Technical evaluation

vCISO Lite versus vCSO.ai

Two ways to buy a vCISO. vCSO.ai sells four services per-engagement with no public rates. vCISO Lite sells the same services with published rate cards — Fractional vCISO $8,000/mo, QCD from $12,500 — and ships a SaaS platform underneath: 250+ SCF-cross-mapped frameworks, Trustworthy Autonomy, Evidence Graph, APRI.

Prepared
Method
Capability walk against vCSO.ai’s published product surface (vcso.ai, vcso.ai/products/theodolite, vcso.ai/services/*, vcso.ai/nick-shevelyov, vcso.ai/about-us, vcso.ai/learn/*) and vCISO Lite’s live platform and founder bio at vcisolite.com/about.
Sources
vcso.ai, vcso.ai/products/theodolite, vcso.ai/services/ma-due-diligence, vcso.ai/nick-shevelyov, vcso.ai/about-us, vcso.ai/learn/best-fractional-ciso-firms-2026, vcisolite.com/about, vcisolite.com/features/compliance, vcisolite.com/services, vcisolite.com/pricing. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where vCSO.ai leads

  • Nick’s SVB banking-vertical judgment. 15 years running security at Silicon Valley Bank.[1] For banking or banking-adjacent M&A specifically, a load-bearing credential vCISO Lite doesn’t match on the same axis.
  • Board seat at authID (NASDAQ: AUID). Public-company governance experience most CISOs don’t have.
  • Cyber-vendor design-partner ecosystem. Palo Alto Networks, Zscaler, CrowdStrike, FireEye, Eclypsium.[1] Real vendor-ecosystem access.
  • 24 named customer logos + 7 CEO/CTO testimonials. authID, G42, Kodem, StackRox, Wipro, National Audubon Society, ActZero.ai, Heritage Bank, and more.[5] Real reference base at a scale vCISO Lite doesn’t match today.
  • Nick personally on every engagement. Their /about-us page states “named individual ownership of engagements — not team-based accounts.” Real product for buyers who want the named senior CSO personally on the call.

Where vCISO Lite leads

  • Founder credentials are comparable, not lesser. Yolonda has the same CMU CISO Executive Education cert Nick has, plus CISSP/CISM/GCIH/GSEC (broader cert set), USAF veteran (Cyberspace Ops Officer, unique credential), 20-year operator track across USAF → Pwnie Express → Target → sweetgreen → Grubhub (scaled through IPO), TEDx / Grace Hopper / DevOpsDays speaker, and TWO 2026 books whose methodologies are foundational IP inside the platform.[1] Different specialty domain (cross-industry IPO-scale ops + published methodology author vs SVB banking + cyber-vendor ecosystem), comparable caliber.
  • Yolonda authored the M&A cyber-diligence methodology; QCD is the productized version. Nick applies 15 years of judgment as a per-engagement service. Yolonda’s 2026 book Someone Else’s Debt is the codified five-pillar CCOD framework, foundational IP inside vCISO Lite’s QCD product. Nick’s judgment scales to as many engagements as he can personally take. Yolonda’s methodology runs on the platform for every customer.[2]
  • Vendor-incident response also methodology-anchored. Yolonda’s Someone Else’s Breach (2026) is the source playbook for the platform’s vendor-incident capability.[3]
  • Every service has a published rate card. Fractional vCISO $8,000/mo · QCD from $12,500 · Audit Prep $7,000 · Compliance Kickstart $5,000 · Quarterly Review $5,500/qtr · TPR Questionnaires from $1,750 on /services. vCSO.ai is per-engagement, no public rate on any of its four named services.[4]
  • 250+ SCF-cross-mapped frameworks, 1,468 universal controls. Theodolite (in private preview) maps to CIS Controls v8 + 56 cyber-DD questions.[6] Every SCF-mapped control unlocks the frameworks that share it.
  • Shipped chatbot + live MCP endpoint. APRI (our MCP tool graph + evidence-backed answer surface) completes vendor questionnaires end-to-end with cited evidence, opens remediation issues as Linear tickets, generates board packs. Caller-entitlement scoped, complete tool-call audit trail, observe-first with confirmation gates. Live MCP endpoint at mcp.vcisolite.com for Claude + Cursor. vCSO.ai has no shipped conversational AI on their product surface — the “.ai” is domain branding.
  • Trustworthy Autonomy — a category vCSO.ai doesn’t compete in. Autonomous execution layer, public beta 2026-07-07; Level 1 agent governance proven prod 2026-08-17.
  • Evidence Graph — externally-anchored, licensable as SDK. Per-event Ed25519 signing + RFC-3161 external anchor + transparency log live prod 2026-08-20. Auditor re-derives without trusting the platform. vCSO.ai/Theodolite mentions “zero central persistence” but no external-anchor mechanism.
  • Platform underneath the services. SaaS platform at $299–$8,500/mo published tiers on /pricing. Enterprise MSRP $8,500/mo bundles Trustworthy Autonomy + Evidence Graph + APRI + services in-SKU. vCSO.ai is services only — no platform layer.
  • Founder-direct. [email protected] reaches the founder, not an SDR queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
SMB and mid-market operators evaluating a vCISO product. Direct-to-customer buyers weighing shipped platform + services vs boutique operator-led advisory. Not: Fortune-500 banking CIO engagements where 15-year SVB tenure is the load-bearing credential — Nick’s home turf, noted where relevant.
Evaluation frame
Ten capability categories the vCISO buyer typically weighs. Not: everything each vendor does.
Comparison basis
Published product and services pages, both founders’ bios, both pricing positions, both books. Not: NDA material, analyst reports behind paywalls, unsourced third-party leaks.

Out of scope

Banking-vertical M&A
Nick’s SVB CSO tenure is a specific credential for banks, mid-size regionals with $1B+ AUM, or banking-adjacent fintechs. This page does not litigate whether vCSO.ai is the right choice there; it may well be.
Cyber-vendor GTM advisory
vCSO.ai’s Product Advisory practice serves cyber vendors pre-seed to Series D (positioning, ICP, VTC Calculator). vCISO Lite does not compete in that market; buyers of that service should evaluate vCSO.ai directly.
Roadmap
Only shipped, generally-available or public-beta capability is compared. Theodolite is in “private development” per vCSO.ai’s own product page and is compared as such.

Capability coverage

Ten capabilities§3

Amber = vCSO.ai ships / has it. Teal = vCISO Lite ships it. Split = both. Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Framework decomposition lives in §5.

vCSO.AI · NICK’S JUDGMENT15 yrs SVB CSO tenure (2007–2021)5-day review + IC report + 100-day planDelivered per engagementNick personally on every oneScales up to Nick’s calendarbounded by one person’s bandwidthReal judgment. Real credential.Bounded by one individual’s calendar.vCISO LITE · QCD METHODOLOGYSomeone Else’s Debt (Yolonda, 2026)Five-pillar CCOD frameworkCodified in the platformruns for every customerScales beyond any individualnot bounded by founder’s calendarAuthor of the methodology.Productized version runs for everyone.
Nick applies the discipline; Yolonda authored it and productized it. Both are real. §4.1 unpacks; §4.5 covers vendor-incident methodology from Someone Else’s Breach.
§4.1

M&A cyber diligence methodology

vCSO.ai's core M&A wedge is Nick's judgment as a service. vCISO Lite's is the codified productized version of the same discipline, authored by Yolonda in Someone Else's Debt (2026).

vCSO.ai

Nick Shevelyov delivers M&A cyber DD per engagement — 5-day initial risk review, IC-grade reporting to the acquirer's investment committee, 100-day post-close plan for the target's security program. 15 years of SVB CSO judgment.

Inputs
Target company access, cloud accounts, code repos, security posture data, incident history.
Outputs
Signed report per engagement · IC deck · 100-day plan.
Evidence
Nick's SVB tenure + board of authID + design-partner history is the credibility signal on which the report rests.
Fails when
Diligence workload exceeds what Nick can personally take on this quarter, or the target is outside the banking/vendor-ecosystem specialties Nick's SVB tenure covers.
vCISO Lite

QCD (Quantitative Cyber Diligence) — five-pillar CCOD (Cyber Cost of Deal) probability-weighted loss quantification: attack-surface exposure, third-party concentration, data-sensitivity + regulatory exposure, incident-response readiness, remediation trajectory. Codified from Yolonda's 2026 book Someone Else's Debt (foundational IP inside the platform).

Inputs
Target cloud accounts, code repos, evidence artifacts, posture scans, incident history, framework mappings, vendor-concentration data.
Outputs
CCOD per pillar · combined loss quantification · IC-grade PDF · signed to the Evidence Graph · re-derivable.
Evidence
Every step of the CCOD calculation lands in the Evidence Graph with per-event Ed25519 signing and RFC-3161 external timestamp anchor. Auditor / acquirer can independently verify without trusting vCISO Lite.
Fails when
Buyer specifically needs Nick's SVB banking-vertical judgment applied to a banking-adjacent target — Nick's tenure is a specific credential the codified methodology does not directly substitute for.
§4.2

Conversational AI assistant + MCP endpoint

vCSO.ai's product surface has no shipped conversational AI. The '.ai' is domain branding — their own competitor guide slots them as 'operator-led advisory, quantification-native.' vCISO Lite ships APRI.

vCSO.ai

Not shipped on the public product surface today. Theodolite is a scanning + assessment tool; no conversational AI, no MCP endpoint, no LLM mechanism disclosed on any vCSO.ai URL fetched.

Inputs
N/A
Outputs
N/A
Evidence
N/A — their own competitor guide describes vCSO.ai as 'operator-led advisory, quantification-native' and reserves the 'AI-powered vCISO platform' category slot for Cynomi.
Fails when
Buyer needs shipped conversational AI grounded in real evidence chains — vCSO.ai does not compete in this category.
vCISO Lite APRI

APRI (AI-Powered Risk Intelligence) — MCP tool graph + evidence-backed answer surface. Completes vendor questionnaires end-to-end with cited evidence, generates board reports (PDF + presenter), opens remediation Linear tickets with owners + ETAs, builds SOC 2 readiness summaries mapped to Trust Service Criteria, re-scores vendor risk against risk policy, assembles M&A data rooms.

Inputs
Natural-language queries, uploaded questionnaires, scanner + policy state, evidence chain, MCP tool calls from external agents.
Outputs
Cited answers · full questionnaire responses · board-pack PDFs · Linear-ticket remediation plans · SOC 2 readiness PDFs · vendor tier changes · scoped M&A data rooms.
Evidence
Three architectural guarantees: caller-entitlement scoped (APRI uses your entitlements, not a service account); every tool call, parameter, and result recorded to the audit trail; observe-first by default (writes go through a confirmation gate). Live MCP endpoint at mcp.vcisolite.com (OAuth 2.1 + PKCE) exposing APRI to Claude / Cursor / custom agents.
Fails when
N/A — vCSO.ai has no equivalent to compare against in this category.
§4.3

Autonomous execution layer

Separate category from §4.2 — the chatbot advises; the execution layer takes action. vCSO.ai has no autonomous-execution product.

vCSO.ai

Not offered. Their model is Nick's judgment + human-delivered engagements. No autonomous execution.

Inputs
N/A
Outputs
N/A
Evidence
N/A
Fails when
Buyer needs governed autonomous action against controls — vCSO.ai does not ship in this category.
vCISO Lite Trustworthy Autonomy

Autonomous operations layer of vCISO Lite, running on the Evidence Graph. Public beta since 2026-07-07. Level 1 agent governance proven in production 2026-08-17.

Inputs
Agent action requests · policy state · framework-control mapping · evidence chain state.
Outputs
Signed authorization decision per action · agent execution · evidence-chain record before AND after the action.
Evidence
Every autonomous action recorded to the Evidence Graph; published evaluation harness grades the agent by task category with pass rates + failure cases visible pre-purchase.
Fails when
Buyer needs GA (not public-beta) autonomous action at trust-ladder rung 2 or 3 today — those reach GA H1 2027 and H2 2027+ respectively.
§4.4

Evidence integrity substrate

The chain that answers 'did the agent do what it said it did?' has to be re-derivable without trusting the platform that produced it.

vCSO.ai / Theodolite

Not offered. Theodolite is a scanner + assessment tool; its 'zero central persistence' claim describes where scan results are stored, not an evidence-integrity chain. No external anchor, no cryptographic chain, no transparency log surfaced on any product page.

Inputs
N/A — no evidence-integrity surface to feed.
Outputs
N/A — the chain does not exist.
Evidence
The comparison here is presence/absence, not weaker-vs-stronger. Local storage of scan results is a database, not an integrity chain an untrusting auditor can independently verify.
Fails when
Adversarial auditor asks to verify the chain independently against an external record; there is no chain to verify.
vCISO Lite Evidence Graph

Hash-chained records anchored to an external RFC-3161 timestamp authority. Per-event Ed25519 signing shipped 2026-08-16; transparency log + receipts live in production since 2026-08-20.

Inputs
Every agent action, evidence artifact, policy decision, framework mapping.
Outputs
Sealed evidence chain · external timestamp attestation · re-derivable proof.
Evidence
Auditor re-derives the chain against the RFC-3161 attestation record; verification does not depend on trusting vCISO Lite. SDK-licensable since 2026-08-15.
Fails when
Buyer's audit tooling has not been briefed on RFC-3161 verification; onboarding the audit firm to the chain takes one call.
§4.5

Vendor-incident response methodology

vCISO Lite ships the vendor-incident-response capability from Yolonda's 2026 book Someone Else's Breach as the source methodology. vCSO.ai does not have a core vendor-incident surface.

vCSO.ai

Not a core vCSO.ai surface. Their positioning centers on M&A DD and cyber-vendor product advisory.

Inputs
N/A
Outputs
N/A
Evidence
N/A
Fails when
Buyer needs a specific third-party incident-response playbook — vCSO.ai's public surface does not name one.
vCISO Lite

Vendor-incident capability shipped from Yolonda's 2026 book Someone Else's Breach (a practitioner's playbook for third-party incident response). Source methodology is authored IP inside the platform.

Inputs
Third-party incident signals, vendor tier data, contractual exposure, business dependency graph.
Outputs
Incident-response playbook per vendor · contractual-obligation mapping · communication templates · executive briefing.
Evidence
Every incident-response action recorded to the Evidence Graph with per-event signing.
Fails when
Buyer specifically needs banking-adjacent incident-response judgment from a former SVB CSO — Nick's tenure is a specific credential; the codified methodology is a different shape.

Framework & control coverage

Framework depth§5

Theodolite maps to CIS Controls v8 (153 questions) plus 56 proprietary cyber-DD questions. vCISO Lite ships 250+ SCF-cross-mapped frameworks (1,468 universal controls). Theodolite is in “private development” per vCSO.ai’s own product page.

vCSO.ai / Theodolite[6]

CIS Controls v8

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & delivery model

Services vs services · platform on top§6

vCSO.ai is a services firm — four engagement SKUs, all per-engagement, no public rates.[4] vCISO Lite ships the same services with published rate cards anda SaaS platform underneath. The apples-to-apples is Fractional vs Fractional and M&A Due Diligence vs QCD — same job, one side quotes, the other side publishes.

vCSO.ai

Services firm

Per engagement · no public rate on any of 4 named services[4]

Fractional advisory
Strategic Oversight / Fractional CSO — per engagement, no public rate
M&A cyber-diligence
M&A Due Diligence — per engagement, no public rate
Assessment
Focused Cyber Risk Assessment — per engagement, no public rate
Vendor-side advisory
Product Advisory (for cyber vendors) — per engagement, no public rate
Scanner
Theodolite — private preview (not GA)
Free tool
VTC Calculator
Platform
None — services only
Delivery model
Nick personally on every engagement
Sales cycle
30-min scoping call → scoped follow-up
vCISO Lite

Services + Platform

Every service has a published rate card · SaaS platform underneath

Fractional advisory
Fractional vCISO — $8,000/mo · dedicated part-time strategic leadership[7]
M&A cyber-diligence
Quantitative Cyber Diligence (QCD) — from $12,500 · five-pillar CCOD methodology codified from Someone Else’s Debt (2026)[7]
Assessment
Compliance Kickstart — $5,000 one-time · gap analysis + policy library + 90-day roadmap[7]
Audit prep
Audit Prep Package — $7,000 one-time · evidence + mock audit + auditor briefing[7]
Ongoing review
Quarterly vCISO Review — $5,500/qtr[7]
Questionnaire response
Third-Party Risk Questionnaires — from $1,750[7]
Platform (SaaS, on top)
Starter $299/mo · Growth $599/mo · Business $999/mo · Ultra $1,499/mo · Enterprise $8,500/mo flat MSRP (bundles Trustworthy Autonomy + Evidence Graph + APRI + 250+ frameworks + services in-SKU)
Delivery model
Productized services delivered on the platform — artifacts keep working after the engagement ends
Sales cycle
Every service price on /services · Enterprise: one call, flat MSRP on file

Integration surface

Native connectors§7

Theodolite explicitly supports AWS + Azure + SharePoint only. Its product page explicitly excludes GCP, Oracle Cloud, Nessus, Qualys, OpenVAS.[6] vCISO Lite’s full catalog on /features/integrations.

IntegrationvCSO.ai / TheodolitevCISO Lite
AWSNativeNative
AzureNativeNative
GCPNative
Oracle Cloud
Databricks
SnowflakeNative
SharePointNative
Nessus
Qualys
OpenVAS
GitHubNative
GitLabNative
Google WorkspaceNative
Microsoft 365Native
OktaNative
JiraNative
SlackNative
ServiceNowNative
MCP (Model Context Protocol)Native
Integration count published?3 explicitly (AWS, Azure, SharePoint)Full catalog on /features/integrations

Deployment, data, extensibility

Platform architecture§8
AttributevCSO.ai / TheodolitevCISO Lite
Service modelAdvisory-first · Theodolite in “private development” · customer-side PostgreSQL storage (“zero central persistence”)SaaS multitenant · Enterprise-tier isolated deployment on request
Data residencyCustomer-side (per Theodolite “zero central persistence” claim)US (primary)
Public APINot publicly documentedREST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0
SSO / SCIMNot publicly disclosed on product pageSAML 2.0 · OIDC · SCIM 2.0
Audit-trail modelCustomer-side storage; no external-anchor mechanism or per-event signing disclosedEvidence Graph · hash-chained per-event · Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Conversational AI assistant (chatbot)Not shipped on public product surfaceAPRI · MCP tool graph · answers cite evidence chain · caller-entitlement scoped · complete tool-call audit trail · observe-first with confirmation gates · live MCP endpoint at mcp.vcisolite.com for Claude / Cursor / custom agents
Autonomous execution layerNot offered · Nick’s judgment + human-delivered engagementsTrustworthy Autonomy (public beta 2026-07-07) · Level 1 agent governance proven prod 2026-08-17 · published evaluation harness · trace format published
Managed vCISO services delivered by vendorYes · per-engagement basis · Nick personally on every oneYes · productized on the same SKU (vCISO Services, TPR Questionnaires, Compliance Kickstart, Quarterly Review, retainer)
Own complianceNot publicly disclosedSOC 2 Type II · ISO 27001 (in progress) · runs on itself

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside vCSO.ai

A PDF business case, personalized to your company, that lays out the three options, the cost math, and the honest tradeoffs. Written to be credible with a buyer who's already read Nick Shevelyov's SVB CSO bio and needs to see what the productized-methodology alternative actually delivers.

View pricing

Notes & sources

Provenance§10
  1. [1] Nick Shevelyov founder profile (CSO Silicon Valley Bank 2007–2021, board of authID / NASDAQ: AUID, CMU CISO Executive Education, CISSP / CISM / CIPP / GSNA, design partner Palo Alto Networks / Zscaler / CrowdStrike / FireEye / Eclypsium, author of Cyber War…and Peace, Forbes Technology Council) from vcso.ai/nick-shevelyov/ and vcso.ai/about-us/ (accessed 2026-09-14). Yolonda Smith founder profile (CMU CISO Executive Education certification, CISSP/CISM/GCIH/GSEC, BS Computer Science University of Notre Dame, MS Information Assurance University of Maryland, U.S. Air Force veteran / Cyberspace Operations Officer, 20-year operator track USAF → Pwnie Express → Target → sweetgreen Head of Cybersecurity → Grubhub Head of Cybersecurity scaled through IPO, TEDx / DevOpsDays / Grace Hopper / The Diana Initiative speaker) from vcisolite.com/about (accessed 2026-09-14).
  2. [2] vCSO.ai M&A Due Diligence service (5-day initial risk review → management-access diligence → IC reporting → 100-day plan) from vcso.ai/services/ma-due-diligence/ (accessed 2026-09-14). Yolonda’s 2026 book Someone Else’s Debt (M&A cyber-risk quantification framework, source methodology for vCISO Lite’s QCD / five-pillar CCOD product) named on vcisolite.com/about; both methodologies are foundational IP inside vCISO Lite per that page.
  3. [3] Yolonda’s 2026 book Someone Else’s Breach (practitioner’s guide to third-party incident response, source methodology for vCISO Lite’s vendor-incident capability) named on vcisolite.com/about.
  4. [4] vCSO.ai pricing model (“per engagement,” no public rates) from vcso.ai/learn/best-fractional-ciso-firms-2026/ (vCSO.ai’s own competitor guide, accessed 2026-09-14). No pricing surfaced on vcso.ai homepage, services pages, or Nick Shevelyov’s bio page. Their own competitor guide lists vCSO.ai’s pricing as “Per engagement.” vCISO Lite pricing published at vcisolite.com/pricing.
  5. [5] vCSO.ai named customer logos (authID, G42, ETZ, Pixee, Laminar, Kodem Security, Heritage Bank of Commerce, Gale Healthcare Solutions, Quokka, Plate IQ, StackRox, Wipro, TruU, National Audubon Society, ActZero.ai, Edgile, CyTwist, BoostSecurity, Arms Cyber, Motivus, DeepTempo, Eclypsium, Metano.ai) and 7 named-CEO/CTO testimonials from vcso.ai/ homepage (accessed 2026-09-14). 24 total logos.
  6. [6] Theodolite product description (private development, 209 assessment questions = 153 CIS Controls v8 + 56 proprietary cyber-DD questions, cloud support explicitly AWS + Azure + SharePoint only with explicit exclusion of GCP / Oracle Cloud / Nessus / Qualys / OpenVAS, customer-side PostgreSQL storage / “zero central persistence”) from vcso.ai/products/theodolite/ and theodolite.io/ (accessed 2026-09-14). vCISO Lite framework depth (250+ SCF-cross-mapped, 1,468 universal controls) verified against live vcisolite.com/features/compliance.
  7. [7] vCISO Lite productized services with published rate cards — Fractional vCISO ($8,000/mo), Quantitative Cyber Diligence (from $12,500), Compliance Kickstart ($5,000 one-time), Audit Prep Package ($7,000 one-time), Quarterly vCISO Review ($5,500/quarter), Third-Party Risk Questionnaires (from $1,750) — from vcisolite.com/services (accessed 2026-09-14). Every service is priced on the page; no discovery-call scoping required to see a rate.
  8. vCSO.ai’s own competitor guide at vcso.ai/learn/best-fractional-ciso-firms-2026 describes vCSO.ai as “operator-led advisory, quantification-native” and reserves the “AI-powered vCISO/GRC platform” category slot for Cynomi — a helpful self-classification confirming vCSO.ai does not compete in the shipped-conversational-AI category. The “.ai” in their domain is branding, not a shipped AI mechanism.
  9. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. Theodolite’s status was “private development” at time of writing; if it has since moved to GA, corrections at /contact.
  10. This page does not compare against other vCISO providers (Cynomi, Fractional CISO, FRSecure, SideChannel, DISC) on their own merits — each has its own head-to-head brief under /compare. For AI Governance vendor comparisons (Credo AI, OneTrust, Holistic AI), see /vs/credo-ai et al.