GDPR
By lawEU & UK
Applies ifYou have any users, customers or staff in the EU or UK.
AI-assisted security testing · ISO 27001 · SOC 2
innsecs takes SaaS companies from no ISMS to audit-ready for ISO 27001, then tests the product like an attacker would, so the certificate you earn reflects something real. One team, both halves.
Fixed price · Retesting included · We’ll tell you if you don’t need us
Cloud environments we test
The innsecs difference
A compliance platform produces evidence. A testing vendor produces a PDF. Neither one makes your product safer, and neither one talks to the other.
We run both. The penetration test feeds your Annex A 8.8 and 8.29 evidence. The threat model populates your risk register. Remediation closes findings and control gaps at once, because they were always the same gaps.
What we do
Certification and privacy programmes, offensive security testing, and the advisory work that keeps both from decaying six months after the audit.
AI-first security testing
Machines are better at enumerating a large attack surface, reading an entire repository and reconciling tools that disagree. People are better at judging what is genuinely exploitable. We built the practice around that split.
Subdomains, endpoints, parameters, undocumented API routes, forgotten staging hosts and third-party assets, enumerated continuously rather than once at kickoff. A human tester working alone covers what fits in the engagement window; this covers what exists.
Language models read every route handler, policy file and Terraform module looking for the patterns that matter in SaaS: missing tenancy filters, authorization checks that depend on client input, over-permissive IAM, secrets in history. Every candidate goes to a consultant, never to your report.
SAST, dependency scanning, cloud posture, DAST and manual testing produce overlapping, contradictory output. We reconcile them into one ranked list, collapse duplicates, and suppress the classes we have already proven are noise in your environment.
No finding reaches your report until a consultant has reproduced it. AI proposes; a named person proves or discards. That verification step is why our reports are short, our false positive rate is near zero, and our pricing sits at roughly half the market rate.
Regulatory compliance
ISO 27001 and SOC 2 are chosen, a customer asks and you comply. GDPR, HIPAA, COPPA and PCI DSS apply by law from the day you touch the data. We cover both kinds.
EU & UK
Applies ifYou have any users, customers or staff in the EU or UK.
United States
Applies ifYou touch protected health information for a US covered entity.
United States
Applies ifYour service is directed at under-13s, or you know they use it.
California, US
Applies ifYou do business with California residents above the revenue or data thresholds.
Global
Applies ifYou store, process or transmit cardholder data, including via an embedded payment form.
United States
Applies ifYou handle student education records for US schools or districts.
European Union
Applies ifYou are an EU cloud, managed service or other in-scope essential entity.
Cloud security testing
Every platform below gets a real configuration and architecture review, IAM chains, exposure, secrets, logging and workloads. Not a scanner export with a compliance percentage on it.
The deepest surface we test. IAM is where AWS environments quietly go wrong, and it is almost never a single bad policy. It is a chain.
A CI role assumable from an unrestricted GitHub OIDC condition, chaining into production admin.
Free tool · No signup for your score
There is a cheaper way to find out. 12 questions, each mapped to a named ISO 27001:2022 control, across 6 domains. You get a readiness score, your gaps ranked by what they would actually cost you, and an honest timeline.
Takes about four minutes. Your score and top three gaps are free and ungated.
How we work
Built around engineering reality: understand the system, test what matters, prove the impact, then help your team close it properly.
We map your product, environments, team and buyer requirements, then define exactly what the engagement covers, and what it does not.
Gap analysis against the standard, and manual security testing against the running product. Both against the same system, by the same team.
We build the ISMS, write the policies, and work alongside your engineers to close the technical findings. A working relationship, not a handover.
Internal audit, management review, Stage 1 and Stage 2 support, plus a retest proving every finding is actually closed.
Honest comparison
All three get sold into the same problem, and they solve genuinely different parts of it. Here is where each one actually wins.
| Capability | innsecs | Compliance platform | Large audit firm |
|---|---|---|---|
| Scopes your ISMS and writes the Statement of Applicability | Yes | No | Yes |
| Runs a defensible risk assessment on your actual architecture | Yes | Partial | Yes |
| Policies written for your business, not templates | Yes | No | Partial |
| Manual penetration testing included in the same engagement | Yes | No | No |
| Findings retested and verified closed, at no extra cost | Yes | No | No |
| Named senior consultant for the whole engagement | Yes | No | No |
| Reads your Terraform and reviews your pull requests | Yes | No | No |
| Continuous evidence collection and drift monitoring | Partial | Yes | No |
| Fixed price, held for the engagement | Yes | Yes | No |
| Can issue your certificate | No | No | No |
Scopes your ISMS and writes the Statement of Applicability
Runs a defensible risk assessment on your actual architecture
Policies written for your business, not templates
Manual penetration testing included in the same engagement
Findings retested and verified closed, at no extra cost
Named senior consultant for the whole engagement
Reads your Terraform and reviews your pull requests
Continuous evidence collection and drift monitoring
Fixed price, held for the engagement
Can issue your certificate
The last row is not a typo. No consultancy, platform or audit firm can issue your ISO 27001 certificate, only an accredited certification body can, and it must be independent of whoever built your controls. Anyone claiming otherwise is misrepresenting how the standard works.
Our commitments
The figure in your proposal is the figure you pay. Anything genuinely outside scope gets quoted separately, never invoiced quietly.
Every finding is retested and the report reissued with verified fix status. A finding isn't closed because it was reported.
If certification is premature for your stage, or your timeline isn't achievable, we say so before the contract, not after Stage 1.
You get the consultant you scoped with. No junior handoff after kickoff, no rotating bench mid-engagement.
No. Certificates are issued by accredited certification bodies, which must be independent of whoever implemented your controls. We build the ISMS, run the internal audit, and support you through Stage 1 and Stage 2, and we help you select the certification body.
The standard does not name one outright, but Annex A 8.8 and 8.29 are very difficult to evidence convincingly without independent security testing. Auditors expect it. We include it in the programme rather than leaving you to source it separately.
For a SaaS company of 10–100 people with reasonable engineering hygiene, 12–20 weeks to audit-ready is realistic, plus the certification body's own scheduling for Stage 1 and Stage 2.
They solve different problems. A tool collects and monitors evidence. It does not scope your ISMS, run a defensible risk assessment, write policies that match your business, conduct your internal audit, or defend a control decision to an auditor. We work alongside whichever platform you use.
Yes, GDPR, HIPAA, COPPA, CCPA/CPRA, PCI DSS, FERPA, NIS2 and ISO 27701. These differ from ISO 27001 and SOC 2 in an important way: they apply by law because of the data you hold, not because a customer asked. We start by establishing which genuinely bind you, which is often fewer than a vendor questionnaire implies.
AWS, Microsoft Azure, Google Cloud, DigitalOcean, Linode / Akamai Cloud and Vultr, plus on-premise and hybrid estates. We assess IAM and privilege escalation paths, internet-facing exposure, secrets handling, logging coverage and workload security on each.
Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.