, both halves

The people writing your Statement of Applicability are talking to the people testing your API. Evidence lands where it is needed instead of being re-created by a second vendor.

SaaS-native

Multi-tenancy, cloud-first architecture, CI/CD, SSO and SCIM, rapid release cadence. We are not adapting an enterprise playbook downward.

Fixed scope, fixed price

Engagements are quoted as a defined scope with a defined price. No hourly drift, no surprise change orders halfway through the audit prep.

AI for coverage, humans for the verdict

Machine analysis maps your attack surface, reads the whole repository and reconciles every tool. A consultant proves each finding before it reaches your report, so nothing unverified ever ships.

Engineering-fluent

We read your code, your Terraform and your pipelines. Recommendations arrive as pull requests and IaC changes, not as console click-paths that drift back within a quarter.

Named people, not a bench

You get the consultant you scoped with. No junior handoff after the kickoff call, no rotating roster mid-engagement.

Honest about limits

If a scope will not achieve what you need, or if the timeline you want is not realistic, we say so before the contract rather than after Stage 1.

Our principles

What we commit to on every engagement.

Including the ones that occasionally cost us the work.

  1. 01

    The certificate is the start, not the finish

    Passing an audit is a milestone, not an outcome. We design programmes that leave you measurably harder to attack, and we say so plainly when a control exists only to satisfy an auditor.

  2. 02

    Risk over noise

    We do not pad reports. An inflated finding count makes an engagement look thorough and makes remediation impossible to prioritize. Every finding we raise is one we would defend in a room with your engineers.

  3. 03

    Written for the people who fix it

    Reproduction steps someone on your team can walk through. Remediation specific to your stack. Severity justified by exploitability and business impact, not a raw CVSS score copied from a scanner.

  4. 04

    We stay for the retest

    A finding is not closed because it was reported. Retesting is included in every testing engagement. If it is not verified fixed, we do not call it fixed.

  5. 05

    Sized to the company you are

    A 25-person SaaS company does not need a bank's ISMS. We scope tightly, write policies you can actually follow, and refuse to hand over a 200-page document set nobody will ever open.

  6. 06

    Independence where it matters

    We will never claim to issue a certificate or an attestation. ISO 27001 certificates come from accredited certification bodies; SOC 2 reports come from licensed CPA firms. We prepare you, and we tell you exactly where our role ends.

Where we are

A short history, honestly told.

innsecs is young. We would rather say that plainly than imply a decade of history we do not have.

2026

innsecs founded

Started with a single conviction: certification support and offensive security should never have been sold separately.

2026

ISO 27001:2022 practice launched

End-to-end certification programmes built specifically for SaaS companies, with penetration testing included rather than subcontracted.

2026

Security testing practice

Manual-first application, API and cloud testing, with retesting included in every engagement as standard.

Next

Continuous assurance

Retained programmes that maintain certification, run recurring testing, and keep a named security lead accountable year-round.

The team

Named people, not a rotating bench.

You work with the consultant you scoped with. No junior handoff after the kickoff call.

IN

Founder & Principal Consultant

ISO 27001 Lead Implementer

Owns certification programmes end to end, scoping, risk assessment, internal audit and Stage 2 support.

SE

Lead Security Engineer

Application & API Testing

Manual-first testing across web, API and mobile surfaces, with a focus on authorization and tenant isolation.

CS

Cloud Security Consultant

AWS · Azure · GCP

Configuration and architecture review, attack-path analysis, and infrastructure-as-code remediation.

CA

Compliance Analyst

Evidence & Audit Support

Keeps evidence collection on rails and manages the auditor request list through fieldwork.

Hiring: we are always interested in consultants who can hold both halves of this work. Say hello.

Independence

Where our role ends, stated up front.

innsecs is a consultancy, not a certification body and not an audit firm. We are not accredited to issue ISO 27001 certificates, and we are not a licensed CPA firm able to issue a SOC 2 report. Any consultancy that tells you otherwise is misrepresenting how these frameworks work.

What we do is build the management system, run the internal audit, perform the security testing, and prepare you for the external audit, then help you select and engage the independent body that certifies or attests.

Combining implementation with penetration testing under one consultancy is standard practice and explicitly permitted; our testing is an input to your evidence, which the certification body assesses independently. Combining implementation with certification is not permitted, and we never do it.

Questions

Before you get in touch.

If your question is not here, ask it on a scoping call. They are free and we do not run a sales sequence off them.

No. innsecs is a consultancy. ISO 27001 certificates are issued by accredited certification bodies, and SOC 2 reports by licensed CPA firms, both of which must be independent of the party that implemented the controls. We build your programme, run the internal audit, and support you through the external audit. We will help you select and engage the certification body.

It would be if we were issuing the opinion, which is exactly why we do not. Our penetration testing is an input to your evidence, assessed independently by your certification body or CPA firm. Combining implementation and testing under one consultancy is common practice and explicitly permitted; combining implementation and certification is not, and we never do it.

Most of our work is with SaaS companies between roughly 10 and 250 people. Below that, certification is often premature and we will tell you so. Above that, you likely need in-house security leadership, and we are happy to help you hire it.

Yes. Engagements run remotely by default, which is how most SaaS companies operate anyway. Where an audit requires on-site attendance we will travel, and we work across North American, European and APAC time zones.

Engagements are fixed-scope and fixed-price rather than hourly. Pricing depends on your headcount, environment count, product complexity and starting maturity. A scoping call and a written proposal cost nothing, and we would rather tell you the number early than discover it together halfway through.

Work with a team that owns both halves.

Tell us where you are: no ISMS at all, an audit date already booked, or a security questionnaire you cannot answer. We will tell you what it actually takes.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.