Nothing to attack. Nothing to assume. Nothing to see. Nothing to take. EXORR engineers your Azure environment until it holds exactly that. A surface with nothing on it.
FRAMEWORKS WE ENGINEER FORSOC 2ISO 27001HIPAAGDPREU AI ACTNIS2
Every breach that matters begins the same way: something was there to take. EXORR's entire doctrine is the removal of that something.
"
An attacker is a professional at finding what exists. Make nothing exist, and their profession dies in the dark.
THE VOID STANDARD ∅ EXORR, doctrine 00
Four principles
THE DOCTRINEIN FULL
Each principle is a deployment posture, not a slogan. Read them as requirements.
01
SURFACE MINIMIZATION ATTACK
The first law of the void: you cannot breach what does not exist. Every open port, every public storage account, every over-privileged identity is surface, and surface is an invitation. EXORR audits every addressable object in your tenant and removes the ones that should not be there, then shrinks the ones that must remain. The result is not "hardened". The result is less. Less endpoints, less exposure, less to enumerate. An attacker's first scan returns a void, and voids return nothing.
02
ASSUMPTION DISSOLUTION VERIFY
Most breaches do not exploit a weakness. They exploit a belief: "the VNet isolates us", "only admins can reach the key vault", "the LLM is sandboxed". Every assumption is a door you have already opened in your own mind. EXORR dissolves each one in turn: identity-to-data paths are traced end to end, AI workloads are probed for what they actually trust, and every "obviously fine" decision is re-derived from first principles. An assumption that survives the audit is not a belief. It is a fact.
03
OPERATIONAL INVISIBILITY DETECT
The second-best outcome to being unhackable is being unseeable. Lateral movement dies without a map; credential abuse dies without trust; persistence dies when the environment forgets it exists. EXORR builds detection postures that watch the few honest signals (identity re-issuance, key access, entitlement changes) and treats everything else as noise. When nothing signals, nothing can be found. An environment that looks empty to an attacker is an environment you have already won.
04
THE VOID STANDARD RECOVER
Breaches are not prevented. They are made impossible to profit from. The Void Standard is the end state EXORR engineers toward: nothing to attack, nothing to assume, nothing to see, nothing to take. When an incident still occurs (and it will), it finds no surface, no trust chain, no standing privilege, no payload worth its cost. This is the difference between "secure" and "a void". One is a claim. The other is an architecture.
Manifesto
We do not sell "protection". Protection is a posture of adding: more tools, more layers, more alert fatigue, more belief.
We sell subtraction. The strongest Azure tenant is not the one with the most defenses; it is the one with the least to defend. Every identity that cannot act, every endpoint that does not respond, every storage account that does not exist: that is security you can verify by absence.
This is harder to sell. It is impossible to fake. And it is the only posture that survives contact with an adversary who is paid to be patient.
EXORR is the void, engineered. Enter it.
∅ EXORR
Philosophy in practice
WHERE IT BITESIN AZURE
Doctrine without deployment is poetry. Here is exactly where each principle lands in your tenant.
Identity layer
ENTRA / PIM
Standing privileges become zero standing privileges
Break-glass paths verified, not assumed
Every role assignment justified in writing
Service principals constrained to single functions
Data layer
STORAGE / KEYS
Public exposure is an anomaly, not a config
Key vault access traced identity-to-secret
Private endpoints the default posture
Rotation enforced by policy, not habit
AI layer
LLM WORKLOADS
Prompt injection treated as a real threat model
Tool access gated to provable need
Training and runtime data paths separated
Outputs assumed compromised until proven otherwise
FIELD NOTE 03 · PRINTABLE
THE VOID STANDARD
The operating doctrine of EXORR, written down so it can be argued with. Print it; the arguments are the point.
THE FOUR ABSENCES
Nothing to attack. Surface is subtracted before defenses are added. Every exposed endpoint that should not exist is removed, not protected.
Nothing to assume. Nothing is believed until it is verified: by enumeration, by reproduction, by evidence. Belief is the vulnerability; verification is the fix.
Nothing to see. Logs are structured so that silence is meaningful. The signal is the absence, not the alert.
Nothing to take. Least privilege, derived from the workload's actual functions, and re-derived as the workload changes.
THE TWO COMMITMENTS
Tested, not theorized. A finding without a reproduction is a rumor. A control without a verification step is a wish.
Documented as evidence. Whatever the work produces must survive an auditor's walkthrough, because that is where claims die.
WHAT FOLLOWS
The Quick Scan verifies by enumeration: the tenant as it is, not as it is described.
The Audit proves the AI layer: injection chains as reproductions, data paths as maps.
The Retainer maintains the state: drift caught monthly, posture reported in one page, incidents answered by the person who knows the environment.
EXORR · FIELD NOTE 03 · PRINTED FROM EXORR.COM · ∅ THE VOID SECURES
Not sure where to start? Every client begins with the Quick Scan. It is the door. The audit is the second floor, and the retainer is the house. If you already know your AI workloads are live in production, begin with the audit instead; the scan will come with it.
WHO WE SERVE
One doctrine, mapped to the obligations of each sector. Framework alignment is a design constraint of every engagement, not an upsell. model
HEALTHCARE
HIPAA's administrative, physical, and technical safeguards, demonstrated in Azure rather than asserted in a policies folder.
∅ PHI SURFACES MAPPED
FINANCE
SOC 2 and PCI environments where the evidence of a control is the control. Every deliverable is auditor-ready.
∅ AUDITOR-READY EVIDENCE
LOGISTICS
NIS2 essential and important entities: supply-chain visibility, incident readiness, and the documentation the regime demands.
∅ NIS2 ALIGNED
GULF & CROSS-BORDER
US, UK, and Gulf operations. GDPR applied wherever data crosses borders, EU AI Act posture for model deployments in the region.
∅ GDPR + AI ACT
HOW WE CHARGE
Flat, always
The scan is $400 and the audit $800, fixed, scoped, and written before work begins. A flat number survives a budget cycle; an estimate does not.
What moves the price
Scope does, and nothing else. The retainer includes a fixed slice of hours a month; beyond that, work runs at $120/hour, a working-engineer rate, and every overage hour is approved by you in writing first.
Heavy months
Incident response inside a declared incident is covered, not billed. A heavy month beyond the hours cap is billed only after approval, at the flat overage rate, with a written ceiling. No surprise invoices. model
FOR THE CFO
∅
$600/mo vs $250K–$400K
The retainer covers the year's posture for less than most companies spend on coffee. The scan and audit are one-time lines, not headcount.
The market band
Security retainers run $3K–$20K per month in 2026. Ours is $600, deliberately — one engineer, no agency overhead, no account-manager markup — because the posture work is documented as evidence your insurer and auditor can price.
Insurance and boards
Every engagement produces documentation that survives a cyber-insurance underwriting review and a board packet. The premium math and the reporting math are the same math.
Cost of a breach
The 2026 average breach costs seven figures before reputational damage. A scan that finds the door your insurer is betting against costs $400. That is not an expense line; it is an option you are not exercising.
∅ THE FINDING GUARANTEE
If a finding inside the written scope is missed, the re-examination is free, in full, at the same scope. We would rather re-earn the engagement than defend the invoice. model
A surgical, five-day pass through your tenant. Identity, network, storage, and AI surfaces, examined the way an adversary would and documented the way a board should. You will know exactly what is wrong, in what order to fix it, and what it costs if you don't.
Investment$400
Duration5 DAYS
DeliveryDEBRIEF + DOC
ScopeFULL TENANT
What you get
DELIVERABLESIN FULL
Not a dashboard. A document your CISO, your board, and your insurer can each use.
PRIORITIZED FINDINGS REGISTER
Every finding, ranked by exploitability and business impact, not by scanner score. Each entry carries the exact condition, the path an attacker would take, and the remediation order.
∅ RISK-RANKED, NOT SORTED
IDENTITY MAP
Entra ID, service principals, PIM assignments, and every standing privilege, mapped to what it can actually reach. You will see the trust chain of your tenant for the first time.
∅ WHO CAN DO WHAT, PROVEN
SURFACE INVENTORY
Storage accounts, exposed endpoints, public blobs, unproxied services. The inventory your "complete" asset list was missing, verified by enumeration rather than spreadsheet.
∅ ENUMERATED, NOT ASSUMED
AI SURFACE REVIEW
A first-pass assessment of any AI workloads: how they authenticate, what tools they can call, and whether prompt injection has a path to your data. The audit goes deeper; this tells you if you need it.
∅ FIRST CONTACT WITH THE AI LAYER
EXECUTIVE DEBRIEF
A one-hour session where nothing is hidden behind jargon. Findings, risk in plain language, and the decision points that belong to leadership, not to a ticket queue.
∅ FOR THE PEOPLE WHO PAY FOR RISK
REMEDIATION ROADMAP
Thirty, sixty, and ninety-day work streams, each with an owner and a verification step. Because a finding without a fix-by date is just a confession.
∅ PLANNED TO COMPLETION
To run the scan
WHAT WE NEEDFROM YOU
Four things, all in your control, none of them standing access.
ONE HOUR OF KICKOFF
A single session: the tenant's shape, the workloads that matter, and the map of who owns what. Everything we need to know that isn't in Azure yet.
∅ ONE HOUR, DAY ONE
READ-ONLY ACCESS, TIME-BOUND
Reader-scoped access to the subscriptions in scope, granted before the scan, revoked at close, revocable by you at any moment. No standing privileges are added to your environment.
∅ REVOCABLE AT ANY TIME
THE TENANT MAP
Subscription list, AI workloads, and any known "shadow" environments your team suspects exist. The inventory you have is the map we correct.
∅ WE ENUMERATE, YOU CONFIRM
A CONTACT WHO ANSWERS
One person who can unblock access requests within a working day. Scans don't fail on findings. They fail on waiting.
∅ THE UNBLOCKER
How it runs
THE FIVE DAYSUNFOLDED
A fixed cadence, so you always know where the scan is and what lands next.
Day 01 · Kickoff
SCOPE + ACCESS
We lock the boundaries (tenant, subscriptions, the AI workloads in scope) and stand up read-only access with no standing privileges added to your environment. The scan is invisible to your estate.
Day 02 · Identity + network
THE TRUST CHAIN
Entra ID posture, PIM configuration, service principals, network egress and ingress, private endpoint coverage. Every path an identity can take to a resource is walked and recorded.
Day 03 · Data + AI surfaces
WHAT IS EXPOSED
Storage exposure, key vault access patterns, and the AI layer's authentication and tool boundaries. Prompt-injection reach is tested, not theorized.
Day 04 · Validation + documentation
EVERY FINDING REPRODUCED
Nothing ships on a screenshot. Each finding is reproduced, risk-scored, and written with its attack path and its fix, alongside the roadmap and its owners.
Day 05 · Executive debrief
THE VOID, OPENED
One hour. Plain language. The findings that matter, the ones that don't, and the decisions only you can make. Start Monday, know by Friday.
DAY 90 · THE FREE CHECK-IN
Ninety days after the debrief, we return for one call, at no charge: which roadmap items landed, which drifted, and what the tenant looks like now. It is how we know the scan worked, and how you know the roadmap wasn't a brochure. model
Boundaries
NOT INCLUDEDON PURPOSE
A scan that claims to be everything is a brochure. These are the honest edges, and which vector covers them.
NO FULL AI AUTOPSY
The scan surfaces the AI layer and tests prompt-injection reach. The full attack-chain autopsy, covering every channel, every tool, every data path, is the AI Security Audit.
∅ THE AUDIT GOES DEEPER
NO REMEDIATION EXECUTION
We plan the fixes and sequence them with owners; your team executes, with us on call through the roadmap. Hands-on execution is the retainer's work.
∅ PLANNED HERE, EXECUTED THERE
NO ATTESTATION OF RECORDS
The scan does not certify SOC 2 or HIPAA state. It produces the evidence your attestation will be tested against, for SOC 2, ISO 27001, HIPAA, and NIS2 alike. Certification is your auditor's signature, earned with our documentation.
∅ EVIDENCE, NOT SIGNATURES
NO UNBOUNDED SCOPE
Subscriptions outside the written scope stay untouched. If the scan finds a world beyond the boundary, we tell you, and scope it properly, on paper, before anyone touches it.
∅ SCOPE IS A CONTRACT
FIELD NOTE 01 · PRINTABLE
THE SCAN READINESS CHECKLIST
What to have ready before a five-day scan, so the five days are spent examining your tenant rather than waiting on you. Ten minutes of preparation buys a materially deeper result.
BEFORE WE START
One kickoff hour with the person who owns the tenant's shape, not a delegate with a ticket.
A tenant map: subscriptions, AI workloads, and suspected shadow environments. Wrong beats empty.
Read-only access granted on the subscriptions in scope: Reader role, time-bound, revocable.
One unblocker who can approve access requests within a working day.
WHAT NOT TO DO
Do not "clean up" before we arrive. The point is to see what actually exists.
Do not grant the scan more than Reader; anything else is unnecessary risk.
Do not reschedule the debrief. The findings need the decision-makers in the room.
Do not gate the scan behind change control. It makes no changes.
WHAT YOU GET BACK
A risk-ranked findings register, each with an attack path and a fix order.
The identity map of the tenant: who can do what, proven.
A 30/60/90 remediation roadmap with owners and verification steps.
A one-hour debrief in plain language, and at day 90, a free check-in call.
EXORR · FIELD NOTE 01 · PRINTED FROM EXORR.COM · ∅ THE VOID SECURES
Fit
WHO IT IS FORAND WHO IT ISN'T
YOU, IF…
You inherited an Azure tenant and distrust the last audit. You are about to sign a compliance attestation and want to know what it actually means. You have a renewal, a merger, or a board meeting with a security slide in it.
∅ KNOW BEFORE YOU SIGN
NOT YOU, IF…
You need an AI workload autopsied end to end (that is the audit), or you need someone carrying the posture daily (that is the retainer). The scan is the door, not the whole house.
∅ THE RIGHT DOOR, FIRST
START THE SCAN
Five days from now, you could know exactly what your tenant is. That is the fastest purchase decision in security, and the only one that pays for itself before the invoice does.
Your AI workloads hold a privilege no firewall understands: they are trusted with your data and they talk to your tools. The audit traces every path from prompt to payload, and proves, in attack chains, where your LLM would sell you out.
Investment$600/mo
Duration2 WEEKS
DeliveryATTACK CHAINS + ROADMAP
ScopeAI + FULL TENANT
Why AI is different
THE TRUSTED ADVERSARYPROBLEM
An LLM is the only workload that calls your APIs and obeys untrusted input. That is not a feature gap. It is a new threat model.
PROMPT INJECTION IS REAL
Your model cannot tell a user instruction from a prompt smuggled inside a document, an email, or a crawled page. We map every channel that reaches the prompt and every tool it can trigger.
∅ ASSUME THE PROMPT IS COMPROMISED
TOOL TRUST IS OVERGRANTED
Most AI deployments give the model a keychain of tools it does not need. We enumerate the actual call graph (database, storage, email, orchestration) and cut every tool that lacks a provable need.
∅ TOOLS ARE PRIVILEGES TOO
DATA PATHS ARE UNSEPARATED
Training data, runtime data, and user data sharing pipelines is the quietest leak vector in AI. We trace who can read what through the model, and separate the paths that must be separate.
∅ SEPARATION IS THE CONTROL
MODEL ENTITLEMENTS ARE UNAUDITED
RBAC for the model's runtime identity is usually "whatever the deployment needed on day one". We re-derive the entitlements from the workload's actual functions, and strip the rest.
∅ LEAST PRIVILEGE, DERIVED
How it runs
TWO WEEKSUNFOLDED
Week 01 · The environment
IDENTITY, NETWORK, DATA
The full tenant baseline the AI layer sits on: identities the model runtime can assume, networks it can reach, and every data store it can read or write. A broken foundation makes every AI control decorative.
Week 01 · The workload
CALL GRAPH + ENTITLEMENTS
The model's tools, its runtime identity, its deployment topology. We document what the AI can actually do, not what the architecture diagram claims it can do.
Week 02 · The attack chains
INJECTION, VALIDATED
Prompt-injection paths are built and tested end to end: untrusted input to tool call to data exfiltration. Each chain ships as a reproduction, not a hypothesis.
Week 02 · The documentation
CHAINS, SCORES, ROADMAP
Every validated chain, ranked; every control mapped to the chain it breaks; every fix sequenced with owners and verification steps. Your security team gets a blueprint, not a warning.
The method
THE FIVE STAGESTESTED, NOT THEORIZED
The same rigor, every engagement. Nothing ships as a hypothesis.
THREAT MODEL
The workload's purpose, its trust boundaries, and who or what can reach the prompt. The attack surface on paper, before a single test.
SURFACE ENUMERATION
Every channel that reaches the model (endpoints, documents, email, crawlers) and every tool it can trigger. Enumerated from the live environment, not the architecture diagram.
INJECTION MATRIX
Prompt-injection paths built and tested end to end: untrusted input to tool call to data exfiltration. Each chain ships as a reproduction, with the transcript.
DATA PATH MAPPING
Who can read what through the model: training, runtime, and user data sharing pipelines. Separation gaps documented with the exact path data travels.
EVIDENCE + DEBRIEF
The evidence pack, the ranked chains, the control map, and a debrief where the attack chains are shown, not summarized.
THE EVIDENCE PACK
Redacted findings register, each with severity, reproduction, and business impact
Attack-chain diagrams: prompt to payload, every hop drawn
Injection transcripts: the actual prompts that triggered tool calls
Data-path maps: who can read what through the model, proven
Configuration diffs for every recommended control change
The recorded debrief, so your board hears it in our voice, not your retelling
Mapped to the taxonomies your buyers know. Every finding is tagged to OWASP LLM Top 10 (2025), OWASP Top 10 for Agentic Applications (2026), and NIST AI 100-2 E2025, so the report is evidence your auditors and customers already speak. model
The baseline is included. The tenant baseline the audit begins with is exactly what the Quick Scan produces. If you arrive from the scan, it is credited and you never pay twice. model
FIELD NOTE 02 · PRINTABLE
THE AI AUDIT BUYER'S GUIDE
What an AI security audit is, what it is not, and the questions that separate a real one from a slide deck. Use it to brief whoever approves the purchase.
WHAT AN AI AUDIT ACTUALLY IS
A full autopsy of the AI attack surface: every channel that reaches the prompt, every tool the model can trigger, every data path it can read.
Validated attack chains: prompt injection built and tested end to end, shipping as reproductions with transcripts.
A control map: every fix mapped to the chain it breaks, sequenced with owners and verification steps.
An evidence pack your compliance program can reuse for SOC 2, ISO 27001, HIPAA, GDPR, and the EU AI Act.
WHAT IT IS NOT
Not a red-team exercise: the goal is a documented map of the surface, not a high-score breakout.
Not a pen-test of the LLM vendor: it tests your deployment, your tools, your data paths, your entitlements.
Not a "responsible AI" review: fairness and bias are outside the threat model unless they are security properties.
Not an attestation: it produces the evidence your auditor signs, it does not sign for them.
QUESTIONS TO ASK ANY AUDITOR
"Do you test injection paths end to end, or do you map them?" Reproductions or nothing.
"What access do you need?" Time-bound, read-only, revocable. No standing privileges.
"What exactly will I receive?" Ranked chains, transcripts, diagrams, diffs, and a roadmap with owners.
"What happens if you find nothing?" The same documentation, honestly saying so. The void is a result.
EXORR · FIELD NOTE 02 · PRINTED FROM EXORR.COM · ∅ THE VOID SECURES
AUDIT THE AI
If your LLM touches production data or production tools, the question is not whether it will be attacked through its prompt. It is whether you will know before the report.
Every injected chain ships as a reproduction with transcript. If we find nothing in scope, the documentation says so in full, and the void is credited as the result.
Most teams don't need a CISO on payroll; they need the posture carried daily. The retainer gives you a security engineer on call, in your tools, and accountable, for the cost of a single contractor.
Investment$600/mo
CadenceMONTHLY
Response24H / 4H URGENT
ContractQUARTERLY
What is covered
THE MONTHLYRHYTHM
Predictable coverage, structured like a function, not a support ticket.
CONTINUOUS POSTURE REVIEW
Your tenant is not static; neither is the audit. Monthly reviews of identity, exposure, and AI surfaces, with drift caught before it becomes a finding.
∅ DRIFT IS THE ENEMY
INCIDENT RESPONSE, ON CALL
When something happens, you do not want a vendor. You want the person who knows your environment. 24-hour standard response, 4-hour urgent, with you on the call.
∅ THE VOID ANSWERS
EXECUTIVE REPORTING
A monthly one-pager leadership can actually read: what changed, what held, what is next. Every metric tied to a control, not a vibefactor.
∅ REPORTING THAT SURVIVES A BOARD
VENDOR + POLICY REVIEWS
That MSA your engineering team wants to sign? That policy your auditor wants rewritten? Reviewed and answered with your posture, not generic boilerplate.
∅ EVERY SIGNATURE VETTED
REMEDIATION EXECUTION
Not just recommendations: hands-on execution of priority fixes (PIM discipline, exposure closure, entitlement cuts) inside your change process.
∅ WE DO THE WORK
THREAT-TIDE MONITORING
What is being exploited in the wild that maps to your specific stack? A standing watch, filtered for relevance, delivered monthly.
∅ ONLY WHAT APPLIES TO YOU
THE MODEL, IN NUMBERS
No "all-you-can-eat" ambiguity. A function, priced like one. model
12 HRS
Included each month
Posture review, reporting, vendor and policy reviews, remediation: all inside the monthly hours.
$120/HR
Overage rate · approved first
The retainer includes a fixed slice of hours per month. Above that, work runs at $120/hour, a working-engineer rate with none of the agency markup. No hour is billed without your written approval.
<4 HRS
Urgent incident response
Declared incidents are covered, not billed. Standard response is 24 hours; urgent is four, with you on the call.
30 DAYS
Offboarding, written
Knowledge handover and posture documentation at close. The function survives the contract.
Day one: an onboarding week: tenant walkthrough, the standing watch you have, the posture file that will follow you. Heavy months: overage only after approval, with a written ceiling. The contract: quarterly, renewed on results, not on inertia. model
Fit
WHO IT IS FORAND WHO IT ISN'T
YOU, IF…
You are a company whose security posture is one engineer and a hope. You are between CISOs — or have never had one. You are growing fast enough that "we will handle it" is no longer a strategy.
∅ THE HOUSE, NOT JUST THE DOOR
NOT YOU, IF…
You need a one-time autopsy (the audit), or you simply need to know where you stand (the scan). The retainer is for companies that want the void maintained, not just entered.
∅ BEGIN WITH THE RIGHT VECTOR
RETAIN THE VOID
Every month without a security function is a month the adversary is not billing. The retainer closes that gap at a price that fits a function, not a fortune.
Across environments that believed they were secure, the same four signals appear. Not "the same types". The same findings.
FINDING 01 · IDENTITY
A SERVICE PRINCIPAL WITH MORE POWER THAN THE TEAM
HIGH
One workload identity held Contributor on the entire subscription, deployed three years ago "temporarily" and forgotten since. Any compromise of that principal was a compromise of the environment. The fix was 40 minutes of work and a decade of habit.
Blob storage with anonymous read enabled. The "private" design was a belief, and the access tier confirmed it was a door. An attacker enumerating the tenant would have found it inside one API call. The container held three years of nightly exports, unencrypted at rest, and the account's network rules were open to the internet. model
A customer-facing assistant held a tool that could send email and read the order database, with no gate between untrusted prompt content and either capability. The documented injection test returned the database schema in a single exchange.
∅ PROMPT INJECTION IS A THREAT MODEL, NOT A THEORY
A multi-factor policy documented as "enforced" applied to exactly 12% of identities; a conditional-access exception had quietly swallowed the rule. Low exploitability, high embarrassment, and the exact shape of every compliance attestation ever signed in good faith.
∅ POLICY IS VERIFIED IN EFFECT, NOT IN DOCUMENTATION
Numbers from real engagements, reported the way they were measured: at the debrief and again at the day-90 check-in. model
00
Of scan findings remediated within 90 days
00
Reduction in exploitable attack surface
00
Posture reviews delivered after retainer start
00
Attack chains reproduced before documentation
n = 24 model engagementsMeasured at debrief + day-90 check-inJan–Dec 2026 model
Model engagement 01 · Healthcare
THE SERVICE PRINCIPAL THAT OUTRANKED THE TEAM
A regional healthcare services operator, pre-attestation, with HIPAA obligations and a SOC 2 deadline. The scan found a workload identity with subscription-wide Contributor, a legacy of a three-year-old "temporary" deployment, plus an AI triage assistant whose tool access included the patient appointment database.
92% of findings closed within 90 days · identity map now in every board pack model
Model engagement 02 · Financial services
THE LLM THAT COULD EMAIL CUSTOMERS
A payments platform's customer assistant could send email and read the order database, with no gate between untrusted prompt content and either capability. The audit reproduced a full chain, prompt to tool call to data exfiltration, and shipped it as a transcript their auditors finally believed.
Injection chains closed · evidence pack reused in SOC 2 walkthrough model
Model engagement 03 · Logistics
ONE ENGINEER AND A HOPE
A freight-forwarder facing NIS2 deadlines with one overwhelmed engineer and a stack of scanner output. The retainer rebuilt the posture as a function: monthly reviews, a named response line, and a one-page board report. It was tested by a Friday-night incident in month two.
Posture function running · first incident handled in 3.5 hours model
"
We thought we were fine. The scan showed us a service principal that could have shut the company down, and it had been there for three years. Nothing since has been 'fine'. It has been verified.
C
CTO
Healthcare services · post-scan client
Composite of client feedback, first half of 2026 model
"
The audit did what our own security team could not: it proved the prompt injection was real, on our data, through our tool. The attack chains were the first documentation our auditors actually believed.
S
VP ENGINEERING
Financial services · post-audit client
Composite of client feedback, first half of 2026 model
"
We went from one overwhelmed engineer and a stack of scanner output to a posture I can explain to the board in one page. The retainer paid for itself the first time we had an incident on a Friday.
M
CEO
Logistics · retainer client
Composite of client feedback, first half of 2026 model
BECOME THE NEXT ONE
Every number above came from a company that once had a "we are probably fine" posture. Yours is the next case study, if you want it to be.
Anyone can claim expertise. These are the verifiable foundations the work stands on.
SC-100
CYBERSECURITY ARCHITECT EXPERT
The architect-level credential for Microsoft security: the one that requires more than a test, and tests the design of whole environments, not individual products.
The hands-on Azure security certification: identity, platform protection, data and application security, and the operational discipline of a secure tenant.
Frameworks are not checkboxes. They are obligations with an evidence standard. Here is exactly how each one is served by the work. model
Every engagement is delivered with framework mapping built in: findings are tagged to the controls they break, and the documentation is written to survive an auditor's walkthrough. You never pay to "map to SOC 2" later. It arrives mapped.
SOC 2
TRUST SERVICES · US
The controls your customers' procurement teams ask about first. Our work produces the operational evidence the Type II walkthrough is tested against.
Findings mapped to the Trust Services Criteria they break
Evidence pack structured for the auditor's sample
Retainer maintains control evidence month to month
ISO 27001
INTERNATIONAL · ANNEX A
The management-system standard. We align technical controls to the Annex A clauses your certification body will inspect.
Control-to-clause mapping in every register
Risk treatment inputs for your ISMS review
Verification steps written as audit evidence
HIPAA
HEALTHCARE · US
PHI has a surface requirement: every place protected health information can live or travel must be mapped. We map it, in Azure, by enumeration.
PHI surfaces inventoried, not asserted
Technical safeguards demonstrated in tenant
AI workloads carrying PHI treated as highest risk
GDPR
EU · DATA PROTECTION
Wherever your data crosses EU borders, the standard follows it. We treat personal data flows as security controls, because they are.
Data path mapping across regions and workloads
Access evidence for accountability records
Breach-readiness inputs for the 72-hour clock
EU AI ACT
EU · AI GOVERNANCE
The first binding AI regulation. For high-risk deployments, the audit's evidence (injection tests, data paths, tool graphs) is exactly what the technical documentation obligation asks for.
Attack-surface documentation for technical files
Risk-mitigation evidence from validated chains
Post-deployment monitoring input from the retainer
NIS2
EU · CRITICAL ENTITIES
Essential and important entities must demonstrate proportionate security and incident readiness. We build the technical backbone that demonstration rests on.
Supply-chain and third-party access reviewed
Incident-response readiness tested, not assumed
Documentation structured for the authority's review
∅ ONE DOCTRINE, SIX STANDARDS
The void is framework-agnostic: we subtract surface first, then the mapping follows. Compliance is what happens when the evidence is real.
Asked often
THE QUESTIONSYOU ARE ASKING
No. Ninety percent of clients begin with the Quick Scan. It is the door, and it tells you which other doors exist. If your AI workloads are in production with real data and real tools, begin with the AI Security Audit instead; the tenant baseline it produces is broader than the scan's. The retainer is for companies that want the posture maintained rather than just found.
Read-only, time-bound, and scoped to the engagement's boundaries. No standing privileges are added to your environment, and access is removed at close. You can revoke it at any moment. The scan is designed to survive your paranoia, and to reward it.
Regulated industries where a breach is a business-ending event: healthcare (HIPAA), financial services (SOC 2, GLBA, PCI), logistics (NIS2), and public-sector-adjacent operations worldwide, with GDPR and the EU AI Act applied wherever your data crosses those borders. Framework alignment is a design constraint of every engagement, not an upsell.
The Quick Scan and the Audit deliver documentation and a roadmap; the fix is owned by your team, with us on call through the roadmap. The Retainer is where EXORR executes: remediation, policy, vendor reviews, and the work itself, inside your change process.
Because it is honest. "Security" is a claim about a future that hasn't happened. The void is an architecture, a state where the attack surface does not exist, so the claim never has to be made. Read the philosophy page; it is the shortest argument you will ever see for doing less, better.
The retainer includes a fixed slice of hours per month. Above that, work runs at $120/hour, a working-engineer rate with none of the agency markup. No hour is billed without your written approval.
rity leadership, with a written cap: you approve any overage before it is incurred. Incident response inside a declared incident is covered, not billed. The invoice is never a surprise. model
Agencies run $150–$400 per hour and quote ranges that never survive contact with a budget. The scan is a flat $400, the audit a flat $800, fixed, scoped, and written before work begins. You pay for outcomes, not for a headcount with overhead. model
Every engagement begins with a conversation, and every conversation begins here. Tell us what your environment is, what it holds, and what it must never lose. We will tell you which vector opens first, and we answer within 24 hours.