The protocol is written before, not during
We put in writing how your business protects its information: the security policy, the agreements with every provider that processes data on your behalf, and the protocol that kicks in when something happens. Four documents, drafted and signed before they are needed.
The policy, the agreements and the protocol are drafted and reviewed by a lawyer at the firm. There is no form to download here and no template that fills itself in.
From the inventory to the signed protocol
Three sessions and a set of documents. There is no form to fill in and no automatic result: what you are hiring is a lawyer’s judgement about your operation.
Step 1 of 3. Mapping
We walk through which information the business handles, where it lives and who touches it: the team, the cloud provider, the CRM, the payment gateway and whoever else makes the list.
Deliverable: inventory of systems and providers
Step 2 of 3. Drafting
A lawyer at the firm drafts the security policy, the agreement that matches each provider processing data on your behalf, and the incident response protocol.
Deliverable: the four documents, drafted
Step 3 of 3. Rehearsal and signing
We walk your team through the protocol before it is needed —who decides, who gets called, what gets logged— and the documents are signed. What you get is a set in use, not a draft.
Deliverable: rehearsed protocol and signed documents
What can be seen from the outside
It covers what anyone can look at from the outside: domains that resemble yours and corporate mailboxes in the dumps going around. What happens inside your infrastructure is not visible from here, and that is why the protocol gets written.
Radar · last 24 h
1 alert- Critical4 h ago
Look-alike domain registered
techf1ow.co One-character variation on the monitored domain, with an active SSL certificate and a live site.
- All clear22 h ago
No leaks detected
The monitored corporate mailboxes do not appear in the dumps reviewed overnight.
Sample alerts about a made-up company. The monitoring engine does not exist yet: this shows how a notice will be presented, not an actual notice.
What you take away and what it costs
The four documents are the service. There is no single price because the work is not the same at a company with two providers as at one with twenty.
The four documents you end up with
Deliverable 1 of 4. A documented security policy
Access control, encryption at rest and in transit, password management and backups, written for your operation and not copied from a template.
Deliverable 2 of 4. Agreements with your data processors
Your cloud provider, your CRM and your payment gateway process data on your behalf. Each one gets its agreement, drafted by a lawyer at the firm.
Deliverable 3 of 4. An incident response protocol
Who decides, who gets called, what is documented and in what order, from the first hour. Rehearsed with the team before it is needed.
Deliverable 4 of 4. Trade secret shielding
Internal classification of your critical information and the documents that go with it in each relationship. We handle this separately, as a service of its own.
What is at stake
[ PENDING — legal text to be drafted ]
This service is quoted by scope: how many systems, how many providers and how much information has to be documented changes the work. The quote reaches you in writing after the first conversation; we are not giving you an estimate here that we could not stand behind.
The damage is measured in days, not in pesos
That is why monitoring is sold as a subscription and not case by case: by the time someone writes to us, the problem almost never started that day.
- Moment 1 of 4. 0–1daysUnverified
Monitoring on
The alert goes out as soon as the publication shows up in the source we watch, and there is still room to decide what to do.
- Moment 2 of 4.
The window to oppose
[ PENDING — legal text to be drafted ]
- Moment 3 of 4. 6–10monthsUnverified
The registration is decided
[ PENDING — legal text to be drafted ]
- Moment 4 of 4.
The problem becomes yours
[ PENDING — legal text to be drafted ]
How long it takes, and what the firm does not decide
Delivery runs on our own clock. Anything that depends on a regulation is confirmed by a lawyer once we have seen your operation.
- How long the firm takes to deliver the setEstimated by the firm
- —to be definedUnverified
It depends on how many systems and how many providers have to be documented, which is what the mapping produces.
- How soon a security incident is reportedSet by the regulation
[ PENDING — legal text to be drafted ]
What people ask us most
About monitoring and defense
General information about how our services work. This is not a legal opinion and does not replace advice from a lawyer on your specific case.
4 questions on this topicThey open in the support panel, without leaving this page.
See the questionsIs your question missing?
The day of the incident it is too late to write it
The first conversation is with a lawyer and it is there to size the work: how many systems, how many providers and what is written down today.