
Your Outsourced Security Office
When a customer sends a security questionnaire, when your insurer demands proof of controls, when a PCI form or vendor review lands in your inbox, you forward it to us. We handle it on your behalf. Your IT vendor cannot grade its own homework; we work for you, with no conflict of interest.
Fractional CISO leadership from a certified security executive (CISM, CISA, CGRC). Veteran-owned. Federal-grade discipline, applied to your business.
Security demands should not become your second job.
Forward it to us.
The questionnaire, the insurance form, the vendor review, the compliance notice. Whatever lands, you send it our way instead of losing a week to it. We already know your environment, so nothing starts from zero.
We handle it on your behalf.
We prepare the responses, assemble the evidence, and manage the back-and-forth with whoever is asking. You review and sign off. Your name goes on work a certified security firm stands behind.
You stay covered between demands.
Every month you get a signed posture attestation on file, at least one real improvement delivered, and a security partner who answers when something looks wrong. The next demand arrives to a business that is already ready.
We should talk if...
Every one of these starts with a free 30-minute diagnostic call. No cost, no obligation.
NEW VENDOR
You are bringing in a new vendor and they will touch your systems or data.
"The POS installer asks for remote access to finish setup. Nobody checks what else they can reach."
COMPLIANCE UNCERTAINTY
You are not sure you actually meet PCI, HIPAA, or rules for donor and children's data.
"Your card processor sends a PCI form. It has been sitting in the inbox for three weeks."
DATA LEAKAGE
You worry about employees leaking data through email, file shares, or AI tools.
"An employee pastes the client list into a free AI tool to draft emails faster."
POSSIBLE INCIDENT
Something happened recently and you are not sure if your business was affected.
"A customer says they got a strange invoice from your email address. You hope it was nothing."
NEVER INDEPENDENTLY REVIEWED
No one independent has ever reviewed your security, only the people who built it.
"Your IT company says everything is fine. They are grading their own homework."
GROWTH & CHANGE
You are growing, changing systems, integrating AI or moving to the cloud and want it done safely.
"New location, new systems, new logins. Security is the last box on the checklist."
How it works
One program, four levels. Pick the depth, we quote it after your free call.
1. The free diagnostic.
30 minutes, plain English, no technical preparation. We ask about your business, your systems, your vendors, and what worries you. You leave with your top two or three priorities, whether or not we ever work together.
2. We tell you which level fits.
Most businesses need less than they fear and more than they have. If a simple baseline tier fits, we say so. If a customer, insurer, or regulator is creating a deadline, Core Assurance is built for exactly that.
3. Onboarding in the first 30 days.
We baseline your environment, document where you stand, and put your first monthly attestation and first improvement action on the calendar. From then on, security demands go to us, not to the bottom of your inbox.
Compare the levels
Every business needs someone accountable for security. Most small businesses cannot justify hiring one. The Baseline tiers give you a fixed-price security partner: pick the level that fits, and upgrade only when your obligations grow. Every tier includes a monthly posture attestation, a one-page record that security is actively managed, signed by a certified security firm, on file every month. And every tier fixes something: at least one improvement action is delivered every single month, so the subscription never sits idle.
Questions owners ask
Is this a replacement for my IT company?
No. Your IT provider builds and runs the environment. We independently verify it is secure and handle the security demands your IT vendor was never hired to answer. The two roles work best together, and the separation is exactly what customers, insurers, and auditors want to see.
What does the free diagnostic actually cover?
It is a 30-minute fit and scoping call. We ask about your business, your systems, and what is being asked of you, then tell you which level fits and why. It is not a consultation and does not produce deliverables or technical answers. If you need expert answers today, the paid VIP consultation is the right lane.
We just received a questionnaire with a deadline. Can you take it over?
Yes, that is the core of Core Assurance. Bring the questionnaire, the renewal notice, or the compliance form to the diagnostic. We scope against your deadline and quote a fixed monthly price. Done-for-you handling of questionnaires, insurance forms, and vendor reviews is included at that level.
Do you cover AI risk?
Every tier does. Your team is already using AI tools, so a written AI acceptable-use policy and a shadow-AI check come standard, scaled by tier. At Core Assurance this becomes a full AI governance program mapped to NIST AI RMF, so you can adopt AI safely instead of banning it or ignoring it.
Is this 24/7 monitoring or a SOC?
No. This is security leadership, verification, and done-for-you compliance handling. If your obligations require managed monitoring, we specify, select, and manage the right provider for you rather than reselling one.
How is pricing set?
Baseline tiers are fixed monthly prices you can select after the diagnostic. Core Assurance is quoted, because the price follows your actual requirement, not a menu. Everything is month to month with 30 days notice, and every price is confirmed in writing before you commit.
Can't I just answer these questionnaires with AI?
You can draft with AI. You cannot transfer risk to it. A wrong answer on an insurance form can void coverage; a wrong answer to a customer can kill the deal. What you are buying is an answer a certified security firm stands behind, with evidence attached when it is required. We use AI where it helps and put our name where it counts.
