Engagements

One recurring role. Four packaged engagements. One build path. Everything in writing.

Most clients start with the fractional CISO / CTO retainer and add a packaged engagement when a board, a bank, or a roadmap needs a written answer. When the answer needs to become software, the same team scopes and builds it. Every engagement ships a written deliverable and a working session to walk your team through it.

On pricing

The retainer starts at $5,000 a month. Packaged engagements don't have a rate card — each is priced to your organization, your data sensitivity, and your timeline. A 30‑minute call is enough to scope and quote; you'll have a written proposal within two business days.

Scope a call →

01 · Recurring

Fractional CISO / CTO for fintech and digital‑asset firms

Fee
From $5,000 / mo
Time
8–10 hrs / mo
Term
3-month start, then monthly
Discuss this engagement →

A named security executive on your org chart — the one your sponsor bank, SOC 2 auditor, or lead investor just asked about — from someone who has also run the infrastructure, the cloud migration, and the settlement rails. Most clients start here.

What's included

  • Named CISO of record for bank partners, auditors, investors, and regulators.
  • Policy and control set built to your stack and mapped to the framework your counterparties use (SOC 2, sponsor‑bank diligence, NYDFS 500, GLBA).
  • Security questionnaire and diligence responses — drafted, evidenced, and signed. A maintained answer library after the first one.
  • Vendor risk reviews and architecture decisions when there's no CTO in the room.
  • Incident‑response plan, tested once a year, with you on the call if it's ever real.
  • A one‑page monthly risk memo your board and your bank partner can both read.

What's not included

  • Hands‑on engineering or code — that's the Scoping to Build path, with specialists billed at a disclosed rate.
  • SOC 2 / ISO attestation itself — we get you ready; auditors attest.
  • Legal opinions, licensing applications, or BSA officer duties.

Ideal fit

Fintechs and digital‑asset firms with 10–150 people, a technical founder, and an external party — sponsor bank, enterprise customer, auditor, investor — asking who owns security. Especially firms with a diligence deadline in the next 90 days.

Deliverables

  • · Policy and control set (versioned).
  • · Controls matrix in counterparty language.
  • · Diligence / questionnaire responses.
  • · Risk register and remediation roadmap.
  • · Monthly one‑page risk memo.

02 · Sprint

Institutional Readiness for Digital‑Asset Firms

Duration
2 weeks
Format
Fixed scope, fixed fee
Discuss this engagement →

The diligence‑readiness sprint. For digital‑asset and web3 firms that need to be legible to banks, institutional counterparties, and regulators — an ex‑bank CISO's view of what the other side of the table actually checks, before they check it. Usually the first two weeks of a retainer.

What's included

  • Bank‑partnership readiness assessment: what a sponsor bank's risk and compliance teams will examine, mapped against your current posture.
  • Custody and key‑management security architecture review (self‑custody, MPC, qualified custodian integrations).
  • Compliance posture review against institutional counterparty expectations — BSA/AML program surface, travel rule, incident response.
  • Security governance gap analysis at examiner grade: policies, access control, vendor management.
  • Prioritized remediation roadmap sequenced to your partnership timeline.

What's not included

  • SOC 2 / ISO certification work (we get you ready for it; auditors do the attesting).
  • Smart contract audits (referrals to trusted partners).
  • Legal opinions or licensing applications.

Ideal fit

Digital‑asset firms, web3 infrastructure companies, and crypto‑native fintechs pursuing bank partnerships, institutional clients, or a firmer regulatory footing — and done learning what banks check by failing the diligence.

Deliverables

  • · Readiness assessment report.
  • · Custody / key‑management architecture review.
  • · Prioritized remediation roadmap.
  • · Diligence‑ready summary for counterparties.

03

AI Strategy & Roadmap

Duration
2–4 weeks
Format
Fixed scope, fixed fee
Discuss this engagement →

For leadership teams who need a defensible AI plan — not a vendor pitch. Executive workshops, prioritized use cases against your actual constraints, and a 90‑day pilot you can take to a board.

What's included

  • Two executive workshops (current state, target state).
  • Use‑case inventory ranked by ROI, risk, and time‑to‑value.
  • Governance and risk framework mapped to your regulator's expectations.
  • Vendor evaluation criteria (model providers, hosting, build‑vs‑buy).
  • 90‑day pilot plan with success criteria and exit ramps.
  • Board‑ready deck.

What's not included

  • Model implementation, fine‑tuning, or production code.
  • Vendor procurement or contract negotiation.
  • Ongoing operational ownership.

Ideal fit

Banks, fintechs, insurers, and regulated SaaS firms with $50M+ revenue, an exec sponsor, and an AI mandate they don't yet know how to execute responsibly.

Deliverables

  • · Strategy memo (15–25 pages).
  • · Use‑case scorecard.
  • · Governance/risk framework.
  • · 90‑day pilot plan.
  • · Board deck.

04

Secure Cloud Modernization Audit

Duration
2–3 weeks
Format
Fixed scope, fixed fee
Discuss this engagement →

Independent architecture review across cloud and identity systems. Zero‑trust gap analysis, post‑quantum readiness, and a phased modernization roadmap that doesn't break the things that already work.

What's included

  • Cloud architecture review (identity, network, data, key management).
  • Zero‑trust gap analysis with phased remediation.
  • Post‑quantum cryptography readiness assessment.
  • Identity / access governance review.
  • Risk report ranked by likelihood, impact, and remediation cost.

What's not included

  • Pen testing or red‑team operations.
  • Compliance certification (SOC 2, ISO, PCI) work.
  • Smart contract audits (we'll refer trusted partners).

Ideal fit

Mid‑market fintechs and FIs evaluating cloud modernization or due for an independent architecture review — and the board wants a non‑vendor opinion before committing capital.

Deliverables

  • · Risk report with prioritized remediation.
  • · Phased modernization roadmap.
  • · Reference architecture diagrams.

05

Tokenization & On‑Chain Settlement Advisory

Duration
2–4 weeks
Format
Fixed scope, fixed fee
Discuss this engagement →

For FIs and fintechs evaluating tokenized assets, on‑chain settlement, or stablecoin rails. Independent, vendor‑agnostic strategy from someone who has actually built these systems — not a hype piece.

What's included

  • Use‑case framing: where on‑chain settlement adds genuine value vs. where existing rails win.
  • Custody architecture options (self‑custody, qualified custodian, MPC).
  • KYC / AML at the chain edge — keeping travel rule compliant.
  • Regulatory landscape briefing (US/EU as of engagement date).
  • Build‑vs‑partner decision matrix across infrastructure providers.
  • Risk register with prioritized mitigations.

What's not included

  • Smart contract development or audits (referrals to trusted partners).
  • Token issuance legal opinions.
  • Regulatory licensing applications.

Ideal fit

Banks, insurers, payments firms, and asset managers exploring tokenized assets, on‑chain settlement, or stablecoin integration — and the board wants a sober, vendor‑neutral view before committing capital.

Deliverables

  • · Strategy memo with use‑case ranking.
  • · Custody and KYC architecture options.
  • · Build‑vs‑partner decision matrix.
  • · Risk register.

06 · Build

Scoping to Build

Duration
Scoped per build
Format
Fixed fee or milestones
Discuss this engagement →

When a roadmap, audit, or readiness plan needs to become working software, DAPL scopes and delivers the build through its own engineering bench — cloud infrastructure, AI and LLM features, monitoring, integrations — under the same controls the strategy work was written to satisfy. One accountable party from decision to deployment.

What's included

  • Technical scoping: architecture, estimate, and delivery plan, priced before the build starts.
  • Delivery through DAPL's engineering bench, with every specialist's rate disclosed in the SOW.
  • Cloud infrastructure, AI / LLM integration, monitoring and observability, internal tooling.
  • Controls and audit artifacts built in from the first sprint, not retrofitted.
  • Weekly written status and a working demo.
  • Runbooks, handover documentation, and a transition plan to your team or a retainer.

What's not included

  • Open‑ended staff augmentation without a scope.
  • Production ownership after handover, unless under a retainer.
  • Licensing, legal, or regulatory filings.

Ideal fit

Fintechs, digital‑asset firms, and regulated companies whose strategy engagement produced a plan and who want it built by people who understand why the controls are there. Typically a 6–16 week build following a two‑week scoping phase.

Deliverables

  • · Scoping document: architecture, estimate, plan.
  • · Working software in your environment.
  • · Controls and audit artifacts.
  • · Runbooks and handover documentation.

Decide where to start.

Bring the messiest version of the problem you have today. Thirty minutes is enough to point at the right one.