Agentic Compliance

Security testing backs the compliance work.

Your team needs to answer customer security questions and prepare for audits while keeping the business running. We test your systems and handle routine evidence work in the platform. You provide business context and approve your policies.

  • 2scoped pentests per year
  • $20kannual base plan
  • +$3kper additional framework
  • 0offshored work
fig. 01
SOC 2 + ISO 27001, 214 controls
  • verified
  • collected
  • gap
Trusted by teams at

Three systems. One security program.

Compliance, offensive testing and cloud posture — run by the same operators, fed by the same agents, priced in public.

  • Warlock

    Plug-and-play compliance

    • SOC 2, ISO 27001, HIPAA, CMMC and more, mapped once
    • Evidence pulled from live systems, graded for sufficiency
    • Policies drafted from the environment you actually run
    • A named US operator approves every judgment call
    Explore Warlock
  • Reaper

    Human-in-the-loop penetration testing

    • Agents map the attack surface; operators exploit it
    • Every finding confirmed by a human before it's reported
    • The tester who finds it retests the fix
    • From $3,000 · ~2 weeks
    Explore Reaper
  • Knell

    Find the path to your data first

    • Daily scans across 9 providers
    • Attack paths from internet to data store
    • Permission gaps shown, never a clean result
    • New and resolved findings tracked every day
    • $20 / user / month
    Explore Knell

Where to start

What needs to happen next?

  • A customer needs a pentest

    Standalone testing from $3,000. Scope your application and workflows, get findings and remediation guidance. No annual plan required.

  • A security review is holding up a deal

    Bring the buyer's requirements and your deadline. We scope the framework work and identify missing evidence. Bespoke questionnaires and new analysis are quoted separately.

  • Your engineers also own security

    Keep your engineers focused on delivery. Sythe handles scoped testing and routine evidence coordination. Your team supplies business information, approves policies, and implements recommended fixes.

Core primitives

Six objects make up the platform. Compose them into any framework: SOC 2, ISO 27001, HIPAA, CMMC, AIUC-1.

  • Controls

    One control answers SOC 2, ISO and the questionnaire a prospect sent last week. Mapped once.

    controls.map()
  • Evidence

    Pulled from live system state, graded for sufficiency — not a screenshot from six weeks ago.

    evidence.attach()
  • Policies

    Drafted against the environment you actually run, versioned, and routed for approval.

    policies.draft()
  • Compliance Runs

    A bounded unit of agent work with a scope, an owner and a completion condition.

    runs.start()
  • Receipts

    Every change is an ordered record: action, target, outcome, audit event. Reads stay silent.

    receipts.list()
  • Operator gate

    Judgment calls wait for a named, US-based Sythe operator. No operator, no close. That's a system property.

    gate.approve()

Agents draft, people decide

Your agents draft. Our operators decide.

Agent
Implement CC6.2 for us

What's covered

Security testing and compliance delivery.The annual base plan is $20,000 for eligible companies, including one compliance framework. Each additional framework is $3,000 per year. Agree the targets and coverage before signing. Ongoing monitoring, incident response, advisory, and implementation are additional services.

How it works

Know what we handle and what needs you.Routine delivery happens in the platform. Kickoff and pentest scoping and closure meetings are included. Strategic advice and consulting meetings use a separate vCISO retainer.

  1. Agree the scope

    Bring your systems, buyer requirements, and deadline to kickoff. We agree the test targets, scan inventory, and responsibilities before work starts.

  2. Test and explain the findings

    You receive findings with supporting evidence and recommended fixes. Your team makes the changes, or we quote the implementation separately. Each pentest includes one scoped retest.

  3. Keep the evidence work moving

    Operators request evidence, prepare materials, and follow up in the platform. You confirm business accuracy and approve policies. Routine clarification and corrections are included.

The Sythe Labs platform
The Sythe Labs platform dashboard

One place to see everything we're doing.

The Sythe Labs platform is where your team tracks evidence, triaged findings, and reports. Log in any time to see the next action and who owns it. Ongoing security monitoring is an additional service.

Take a tour (opens Google Calendar in a new tab)

The operators

The agent never signs anything. A person you can call does.

Meet your operators.

Jarred Parr
Operator

Jarred Parr

Co-founder · Boulder, CO

Approves policies, access models and every attestation that goes to your auditor.

Andrew Roe
Operator

Andrew Roe

Co-founder · Boulder, CO

Leads offensive testing. Confirms each finding and retests the fix himself.

Who does it: the agent or a named operator
TaskAgentNamed operator, US-based
Pull evidence from live systemsYesNo
Map controls across frameworksYesNo
Draft policies and proceduresYesNo
Answer security questionnairesYesNo
Approve policies and access modelsNoYes
Judge exploitabilityNoYes
Confirm pentest findingsNoYes
Sign off for your auditorNoYes

Every operator is a US-based Sythe Labs employee. We never outsource, subcontract or offshore any part of the work.

Pricing

Independent audit and certification fees are separate. Always.

Warlock

$20,000/ yr

The Startup managed security plan. For companies under $5M revenue or 50 staff.

One compliance framework is included. Each additional framework: +$3,000 / yr. Choose from SOC 2, ISO 27001, HIPAA, CMMC and more.

Each year includes 2 scoped penetration tests, one scoped retest per test, 2 risk assessments, and 12 vulnerability scan runs. Asset and host limits are agreed before work starts. Schedule testing within the service year, subject to availability.

Sythe operators request and review evidence, prepare materials, and follow up in the platform. You supply business information and approve your organization's policies. Routine clarification, corrections, and supported platform integration repairs are included.

Enterprise: Custom. Over $5M revenue or 50 staff.

  • 2 scoped penetration tests per year
  • One scoped retest per penetration test
  • 2 risk assessments per year
  • 12 host-limited vulnerability scan runs per year
  • Third-party risk document uploads and Q&A
  • Enterprise scope agreed separately
  • Additional assets and testing quoted to scope
  • Service levels defined in your agreement

Ongoing security monitoring and incident response are additional services. We recommend fixes; hands-on changes to your systems require a separate implementation scope.

Strategic compliance advice and expressly delegated decisions use a vCISO retainer at $250/hour, with hours approved in advance. Kickoff and pentest scoping and closure meetings are included. Other routine delivery happens in the platform; recurring consulting meetings are extra.

Book a call (opens Google Calendar in a new tab)Talk to us (opens Google Calendar in a new tab)See the frameworks

Managed security plans have no per-seat platform fees. One compliance framework is included; additional frameworks are annual add-ons. Standalone pentests are priced per engagement; Knell subscriptions use per-user pricing.

Knell

$20/ user / month

Standalone cloud-security subscription. Cloud posture with attack paths to your data. Daily scans across 9 providers.

Reaper

$3,000/ test

Standalone penetration testing. No annual managed plan required.

Small apps with straightforward workflows. ~2-week manual pentest with findings and recommended fixes. Confirm dates and retest scope before booking.

Premium $7,000 / test. Multi-module platforms with deeper access control and data models. ~4-week manual pentest.

From our clients

Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else.
EchoWin
Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing.
Maru AI
The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast.
Naked Denver
Get started

Ready to cut through it?

A 30-minute Google Meet with Andrew Roe to discuss your scope, deadlines, and the next steps. No form required to see available times.