Policies don't pass audits.
People do.
Here are your options. You hire an MSSP. Tens of thousands a year, and they will operate some controls, but they will not write your policies to your actual business and they will not own the outcome. You hire a security engineer internally. Full senior salary plus benefits, plus the six months it takes them to learn your stack. And you are still asking one person to do three different jobs.
Or you buy a policy template for a few hundred bucks and hope you figure out the rest before the auditor calls. That one ends the same way every time.
But the real gap is not the evidence. It is the judgment. A SOC 2 audit does not hand you a build spec. It asks you to decide which controls matter for your business, what reasonable looks like for a team your size, and how far to push back when an auditor wants more than the standard requires. None of those calls come from a template. They come from someone who has done this enough times to know the difference between a real finding and a misunderstanding.
I write policies that describe your actual organization. I build the (cost efficient) controls that enforce them. I produce the evidence the auditor signs off on. But the work that matters most is the judgment: knowing where to focus, when a control is good enough, and how to steer the audit to a conclusion. One practitioner, the whole program. You pass the audit. Back to business.
The problem with SOC 2 the way most people do it
The copy-paste trap
There are dozens of policy templates online. Some are decent. Most are not. But none of them describe your organization: your tech stack, your team structure, your actual processes. When the auditor asks "show me where you do this," a borrowed policy has no answer, and the gap only shows up when it matters.
The implementation gap
A policy that says "access is reviewed quarterly" means nothing if you have no mechanism to review it, record the evidence, and prove it happened. Writing the policy is the easy part. Building the controls that enforce it in your cloud, in your workflows, to the standard an auditor will accept. That is a different discipline entirely.
Graham successfully guided our practice through a major IT overhaul. He helped ensure our network and software systems were secure, up-to-date, and compliant. He is a highly responsive problem-solver who always goes the extra mile to find the right answers for our specific needs. We trust him completely with our IT and highly recommend his services.
— Amy, Northwest Metabolic Medicine
The offer
A full-stack SOC 2 program, in 90 days
I sit at the intersection most people miss: the place where a written policy has to turn into a real control, running in your cloud, producing evidence an auditor can verify. I do all of it. The policies that describe your actual organization, the infrastructure-as-code that enforces them, and the evidence package that proves they work. So you are game-day ready.
I actively maintain successful, drama-free SOC 2 environments for my clients. I took a startup from loose, ad-hoc practices to SOC 2 Type 2 with zero adverse findings, and I build that same program for you.
Why work with me
Ready for your SOC 2?
Tell me what you're working on. I read everything and respond within a couple business days. Not ready to talk? Start with the free readiness checklist and find your gaps first.
Featured Projects
This Website
Full AWS best-practice infrastructure, CI/CD, and a production site, all for about a dollar a month. Proof that cost-optimized doesn't mean fragile.
Jarvis, an Executive Summary Agent
A daily AI-generated executive brief delivered to Slack, pulling from AWS, GitHub, Gmail, Drata, and more. Drop-in plugin architecture with per-plugin LLM inference. Secure, isolated, near-zero ops overhead.