LEVELFOURINFORMATIONSECURITY

Information security consulting

Make security the reason you win the deal,
not the reason it stalls.

Level Four builds right-sized security programs that stand up to your customers’ questionnaires — and publishes the evidence that gets you through their review without a three-month detour.

Start with a scoping call

Fixed fee. Three to four weeks. Senior practitioners, start to finish.

Why now

Security review became a stage of the sale

Somewhere in your pipeline is a deal waiting on a questionnaire. The person who sent it is usually not trying to be difficult — they are answering to a regulator, an auditor, an insurer or a board, and they cannot close until they have something in writing from you. Whether that obligation reaches them through a statute or a contract, the effect on your revenue is identical: weeks of delay, and a document a sales engineer is rebuilding from scratch every time one arrives.

The fix is not a bigger security budget. It is a program sized to your actual risk, written down once, in a form that answers in every framework your customers ask in.

Before

Every questionnaire is a project

Engineering and sales stop to reconstruct the same answers. Nobody is confident the answers are true. The deal waits.

After

Every questionnaire is a lookup

One control register, one answer bank, one public page a prospect finds before they even send the document. Days instead of weeks.

Either way

Your customer answers for you

When something goes wrong at a vendor, the customer’s name is on the notification. Under some rules that is literally true — a dealer’s reportable breach is published in a federal database under the dealer’s own name, whoever caused it.

Philosophy

Safe, right-sized, frictionless

Security should be practical, business-enabling and protective. It should not be overburdening, restrictive or in the way. Those are not competing goals — a control that people quietly route around protects nothing at all.

Safe

Protective where it actually counts

We start from what would genuinely hurt your business and work back, rather than working forward from a checklist written for someone else’s threat model.

Right-sized

Affordable to build and to keep

Scoped to your size, your data and your customers — not to a template written for a bank. You should be able to afford the program you end up with, and to keep running it after we leave.

Frictionless

Business-enabling, not in the way

Controls designed around how your people already work. Security that slows every deal and every deploy gets disabled the first time it is inconvenient.

Who we work with

Organizations that get asked hard questions by people who can walk away

The pressure looks different depending on who is asking. The work underneath it is the same: know what you actually do, write it down in a form someone else can check, and fix the gaps in an order you can afford.

SaaS and software companies

Selling into enterprise buyers whose procurement teams send a questionnaire before they send a contract.

FinTech

Payments, lending and financial data, with sponsor banks, partners and regulators all asking at once — and many non-bank lenders and payment companies covered by the FTC Safeguards Rule themselves.

eCommerce providers

Cardholder data in scope, PCI DSS obligations attached to it, and platform and card-brand requirements on top.

Vendors serving auto dealers

Where our deepest domain work is. Your customers carry a federal obligation to assess you, and they are increasingly acting on it.

Dealerships and dealer groups

On the other side of the same rule: an information security program you own, and a defensible way to assess the vendors you buy from.

Small and mid-sized businesses

Getting the same questionnaires as companies ten times the size, with none of the staff to answer them.

Nonprofits

Donor and beneficiary data, grant-maker due diligence, and a budget that has to be argued for. Scoped accordingly.

More than one of these?

Most companies are. A FinTech selling SaaS to dealers is all four at once, and the register handles it — Contact us and a thirty-minute call sorts out which frames apply.

The name

Most programs stop at three

We score every control on a five-point scale. A control can be present, and consistent, and still be invisible to the person deciding whether to buy from you. Level four is the one that produces evidence a customer can read without asking you for it — a register, an artifact, a page. The distance between three and four is the entire business.

Engagements

What we do

One assessment that tells you where you stand and what to do about it, then a set of follow-on projects you can commission individually — or not at all.

Core

Security assessment and roadmap

A control register crosswalked across the SOC 2 Trust Services Criteria, ISO/IEC 27001, NIST CSF 2.0 and NIST SP 800-53 — and, where they apply to you, PCI DSS, FTC Safeguards § 314.4 and ISO/IEC 42001. Scored, prioritized and sequenced.

Follow-on

The projects the roadmap names

SOC 2 readiness, PCI DSS scope reduction, email authentication, a vulnerability disclosure program, a public trust page, customer contract terms, and a questionnaire answer bank. Each separately scoped and separately commissionable.

See what is in the engagement

What we believe

Judge us on what changes

Anyone can hand over a report and leave. We would rather be measured by what is different three months later — the deal that stopped stalling, the questionnaire that took a day instead of two weeks, the control that finally has a record behind it. We move the ball down the field, and we scope the work so that something actually moves.

  • Do the right thing. The reason to hire an advisor is that you cannot verify everything they tell you. We treat that as an obligation rather than an opportunity.
  • Customers are partners. When the right answer is smaller than what we would like to sell, the right answer is what we recommend. We would rather be the firm you call again than the invoice you remember.
  • Everything with quality. Work leaves here when it is right, not when the budget is used up.
  • Safe, right-sized and frictionless. Security that gets quietly worked around protects nothing at all, so we design for how your people already work.
All eight, in full

Where we go deepest

Automotive retail technology

Every dealership that finances or leases vehicles falls under the FTC Safeguards Rule. FTC Safeguards § 314.4(f) requires the dealer to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess the provider. That obligation is what generates the questionnaire traffic in this market — and we have spent years on the other side of it, inside a portfolio of dealer-facing brands.

We also published the only study we know of that measures what this market actually discloses. In August 2026 we assessed 101 vendor brands, operated by 87 independent companies, against two layers of entirely public signal. Nothing was scanned or tested. Every assessed brand receives its own scorecard before the aggregate is published.

Assessed on Faith · findings publish after vendor notification

Read the method