Monthly Engagement

Your obligations are continuous. Most engagements are not.

Compliance does not end at handoff. FedRAMP requires monthly scanning and POA&M management. SOC 2 Type II is assessed across an observation window, not a moment. HIPAA requires ongoing evaluation. But the engineering that satisfies those obligations usually stops the day a project closes, and the system starts drifting away from the documentation that describes it. This is the engagement that keeps them in agreement.

Monthly · 30 days notice to cancel
$6,000 / month
Named senior engineer · one platform
Quarterly assessment refresh included
Talk about a retainer

The obligations that do not pause.

This is not a maintenance plan invented to create recurring revenue. Each of these is a continuous requirement of the framework itself.

FedRAMP

Continuous monitoring is mandatory: monthly vulnerability scanning, POA&M management, and significant-change reporting. An ATO is harder to keep than to get.

SOC 2 Type II

Assessed over an observation window of six to twelve months. Controls have to hold for the entire period, not on the day the auditor looks.

HIPAA

The Security Rule requires periodic evaluation as the environment changes. Every architecture change is a re-evaluation trigger whether or not anyone files one.

What drift actually looks like.

Nothing dramatic happens. Someone adds a managed service that is not in the boundary. A retention policy gets relaxed to save storage cost. A role picks up a permission during an incident and keeps it. A pipeline stage gets bypassed for a hotfix and the bypass stays.

Each is reasonable in isolation. Together, over two quarters, they are the gap between your control narrative and your running system, and they surface at the worst possible time: during an assessment, or in a customer security review attached to a deal you were about to close. Drift is cheap to catch monthly and expensive to catch annually.

What the retainer covers.

M/01

Control drift detection

Monthly review of infrastructure state against the control baseline we established, with a written delta showing what moved and what it affects.

M/02

Evidence review

Confirmation that logging, retention, and audit trails are still producing what an assessor will ask for, and that nothing has silently stopped emitting.

M/03

Remediation of small findings

Drift that can be fixed inside the monthly scope gets fixed, not just reported. Anything larger is quoted separately before work starts.

M/04

Quarterly assessment refresh

Every third month, a fuller pass against the framework: updated control mapping, refreshed narratives, and a current findings list.

M/05

Auditor and security-review support

When an assessor or a customer's security team sends questions, you have an engineer who already knows the system and can answer in their language.

M/06

Architecture review on change

Before you add a service, region, or data flow, a review of what it does to the boundary. Cheaper than discovering it afterward.

What it is not.

Out of scope, deliberately
  • Production on-call, incident response, or an uptime SLA
  • Break-fix support for application defects
  • Unlimited engineering hours under a monthly cap
  • Policy authoring, workforce training, or vendor risk management
  • A replacement for your GRC platform or your assessor

If you need any of those, say so on the call. Some we can scope separately, and some we will point you elsewhere for. A retainer that quietly absorbs work it was never sized for goes bad for both sides within a quarter.

Who this fits.

The natural fit is a team that has just finished a build, ours or someone else's, and now owns a system with continuous obligations attached to it. The second is a team holding an ATO or a Type II report who has discovered that keeping it is a standing engineering commitment nobody was assigned.

If we have not worked together, start with the Two-Week Audit. It gives us the map we need and gives you a roadmap you own regardless of what happens next.

Questions.

Do I have to have worked with you before?
No, but we need to understand the system before we can defend it. Teams who have not worked with us start with the Two-Week Audit, which gives us the map and gives you a roadmap you own regardless. Retainers that begin without that context spend the first two months doing it anyway, more slowly.
Is this a support contract or an SLA?
No. This is not production on-call, not incident response, and not break-fix. It is compliance engineering: keeping controls enforced, evidence flowing, and documentation matching reality between assessments. If you need 24/7 production support, you need a different arrangement and we will tell you that.
What if we need more work than the retainer covers?
We tell you before we start, not after. Work beyond the monthly scope is quoted as a separate fixed-fee engagement. You will never get a surprise invoice, and we will not quietly absorb work that should have been scoped, because that is how retainers turn resentful.
Can we cancel?
Yes, with 30 days notice, and no minimum term beyond the first quarter. The first three months exist because control drift is not visible in shorter windows. After that, if it is not delivering value, you should stop paying for it.
How is this different from a GRC platform?
A GRC platform tells you a control is failing. It cannot fix the Terraform. We are the engineering side of the same problem and we work alongside Vanta, Drata, or whatever you already run rather than replacing it. The platform is the dashboard; we change the system it is measuring.
Who actually does the work?
A named senior engineer who knows your environment, not a rotating pool and not a junior assigned to the account. Continuity is the entire point of the arrangement. A retainer staffed by someone relearning your system every month is worth less than no retainer at all.

Talk about a retainer.

Thirty minutes. Tell us what you are holding, what changed since your last assessment, and who currently owns keeping it defensible. If a retainer is not the right instrument, we will say so.

Book a 30-minute call
Not sure where you stand? Start with the Two-Week Audit — $15,000 fixed fee, and the report is yours either way.