SOC 2 · ISO 27001 · HIPAA · CMMC · NIST CSF 2.0

The security reviewis holding upyour deal.

Nova Lim answers the questionnaire, sits on the buyer security call, and builds the evidence trail behind it. Fixed scope, published pricing, one senior advisor from intake to sign-off. No platform to buy and no vendor kickbacks, ever.

Entry pointSecurity Deal Desk
Response SLA48 hours
PricingPublished, fixed
Staffed byFounder, start to finish
Vendor feesNone taken
48 hours
From questionnaire intake to answers back in your hands
Zero kickbacks
Testers and platforms bill you directly. We take nothing on top
One name
The person who scopes the work is the person who does it

What we do

Three outcomes. Nine ways to get there.

Security work only matters if it does something for the business. Every service below sits under the outcome it buys you — winning the deal, staying ready, or proving the thing actually holds.

PILLAR 01

Win the deal

Enterprise buyers now treat every vendor as a breach path. The security review is a revenue gate, and it is usually the founder or the CTO absorbing it at the worst possible moment.

Start here

Security Deal Desk

Questionnaires, DDQs and buyer security calls, handled. We run intake, build an approved-claims library so nobody overstates anything in writing, track every exception you commit to, and represent you live on the call.

$3,000–$7,500 /month
48-hour response SLA
Or $2,500–$5,000 per project
B2B SaaS founders · CROs · sales leaders
Readiness

Audit Readiness Sprint

SOC 2 or HIPAA from nothing to audit-ready. Gap assessment, a policy set written for how you actually operate, remediation, and an indexed evidence package your auditor accepts.

$12,000–$18,000
21 working days
Fixed scope, fixed fee
Pre-audit startups · CTOs
Proof

Managed Pentest Remediation

Satisfy a mandatory pentest requirement without paying a markup on it. We scope the rules of engagement, select an independent certified tester, manage the engineering fixes, and assemble the auditor package.

$3,500–$7,500
14 days post-test
Tester bills you directly
Startups needing pentest proof

PILLAR 02

Operate assurance

Compliance decays the day the audit ends. Access reviews slip, policies go stale, and twelve months later it is a fire drill again. This is the work that makes the next audit boring.

Recurring

Continuous Assurance

Control calendar, monthly evidence checks, access reviews, policy maintenance and auditor liaison. Your next SOC 2 or ISO 27001 cycle requires no panic and no scramble.

$1,500–$5,000 /month
Ongoing · 6–12 month term
Evidence Care or Operator tier
Post-audit startups · COOs
Leadership

Fractional Security Leadership

A vCISO who owns the roadmap, the board deck and the governance, at a fraction of an executive hire. Steering meetings, budget planning, and someone accountable when the board asks.

$3,000–$15,000 /month
Ongoing · monthly or quarterly
Advisory or executive-lead tier
Scaling mid-market execs · boards
New

Managed Disclosure Program

A vulnerability disclosure program that auditors accept and researchers actually use. Policy with safe-harbour language, security.txt, intake channel, triage of inbound reports, and remediation tracking. Graduates to a funded bounty when you are ready.

$4,500 setup · then $1,500–$3,500/mo
2 weeks to live
Bounty pool funded direct, zero markup
SOC 2 CC7.1 · ISO 27001 · EU CRA

PILLAR 03

Validate security

Policies that have never been tested are not controls, they are documents. This pillar is where we find out whether the thing survives contact with reality.

Tabletop

Incident Readiness Sprint

Turn a static incident policy into a rehearsed decision system. Authority matrix, scenario runbooks, contact trees, and a facilitated two-to-four hour executive tabletop with an after-action plan.

$6,000–$15,000
7–15 business days
Standard or complex scope
CEOs · CTOs facing board or insurer demand
Technical

Cloud Architecture Assurance

A read-only audit of AWS, GCP or Azure. Identity and data-flow review, logging coverage, threat model, and a prioritised remediation backlog your engineers can actually work from.

$8,000–$35,000
2–5 weeks
Single cloud or multicloud
Cloud-native engineering teams · CTOs
Technical

AI Security & Trust Review

Ship Copilots, LLMs and AI features without failing the next enterprise review. Model and tool inventory, data-flow review, acceptable-use policy, and a verified answer library for AI questionnaires.

$8,000–$30,000
2–4 weeks
Diagnostic or implementation
AI-enabled SaaS teams · product leads

The deal desk clock

A questionnaire lands.
Here is exactly what happens.

Every engagement produces a dated record of what was answered, what was promised, and who owns it. You always know where you stand — and so does your buyer's security team.

Hour 00IntakeQuestionnaire forwarded · scope and deadline confirmed · buyer contact identifiedReceived
Hour 04Claims validatedEvery answer matched to something defensible. Nothing asserted that we cannot evidenceValidated
Hour 24Draft returnedGaps flagged as exceptions with a remediation date, not papered overDraft
Hour 48Final answers deliveredSubmission-ready. Added to your approved-claims library for next timeDelivered
Day 05Buyer security callWe join and answer the technical questions. Your engineers stay on the roadmapRepresented
OngoingException registerEvery commitment logged with an owner and a date, so the renewal is not a surpriseTracked

Cloud architecture assurance

You see the gaps before your buyer does.

A coverage map from a real assessment. Every filled cell is a control with evidence behind it. Every empty one is a question an auditor or an enterprise buyer is going to ask.

Control coverage map A gap assessment grid showing partial control coverage across the six NIST CSF 2.0 functions before remediation. NIST CSF 2.0 — CURRENT STATE COVERAGE Govern 40% Identify 60% Protect 45% Detect 25% Respond 20% Recover 30% FILLED = CONTROL EVIDENCED PRE-REMEDIATION

Pricing

Every service, priced in public.

You should know whether this is worth a call before you get on one. Ranges reflect scope and complexity; your number is fixed in writing before any work starts.

ServiceWho it is forFeeTimeline
Security Deal DeskB2B SaaS founders, CROs$3,000–$7,500/mo · or $2,500–$5,000/project48-hr SLA
Audit Readiness SprintPre-audit startups, CTOs$12,000–$18,00021 working days
Managed Pentest RemediationStartups needing pentest proof$3,500–$7,500 management fee14 days post-test
Continuous AssurancePost-audit startups, COOs$1,500–$5,000/mo6–12 mo term
Fractional Security LeadershipMid-market execs, boards$3,000–$15,000/moOngoing
Managed Disclosure ProgramTeams with a public attack surface$4,500 setup · $1,500–$3,500/mo2 weeks to live
Incident Readiness SprintCEOs, CTOs, insurers, boards$6,000–$15,0007–15 business days
Cloud Architecture AssuranceCloud-native engineering teams$8,000–$35,0002–5 weeks
AI Security & Trust ReviewAI-enabled SaaS, product leads$8,000–$30,0002–4 weeks

Pass-through costs are never marked up. Penetration testers, bug bounty platforms and researcher payouts are contracted and billed directly to you at their own rates. Nova Lim accepts no referral fee, commission or reseller margin from any vendor, tester or platform.

Portrait of the founder of Nova Lim

The approach

You will not be handed to a junior.

Large firms sell you a partner and staff the work with people two years out of school. That model exists because it scales. It is also why security programs drift, why nobody can answer the auditor's follow-up, and why the invoice keeps arriving.

Nova Lim is deliberately small. The person who scopes your program answers the questionnaire, sits on the buyer call, and picks up the phone. If that stops being true, the price stops being fair.

Founder, Nova Lim LLC

Before you ask

Isn't a bug bounty out of our budget?

A managed bug bounty runs thirty thousand to half a million a year once platform fees, triage and payouts are counted. That is why we start you on a disclosure program instead — the policy, the intake channel and the triage discipline. It satisfies the auditor, it costs a fraction, and it proves your remediation workflow works before you ever fund a bounty pool.

We already have an IT provider.

Good. They run your systems, which is a different job from proving to an auditor or an enterprise buyer that the controls exist and work. We stay in our lane and work alongside them.

Can't a compliance platform do this?

A platform collects evidence. It does not decide what your controls should be, write answers that hold up under scrutiny, or defend them on a live buyer call. Bring your platform — we will use it.

Why would we trust a tester you picked?

Because we do not get paid for the pick. Testers, platforms and tools contract with you directly at their own rates, and we take no referral fee or margin on any of it. Our only incentive is that the finding gets fixed.

Find out what it costs before you commit to anything.

Thirty minutes. Tell us which deal is blocked and which framework you are being asked for. You will get a fixed-price proposal within 24 hours, or a straight answer that you do not need us yet.