For SOC 2 / ISO 27001 and vCISO practices
Stop re-collecting the same client evidence every cycle.
The DNS, email-authentication and TLS slice of a readiness engagement is the same work every time, for every client — and it is the part nobody bills for. Give us five client domains and we’ll send back one workpaper covering all of them, with your firm on the cover. Free, and there’s nothing to buy afterwards.
- 1
You tell us the domains
Your firm's name and up to five client domains. Nothing to install, no access to anything of theirs — every check reads public DNS, TLS and WHOIS records.
- 2
We run the same 15 checks a reviewer runs
DNS, MX, SPF, DKIM, DMARC, TLS, redirects, security headers, CORS, DNSSEC, MTA-STS, TLS-RPT, WHOIS and CT logs — per domain, with each finding mapped to the SOC 2 or ISO 27001 control it evidences.
- 3
You get one workpaper, with your name on it
A single document across all five clients, gaps ranked by severity, ready to send or drop into an engagement. Yours to use however you like.
What the free workpaper is not
It’s a working draft: real findings, but unsigned. The paid report is Ed25519-signed and dated, so your client’s auditor can confirm independently that it hasn’t been altered since you issued it — without an account, and without trusting either of us. Try verifying one.
Prepared from public records. It is not an authorised assessment of those domains, and we don’t contact your clients — ever.

This is the shape of the document — one section per client instead of one domain. See a full sample.