OUR CORE SERVICE PACKAGES

Three core packages.
A clear path forward.

For startups and SaaS teams that need to earn customer trust without building a full-time security team.

01

AI Security Assessment

Estimated delivery2–4 weeks

One agreed AI application or agent workflow.

What we test & review

  • Prompt injection and unsafe model output handling
  • Sensitive data exposure and RAG access boundaries
  • Agent permissions, tool use, and human approval controls
  • AI API access, secrets, and third-party dependencies
  • Logging, abuse monitoring, and usage limits

What you receive

  • Executive summary and prioritized findings with test evidence
  • Framework mapping and practical remediation roadmap
  • Technical findings walkthrough with your team
Discuss AI security
02

Cloud Security Assessment

Estimated delivery3–4 weeks

An agreed set of AWS, Azure, or Google Cloud accounts.

Frameworks & references

Applicable cloud-provider security guidance also informs the review.

What we test & review

  • CSPM review of cloud configuration and security posture
  • Public storage, exposed services, and network access rules
  • IAM permissions, privileged access, and unused credentials
  • Encryption, key management, and secrets handling
  • Audit logging, alert coverage, and backup configuration

What you receive

  • Cloud posture report with validated, prioritized findings
  • Asset-level remediation backlog and configuration guidance
  • Readout covering exposure, owners, and recommended next steps
Discuss cloud security
03

Governance & Compliance

Estimated delivery4–8 weeks

Readiness assessment for one selected framework and agreed business scope.

What we review

  • Framework scope, control ownership, and accountability
  • Policies, risk assessment, and exception management
  • Access reviews, change management, and incident response evidence
  • Vendor oversight and data handling processes
  • AI inventory and lifecycle governance for ISO 42001 scope

What you receive

  • Readiness gap assessment and prioritized action plan
  • Control-to-evidence matrix with owners and missing evidence
  • Policy improvement recommendations and audit preparation roadmap
Discuss compliance

Timelines are planning estimates from kickoff once agreed access and inputs are available. Final scope and delivery dates are confirmed in the proposal. Implementation and retesting are scoped separately. Governance timelines cover the readiness assessment, not the full remediation program, SOC 2 observation period, or independent audit.

GOVERNANCE & COMPLIANCE / FRAMEWORK OPTIONS

Choose the framework that fits.

Policies, controls, and audit preparation aligned to the requirements that matter to your business.

SOC 2

Prepare for SOC 2 with practical policies, security controls, and organized evidence. We support Type I and Type II readiness and help your team respond to customer security reviews.

Discuss SOC 2

ISO 27001

Build or mature your information security management system. Establish risk assessments, policies, controls, and clear ownership to prepare for an independent certification audit.

Discuss ISO 27001

ISO 42001

Develop an AI management system with clear governance, risk assessment, and accountability. Bring your AI processes and supporting evidence together for certification readiness.

Discuss ISO 42001

Truva supports readiness and audit preparation. Independent auditors issue SOC 2 reports; certification bodies issue ISO certifications.

Book a free 30-minute security consult