Agentic Compliance
Security testing backs the compliance work.
Your team needs to answer customer security questions and prepare for audits while keeping the business running. We test your systems and handle routine evidence work in the platform. You provide business context and approve your policies.
- 2scoped pentests per year
- $20kannual base plan
- +$3kper additional framework
- 0offshored work
- verified
- collected
- gap
Three systems. One security program.
Compliance, offensive testing and cloud posture — run by the same operators, fed by the same agents, priced in public.
Warlock
Plug-and-play compliance
- SOC 2, ISO 27001, HIPAA, CMMC and more, mapped once
- Evidence pulled from live systems, graded for sufficiency
- Policies drafted from the environment you actually run
- A named US operator approves every judgment call
Reaper
Human-in-the-loop penetration testing
- Agents map the attack surface; operators exploit it
- Every finding confirmed by a human before it's reported
- The tester who finds it retests the fix
- From $3,000 · ~2 weeks
Knell
Find the path to your data first
- Daily scans across 9 providers
- Attack paths from internet to data store
- Permission gaps shown, never a clean result
- New and resolved findings tracked every day
- $20 / user / month
Where to start
What needs to happen next?
A customer needs a pentest
Standalone testing from $3,000. Scope your application and workflows, get findings and remediation guidance. No annual plan required.
A security review is holding up a deal
Bring the buyer's requirements and your deadline. We scope the framework work and identify missing evidence. Bespoke questionnaires and new analysis are quoted separately.
Your engineers also own security
Keep your engineers focused on delivery. Sythe handles scoped testing and routine evidence coordination. Your team supplies business information, approves policies, and implements recommended fixes.
Core primitives
Six objects make up the platform. Compose them into any framework: SOC 2, ISO 27001, HIPAA, CMMC, AIUC-1.
Controls
One control answers SOC 2, ISO and the questionnaire a prospect sent last week. Mapped once.
controls.map()Evidence
Pulled from live system state, graded for sufficiency — not a screenshot from six weeks ago.
evidence.attach()Policies
Drafted against the environment you actually run, versioned, and routed for approval.
policies.draft()Compliance Runs
A bounded unit of agent work with a scope, an owner and a completion condition.
runs.start()Receipts
Every change is an ordered record: action, target, outcome, audit event. Reads stay silent.
receipts.list()Operator gate
Judgment calls wait for a named, US-based Sythe operator. No operator, no close. That's a system property.
gate.approve()
Integrations · Run Sythe Labs where you already work.
- Available nowAcquiaAcquia Cloud, Source, and DrupalView integration
- Available nowGoogle WorkspaceDirectory users and related compliance evidenceReview details
- Customer setup guideGoogle CloudCompute, storage, databases, containers, serverless, and artifactsRead setup guide
- Available nowVercelProjects and domainsView connection guide
- Customer setup guideCloudflareOne account and all full, partial, and secondary public zonesOpen setup guide
- Customer setup guideNeonOne organization and all of its projectsOpen setup guide
- Customer setup guideNotionOne workspace and its full-member roster; guests excluded by NotionOpen setup guide
- View integrationsMCP server docs
Agents draft, people decide
Your agents draft. Our operators decide.
What's covered
Security testing and compliance delivery.The annual base plan is $20,000 for eligible companies, including one compliance framework. Each additional framework is $3,000 per year. Agree the targets and coverage before signing. Ongoing monitoring, incident response, advisory, and implementation are additional services.
Penetration testing
Manual testing of agreed targets, with findings, recommended fixes, and a scoped retest. Implementing fixes is separate.
See the processVulnerability management
12 scan runs per service year against an agreed host scope, with triaged findings and recommended next steps.
Risk assessments
An organization-wide baseline and an update each year, within agreed scope. Use the assessments to prioritize risks and decide what needs treatment.
Third-party risk assistance
Upload vendor documents and ask questions about them. The assistant references supporting material and flags missing information. Your team decides whether to approve the vendor; human review is separately scoped.
Compliance & GRC
Operators prepare and track evidence in the platform. You provide business context and approve policies. One framework is included in the annual plan; additional frameworks and independent audit fees cost extra.
See the processSecurity advisory
Compliance consulting, remediation planning, and delegated approval management through a vCISO retainer at $250/hour, with hours approved in advance.
How it works
Know what we handle and what needs you.Routine delivery happens in the platform. Kickoff and pentest scoping and closure meetings are included. Strategic advice and consulting meetings use a separate vCISO retainer.
Agree the scope
Bring your systems, buyer requirements, and deadline to kickoff. We agree the test targets, scan inventory, and responsibilities before work starts.
Test and explain the findings
You receive findings with supporting evidence and recommended fixes. Your team makes the changes, or we quote the implementation separately. Each pentest includes one scoped retest.
Keep the evidence work moving
Operators request evidence, prepare materials, and follow up in the platform. You confirm business accuracy and approve policies. Routine clarification and corrections are included.

One place to see everything we're doing.
The Sythe Labs platform is where your team tracks evidence, triaged findings, and reports. Log in any time to see the next action and who owns it. Ongoing security monitoring is an additional service.
Take a tour (opens Google Calendar in a new tab)The operators
The agent never signs anything. A person you can call does.
Meet your operators.

Jarred Parr
Co-founder · Boulder, CO
Approves policies, access models and every attestation that goes to your auditor.

Andrew Roe
Co-founder · Boulder, CO
Leads offensive testing. Confirms each finding and retests the fix himself.
| Task | Agent | Named operator, US-based |
|---|---|---|
| Pull evidence from live systems | Yes | No |
| Map controls across frameworks | Yes | No |
| Draft policies and procedures | Yes | No |
| Answer security questionnaires | Yes | No |
| Approve policies and access models | No | Yes |
| Judge exploitability | No | Yes |
| Confirm pentest findings | No | Yes |
| Sign off for your auditor | No | Yes |
Every operator is a US-based Sythe Labs employee. We never outsource, subcontract or offshore any part of the work.
Pricing
Independent audit and certification fees are separate. Always.
Warlock
The Startup managed security plan. For companies under $5M revenue or 50 staff.
One compliance framework is included. Each additional framework: +$3,000 / yr. Choose from SOC 2, ISO 27001, HIPAA, CMMC and more.
Each year includes 2 scoped penetration tests, one scoped retest per test, 2 risk assessments, and 12 vulnerability scan runs. Asset and host limits are agreed before work starts. Schedule testing within the service year, subject to availability.
Sythe operators request and review evidence, prepare materials, and follow up in the platform. You supply business information and approve your organization's policies. Routine clarification, corrections, and supported platform integration repairs are included.
Enterprise: Custom. Over $5M revenue or 50 staff.
- 2 scoped penetration tests per year
- One scoped retest per penetration test
- 2 risk assessments per year
- 12 host-limited vulnerability scan runs per year
- Third-party risk document uploads and Q&A
- Enterprise scope agreed separately
- Additional assets and testing quoted to scope
- Service levels defined in your agreement
Ongoing security monitoring and incident response are additional services. We recommend fixes; hands-on changes to your systems require a separate implementation scope.
Strategic compliance advice and expressly delegated decisions use a vCISO retainer at $250/hour, with hours approved in advance. Kickoff and pentest scoping and closure meetings are included. Other routine delivery happens in the platform; recurring consulting meetings are extra.
Book a call (opens Google Calendar in a new tab)Talk to us (opens Google Calendar in a new tab)See the frameworksManaged security plans have no per-seat platform fees. One compliance framework is included; additional frameworks are annual add-ons. Standalone pentests are priced per engagement; Knell subscriptions use per-user pricing.
Knell
Standalone cloud-security subscription. Cloud posture with attack paths to your data. Daily scans across 9 providers.
Reaper
Standalone penetration testing. No annual managed plan required.
Small apps with straightforward workflows. ~2-week manual pentest with findings and recommended fixes. Confirm dates and retest scope before booking.
Premium $7,000 / test. Multi-module platforms with deeper access control and data models. ~4-week manual pentest.
From our clients
Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else.
EchoWinSythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing.
Maru AIThe strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast.
Naked DenverSee what the work looked like.
Ready to cut through it?
A 30-minute Google Meet with Andrew Roe to discuss your scope, deadlines, and the next steps. No form required to see available times.


