← Back to Home
Services / Projects & Assessments

A defined scope.
A fixed deliverable.
A clear starting point.

Every engagement on this page is a project — scoped, priced, and built toward a specific outcome. Some clients come for one engagement and leave with a result. Most come for one engagement and stay.

Start here
Anchor engagement

Technology Strategy Assessment

Most organizations know something is off before they can say what. IT costs are growing faster than the business. A compliance requirement appeared that nobody saw coming. A technology decision made three years ago is limiting what the company can do now.

This is a fixed-fee, 2–3 week review across infrastructure, operations, security posture, and data — the full leadership picture, not a single-discipline audit. It closes with a scored report and a live presentation that tells you exactly where things stand, what the risk exposure is, and what to address first.

  • Current-state assessment across all four technology disciplines
  • Prioritized findings mapped to business impact
  • 90-day roadmap with clear first steps
  • One scored report, presented live
Fixed fee
$9,000

All four disciplines. One engagement.

Duration
2–3 weeks
Deliverable
Scored report + live presentation
Format
Fixed fee, no scope creep
Book the assessment →

Technology Strategy

3 engagements

Digital Transformation Roadmap

Most organizations don't set out to fall behind. They make reasonable decisions under real constraints, and those decisions compound. By the time the gap between where the technology is and where the business needs to go becomes visible, the path back is longer than anyone expected.

This engagement maps where technology needs to go to support the business you're building — and sequences the path to get there in an order the organization can actually execute.

  • Current-state assessment of IT operations, infrastructure, and vendor landscape
  • Gap analysis against where the business needs to be in 12–24 months
  • Phased transformation roadmap, sequenced by impact and feasibility
  • Decision framework for what to modernize, what to replace, and what to leave alone
Starting at $7,500Scoped to org size
4–6 weeks

AI Policy & Governance Framework Build

By the time most organizations think about AI governance, the adoption has already happened. Tools are in use across departments. Employees are running sensitive data through consumer platforms. And nobody has a clear picture of what's actually in use, what it's touching, or what the exposure is.

We map what's actually in use, identify the risk and exposure it carries, build the controls to manage it, and put governance in place that holds as adoption continues. Implementation-ready, not advisory.

  • Inventory and mapping of AI tools in use across the organization
  • Risk and exposure assessment by tool and use case
  • Acceptable-use policy and vendor-vetting workflow
  • Escalation path for new AI tool requests
Starting at $7,000Scoped to tool inventory
3–5 weeks

Data Strategy Assessment

Most organizations have more data than they can use and less data than they think they have. It lives in systems that don't talk to each other, in formats that don't transfer cleanly, owned by teams that can't always find it when they need it.

Every AI initiative, digital transformation program, and compliance obligation runs directly into this problem. None of them can move faster than the data underneath them.

  • Inventory of data assets across systems and environments
  • Classification by sensitivity, ownership, and business value
  • Gap analysis across governance, quality, and compliance obligations
  • Prioritized roadmap for rationalization and governance
Starting at $6,500Scoped to data environment
3–4 weeks

IT Operations & Delivery

4 engagements

IT Service Management Design

Most IT environments grow faster than their processes do. Tickets pile up without triage logic. Changes go in without a review gate. Incidents get resolved but never formally closed — so the same problem surfaces six months later under a different name.

This engagement documents how work actually flows through IT today, identifies where gaps are creating risk or inefficiency, and builds the process layer the team needs to operate with consistency. The result is implemented workflows — not a slide deck describing best practices.

  • Current-state assessment of incident, change, and request management workflows
  • Gap analysis against operational maturity requirements
  • Designed and documented processes, configured in your existing toolset
  • Runbooks and escalation paths your team can use on day one
$10,500Fixed fee
4–6 weeks

Vendor & SaaS Rationalization Audit

Most organizations don't know what they're paying for. Licenses overlap. Tools that solved a problem two years ago are still renewing. Contracts are on personal cards, in personal inboxes, and owned by people who left.

This engagement produces a complete picture of the technology spend — what's in use, what's redundant, what's underutilized, and what's creating security or compliance exposure through poor vendor oversight.

  • Full inventory of SaaS subscriptions, licenses, and vendor contracts
  • Utilization and overlap analysis across the current stack
  • Risk and compliance assessment of key vendor relationships
  • Prioritized rationalization roadmap with renewal calendar
Starting at $6,500Scoped to stack size
2–4 weeks

MSP Contract & Performance Management

Most organizations hand their infrastructure to a managed service provider and assume the relationship manages itself. It doesn't. SLAs go untracked, contract terms go unenforced, and by the time the client notices, they've been underserved for months — often paying for coverage they're not receiving.

This engagement starts where the contract is — reviewing what was promised, measuring what's being delivered, and closing the gap through enforcement, renegotiation, or transition.

  • Contract and SLA review against current service delivery
  • Performance gap documentation and remediation plan
  • Renegotiation support and vendor-side representation
  • Transition planning and cutover management when the relationship ends
Starting at $5,000Scoped to relationship complexity
2–4 weeks

Business Continuity & Disaster Recovery Planning

Most organizations don't think about continuity until something goes wrong. A ransomware attack, a data center outage, a key system failure — and suddenly there's no documented plan, no defined recovery order, and no one who knows what to do first.

This engagement builds the plan before it's needed — assessing critical systems, defining recovery objectives, and documenting a plan your team can execute under pressure. We also design the test protocol, because a plan that's never been tested is a plan that won't hold.

  • Business impact analysis across critical systems and processes
  • Recovery time and recovery point objective definition
  • Business continuity and disaster recovery plan documentation
  • Tabletop exercise design and facilitation
Starting at $6,500Scoped to org complexity
3–5 weeks

Security, Privacy & Compliance

10 engagements

Security Risk Assessment

Most organizations don't know what they're actually exposed to. They have controls — firewalls, EDR, MFA policies — but no clear picture of whether those controls are covering the right things, configured correctly, or keeping pace with how the environment has changed.

This engagement maps the current security posture across the on-network environment and closes with a prioritized risk register your team can execute against.

  • Threat landscape and attack surface assessment
  • Control review across identity, endpoint, network, and data
  • Risk register with prioritized findings by likelihood and business impact
  • Remediation roadmap sequenced by risk reduction and feasibility
Starting at $7,500Scoped to environment size
2–3 weeks

Privacy Program Build

Privacy requirements don't stop at one border. An organization with customers, employees, or data in multiple regions is operating under multiple legal frameworks simultaneously — GDPR, CCPA, PIPEDA, LGPD, and others — and the obligations compound as the business grows.

This engagement builds a privacy program that holds across the jurisdictions that apply to your organization. The result is a program your team can run, not a binder that sits on a shelf.

  • Data mapping and processing inventory across systems and third parties
  • Gap analysis against applicable privacy obligations by jurisdiction
  • Policy framework covering collection, retention, and data subject rights
  • Operational procedures and documentation for ongoing compliance
Starting at $8,000Scales by jurisdiction
4–8 weeks

Client Risk Assessment Support

When a customer, partner, or enterprise client sends a security questionnaire or initiates a vendor risk assessment, most organizations scramble. The questions are technical, the stakes are high — a failed assessment can hold up a contract or end a relationship — and there's rarely anyone internally who knows how to respond accurately and credibly.

TinBOX steps in as the technical and compliance resource behind the response — reviewing what's being asked, assessing how your organization actually meets each requirement, and responding accurately.

  • Assessment and questionnaire review against actual organizational posture
  • Accurate, defensible response development
  • Gap identification with remediation options
  • Ongoing support for recurring assessment cycles
Starting at $4,000Scoped to assessment scope
1–3 weeks

HIPAA Compliance Assessment

Healthcare data carries legal obligations that don't disappear because the organization isn't a hospital. Any entity that handles protected health information — a technology platform, a benefits administrator, a business associate — is covered. Most organizations in this position don't know their full exposure until it's too late.

This engagement maps where PHI exists, assesses the safeguards required under both the Privacy Rule and the Security Rule, and closes the gaps required for compliance.

  • PHI inventory and data flow mapping
  • Gap assessment across Privacy Rule and Security Rule requirements
  • Risk analysis and risk management plan documentation
  • Policy and procedure development for compliance obligations
Starting at $10,000Scoped to PHI environment
4–8 weeks

SOC 2 Readiness

Customer security questionnaires are getting longer. Enterprise procurement teams are requiring SOC 2 reports before contracts close. If you don't have one, the deal stalls — or goes to a competitor who does.

We assess your current controls against the Trust Service Criteria you're targeting, close the gaps that matter to auditors, and prepare the evidence documentation the audit firm needs to work efficiently. The goal is a clean audit — not the longest possible list of controls.

  • Scoping session to define applicable Trust Service Criteria
  • Control gap assessment against audit requirements
  • Remediation plan with prioritized findings
  • Evidence documentation and audit-readiness review
Starting at $18,000Scoped to criteria and org size
2–4 months

ISO 27001 Readiness

ISO 27001 certification signals something specific to enterprise clients and international markets: that information security is managed systematically, not reactively. The standard requires a formal Information Security Management System — documented, implemented, and internally audited before certification.

This engagement builds the ISMS from the ground up or closes the gap on an existing one, and prepares the organization for the external audit.

  • ISMS scope definition and risk assessment
  • Control implementation against Annex A requirements
  • Policy and procedure documentation
  • Internal audit and management review preparation
Starting at $18,000Scoped to org size and scope
2–4 months

ISO 27701 Readiness

Having a security management system isn't the same as having a privacy management system. ISO 27701 extends ISO 27001 with a formal Privacy Information Management System — the documented structure regulators and enterprise clients increasingly expect when an organization handles personal data at scale.

For organizations under GDPR or similar obligations, it provides a recognized framework for demonstrating accountability. Requires ISO 27001 certification or concurrent pursuit.

  • Privacy control gap assessment against ISO 27701 requirements
  • Extension of existing ISMS documentation to cover PIMS requirements
  • Controller and processor obligation mapping
  • Certification readiness review and audit preparation
Starting at $12,000Scoped to existing ISMS maturity
6–10 weeks

CMMC Readiness

If your organization is pursuing Department of Defense contracts, Cybersecurity Maturity Model Certification is no longer optional — it's a contract requirement. The level required depends on the sensitivity of the information you'll handle, and the assessment process is rigorous.

We work toward the specific level the contract requires — not a higher bar than necessary, not a lower one than defensible. Scope and price vary significantly by CMMC level.

  • CMMC level scoping based on contract requirements
  • Practice gap assessment against applicable domain requirements
  • System Security Plan (SSP) development
  • Plan of Action & Milestones (POA&M) for remediation
Starting at $15,000Level 1 baseline — Level 2+ scoped
2–4 months

FedRAMP & StateRAMP Readiness

Selling cloud services to federal or state and local government agencies requires more than a security assessment — it requires a formal authorization. FedRAMP governs federal procurement; StateRAMP applies the same framework to state and local government. Both require a documented, assessed, and authorized security posture before a contract can close.

This engagement prepares cloud service providers for the authorization process through a documented, assessment-ready security posture.

  • Authorization boundary scoping and system documentation
  • Control implementation gap assessment against applicable baseline
  • System Security Plan (SSP) development
  • Continuous monitoring program design and assessment coordination
Scoped on request
Varies by baseline

ISO 42001 Readiness

AI governance is no longer a future consideration. Organizations adopting AI tools face growing pressure from customers, regulators, and board-level stakeholders to demonstrate that AI use is documented, controlled, and auditable.

ISO 42001 is the international standard for AI management systems. This engagement assesses where the organization stands, builds the governance structure required to meet it, and prepares documentation and controls for certification. It pairs directly with the AI Policy & Governance Framework Build for organizations that need both internal controls and a certification path.

  • AI management system assessment against ISO 42001 requirements
  • Gap analysis across governance, risk, and operational controls
  • Policy and procedure development for AI lifecycle management
  • Certification readiness roadmap with audit preparation guidance
Starting at $10,000Scoped to AI environment
6–10 weeks

Engineering & Cloud

6 engagements

Cloud Migration Planning

Most cloud migrations fail not because of the technology but because of the sequencing. Applications move before the network is ready. Dependencies aren't mapped. The team discovers mid-migration that a critical workload can't leave on-premise without a rebuild that wasn't in the budget.

This engagement plans the migration before anything moves — mapping the environment, assessing workload readiness, and sequencing the path by risk and operational continuity.

  • Current-state inventory across on-network and hosted environments
  • Workload dependency mapping and cloud readiness assessment
  • Phased migration plan sequenced by risk and operational continuity
  • Target architecture design and tooling recommendations
Starting at $7,500Scoped to environment complexity
3–5 weeks

DevSecOps Assessment & Pipeline Design

Security reviews at the end of a development cycle don't work. By the time a vulnerability is found in QA or production, the cost to fix it is ten times what it would have been at the design stage. Organizations that integrate security into the development pipeline find issues earlier, fix them faster, and ship with more confidence.

This engagement assesses where security currently sits in the development lifecycle and builds it into the pipeline — from code commit to deployment.

  • Assessment of current development pipeline and security integration points
  • Toolchain design for static analysis, dependency scanning, and secrets detection
  • Security gate design and policy configuration
  • Developer workflow documentation and runbook for ongoing operations
Starting at $8,000Scoped to pipeline complexity
4–6 weeks

Cloud Architecture Review

Cloud environments drift. What was designed intentionally at launch looks different eighteen months later — new services added without architecture review, permissions that expanded to solve an urgent problem and never got tightened back down, costs that grew faster than the business case that justified them.

This engagement reviews the current cloud environment against what it should look like: secure, cost-efficient, resilient, and aligned with how the organization actually operates.

  • Architecture review across security, reliability, cost, and operational posture
  • IAM and permissions audit
  • Cost optimization analysis and rightsizing recommendations
  • Prioritized remediation roadmap with effort and impact estimates
Starting at $7,000Scoped to cloud footprint
2–4 weeks

AI-Generated Code Quality Audit

AI coding tools are shipping code faster than teams can review it. The productivity gain is real. So is the risk: AI-generated code introduces patterns that look correct, pass automated checks, and fail in production — or worse, introduce security vulnerabilities that don't surface until after a breach.

Where the audit surfaces problems requiring remediation, TinBOX can execute the fixes through our developer network — so findings translate directly into resolved issues, not a backlog no one has time to clear.

  • Codebase review focused on AI-generated code patterns and failure modes
  • Security vulnerability assessment across the reviewed surface
  • Dependency and supply chain risk analysis
  • Prioritized findings with remediation guidance
Starting at $4,500Scoped to codebase size
2–3 weeks

Legacy Modernization Assessment

Legacy systems don't fail dramatically — they accumulate cost. Maintenance overhead grows, integration with modern tooling becomes harder, and the team that understood the original architecture retires or moves on. By the time leadership decides something has to change, the options are narrower than they would have been three years earlier.

This engagement assesses the legacy environment and builds a modernization strategy that's honest about tradeoffs. For organizations ready to move from assessment to execution, TinBOX can manage the modernization directly through our developer network.

  • Inventory and dependency mapping of legacy systems
  • Risk and cost assessment of current-state maintenance
  • Modernization strategy across rewrite, refactor, wrap, and retire options
  • Phased roadmap sequenced by business impact and technical feasibility
Starting at $6,500Scoped to system complexity
3–5 weeks

Custom Software Development

Finding development talent is hard. Evaluating it is harder. Managing a build without technical leadership in-house is where most small business software projects fail — not because the idea was wrong, but because there was no one to hold the work to the right standard.

TinBOX brings the strategy and the network. We scope the problem, design the architecture, and deliver the build through a vetted developer network — with advisory oversight at every stage so the output matches the business need it was built to solve.

  • Requirements definition and architecture design
  • Developer sourcing and engagement management through our network
  • Build oversight with advisory review at defined milestones
  • Delivery, testing, and handoff documentation your team can own
Scoped on request
Varies by scope

Proposal & Bid Support

4 engagements

Government Contract Readiness

Pursuing a federal or state government contract requires more than a strong proposal. Before the bid is submitted, the organization needs to demonstrate it can meet the contract requirements — compliance certifications in progress, documented security posture, and an operational model that holds up to government scrutiny.

This engagement prepares the organization to compete: identifying compliance and documentation requirements for the target contract vehicle and closing the gaps that would disqualify the bid.

  • Contract vehicle and compliance requirement scoping
  • Gap assessment against security and certification requirements
  • Documentation development for proposal and audit readiness
  • Coordination with compliance engagements already in progress
Scoped on request
4–8 weeks

RFP Response Support

Most organizations write RFP responses the way they write internal documents — describing what they do rather than answering what the evaluator is scoring. The technical sections are vague. The compliance requirements are acknowledged but not substantiated.

TinBOX reviews the solicitation, maps the evaluation criteria, and builds the response around what actually gets scored — with technical sections written by people who understand the architecture, security, and compliance requirements the client is claiming to meet.

  • Solicitation review and evaluation criteria mapping
  • Technical section development across architecture, security, and compliance
  • Response structure and narrative coordination
  • Review and gap analysis prior to submission
Scoped on request
Varies by RFP

Technical Proposal Writing

Government and enterprise procurement teams score technical proposals on specificity. A response that says "we follow industry best practices for security" scores lower than one that names the controls, explains the architecture, and demonstrates that the team understands the environment they're proposing to support.

TinBOX writes the technical sections with the depth that comes from having built these programs, not just described them.

  • Security and compliance narrative development
  • Architecture and infrastructure section writing
  • Operational approach and staffing model documentation
  • Alignment review against solicitation requirements
Scoped on request
Varies by proposal

Pre-Award & Oral Support

Winning a proposal on paper doesn't mean winning the contract. Government and enterprise procurement increasingly includes oral presentations, site visits, and negotiation rounds where the written response gets pressure-tested by the people who will approve the award.

For clients already engaged with TinBOX on the written proposal, we extend the engagement through the full pre-award process — preparing the team to defend what was submitted and providing advisory support through negotiation rounds.

  • Oral presentation development and rehearsal against the submitted proposal
  • Technical question preparation and response coaching
  • Site visit preparation and on-site advisory support
  • Negotiation support through contract award
Scoped on request
Varies by procurement

Most engagements end with the same question.

A completed project creates a foundation. The Advisory Retainer is what maintains it — ongoing access to the full TinBOX leadership team across all four disciplines, for a fixed monthly fee. Most clients find their way here after a first engagement. Some start here from the beginning.