SentinelForge

Industries we focus on

We stay close to a small number of verticals so we can be useful, not generic.

Financial services & fintech

Banking, payments, wealth-tech, insurance carriers. About 42% of our engagements. We understand SOC 1, SOC 2, PCI DSS 4.0, NYDFS Part 500, and the OCC's expectations for third-party risk. Our senior consultants have worked inside financial regulators or the CISO office of tier-1 banks.

Healthcare & healthtech

Provider networks, digital-health SaaS, medical-device firmware, claims platforms. Roughly 20% of our work. HIPAA §164.308, HITRUST, FDA premarket cybersecurity guidance. We hold BAAs with all major healthcare clients.

SaaS & platform

B2B SaaS moving upmarket. About 25% of our work. Common ask: prepare the security story for enterprise procurement, close the gaps a Fortune 500 CISO will actually check on the questionnaire.

Public sector & defense

Selective engagements only, US-cleared personnel available. FedRAMP High, CMMC Level 2/3, DFARS 7012. Roughly 8% of our work. Not our main focus, but where we go we go deep.

Compliance frameworks our reports map to

Every report is cross-referenced to the controls your auditor will ask about.

FrameworkControls we addressCommon use
SOC 2 (Trust Services)CC7.1, CC7.2, CC7.3, CC7.4, CC8.1Annual pentest, vuln management
PCI DSS 4.011.3, 11.4, 6.2, 6.3Annual & post-change pentesting for CDE
ISO/IEC 27001:2022A.5.7, A.8.8, A.8.29ISMS security testing evidence
HIPAA Security Rule§164.308(a)(1)(ii)(A), §164.308(a)(8)Risk analysis, evaluation
NIST CSF 2.0ID.RA, PR.IP-12, DE.CM, RSCybersecurity risk-management program
NYDFS 23 NYCRR 500§500.5, §500.16Annual penetration testing
FedRAMPCA-8, RA-5Annual authorization testing
CMMC 2.0 Level 2CA.L2-3.12.1, RM.L2-3.11.2Assessment support

Not on the list? Ask us — we've likely cross-mapped to it before.