TuAvocado
Preventive

The protocol is written before, not during

We put in writing how your business protects its information: the security policy, the agreements with every provider that processes data on your behalf, and the protocol that kicks in when something happens. Four documents, drafted and signed before they are needed.

The policy, the agreements and the protocol are drafted and reviewed by a lawyer at the firm. There is no form to download here and no template that fills itself in.

How it works

From the inventory to the signed protocol

Three sessions and a set of documents. There is no form to fill in and no automatic result: what you are hiring is a lawyer’s judgement about your operation.

  1. Step 1 of 3. Mapping

    We walk through which information the business handles, where it lives and who touches it: the team, the cloud provider, the CRM, the payment gateway and whoever else makes the list.

    Deliverable: inventory of systems and providers

  2. Step 2 of 3. Drafting

    A lawyer at the firm drafts the security policy, the agreement that matches each provider processing data on your behalf, and the incident response protocol.

    Deliverable: the four documents, drafted

  3. Step 3 of 3. Rehearsal and signing

    We walk your team through the protocol before it is needed —who decides, who gets called, what gets logged— and the documents are signed. What you get is a set in use, not a draft.

    Deliverable: rehearsed protocol and signed documents

The monitoring radar

What can be seen from the outside

It covers what anyone can look at from the outside: domains that resemble yours and corporate mailboxes in the dumps going around. What happens inside your infrastructure is not visible from here, and that is why the protocol gets written.

Radar · last 24 h

1 alert
  • Critical4 h ago

    Look-alike domain registered

    techf1ow.co One-character variation on the monitored domain, with an active SSL certificate and a live site.

  • All clear22 h ago

    No leaks detected

    The monitored corporate mailboxes do not appear in the dumps reviewed overnight.

Demo

Sample alerts about a made-up company. The monitoring engine does not exist yet: this shows how a notice will be presented, not an actual notice.

Radical transparency

What you take away and what it costs

The four documents are the service. There is no single price because the work is not the same at a company with two providers as at one with twenty.

The four documents you end up with

  1. Deliverable 1 of 4. A documented security policy

    Access control, encryption at rest and in transit, password management and backups, written for your operation and not copied from a template.

  2. Deliverable 2 of 4. Agreements with your data processors

    Your cloud provider, your CRM and your payment gateway process data on your behalf. Each one gets its agreement, drafted by a lawyer at the firm.

  3. Deliverable 3 of 4. An incident response protocol

    Who decides, who gets called, what is documented and in what order, from the first hour. Rehearsed with the team before it is needed.

  4. Deliverable 4 of 4. Trade secret shielding

    Internal classification of your critical information and the documents that go with it in each relationship. We handle this separately, as a service of its own.

What is at stake

[ PENDING — legal text to be drafted ]

This service is quoted by scope: how many systems, how many providers and how much information has to be documented changes the work. The quote reaches you in writing after the first conversation; we are not giving you an estimate here that we could not stand behind.

The commercial argument

The damage is measured in days, not in pesos

That is why monitoring is sold as a subscription and not case by case: by the time someone writes to us, the problem almost never started that day.

  1. Moment 1 of 4. 0–1daysUnverified

    Monitoring on

    The alert goes out as soon as the publication shows up in the source we watch, and there is still room to decide what to do.

  2. Moment 2 of 4.

    The window to oppose

    [ PENDING — legal text to be drafted ]

  3. Moment 3 of 4. 6–10monthsUnverified

    The registration is decided

    [ PENDING — legal text to be drafted ]

  4. Moment 4 of 4.

    The problem becomes yours

    [ PENDING — legal text to be drafted ]

Timelines

How long it takes, and what the firm does not decide

Delivery runs on our own clock. Anything that depends on a regulation is confirmed by a lawyer once we have seen your operation.

How long the firm takes to deliver the setEstimated by the firm
to be definedUnverified

It depends on how many systems and how many providers have to be documented, which is what the mapping produces.

How soon a security incident is reportedSet by the regulation

[ PENDING — legal text to be drafted ]

Frequently asked

What people ask us most

About monitoring and defense

General information about how our services work. This is not a legal opinion and does not replace advice from a lawyer on your specific case.

4 questions on this topicThey open in the support panel, without leaving this page.

See the questions

Is your question missing?

The day of the incident it is too late to write it

The first conversation is with a lawyer and it is there to size the work: how many systems, how many providers and what is written down today.