Information security consulting
Make security the reason you win the deal,
not the reason it stalls.
Level Four builds right-sized security programs that stand up to your customers’ questionnaires — and publishes the evidence that gets you through their review without a three-month detour.
Fixed fee. Three to four weeks. Senior practitioners, start to finish.
Why now
Security review became a stage of the sale
Somewhere in your pipeline is a deal waiting on a questionnaire. The person who sent it is usually not trying to be difficult — they are answering to a regulator, an auditor, an insurer or a board, and they cannot close until they have something in writing from you. Whether that obligation reaches them through a statute or a contract, the effect on your revenue is identical: weeks of delay, and a document a sales engineer is rebuilding from scratch every time one arrives.
The fix is not a bigger security budget. It is a program sized to your actual risk, written down once, in a form that answers in every framework your customers ask in.
Before
Every questionnaire is a project
Engineering and sales stop to reconstruct the same answers. Nobody is confident the answers are true. The deal waits.
After
Every questionnaire is a lookup
One control register, one answer bank, one public page a prospect finds before they even send the document. Days instead of weeks.
Either way
Your customer answers for you
When something goes wrong at a vendor, the customer’s name is on the notification. Under some rules that is literally true — a dealer’s reportable breach is published in a federal database under the dealer’s own name, whoever caused it.
Philosophy
Safe, right-sized, frictionless
Security should be practical, business-enabling and protective. It should not be overburdening, restrictive or in the way. Those are not competing goals — a control that people quietly route around protects nothing at all.
Safe
Protective where it actually counts
We start from what would genuinely hurt your business and work back, rather than working forward from a checklist written for someone else’s threat model.
Right-sized
Affordable to build and to keep
Scoped to your size, your data and your customers — not to a template written for a bank. You should be able to afford the program you end up with, and to keep running it after we leave.
Frictionless
Business-enabling, not in the way
Controls designed around how your people already work. Security that slows every deal and every deploy gets disabled the first time it is inconvenient.
Who we work with
Organizations that get asked hard questions by people who can walk away
The pressure looks different depending on who is asking. The work underneath it is the same: know what you actually do, write it down in a form someone else can check, and fix the gaps in an order you can afford.
SaaS and software companies
Selling into enterprise buyers whose procurement teams send a questionnaire before they send a contract.
FinTech
Payments, lending and financial data, with sponsor banks, partners and regulators all asking at once — and many non-bank lenders and payment companies covered by the FTC Safeguards Rule themselves.
eCommerce providers
Cardholder data in scope, PCI DSS obligations attached to it, and platform and card-brand requirements on top.
Vendors serving auto dealers
Where our deepest domain work is. Your customers carry a federal obligation to assess you, and they are increasingly acting on it.
Dealerships and dealer groups
On the other side of the same rule: an information security program you own, and a defensible way to assess the vendors you buy from.
Small and mid-sized businesses
Getting the same questionnaires as companies ten times the size, with none of the staff to answer them.
Nonprofits
Donor and beneficiary data, grant-maker due diligence, and a budget that has to be argued for. Scoped accordingly.
More than one of these?
Most companies are. A FinTech selling SaaS to dealers is all four at once, and the register handles it — Contact us and a thirty-minute call sorts out which frames apply.
The name
Most programs stop at three
We score every control on a five-point scale. A control can be present, and consistent, and still be invisible to the person deciding whether to buy from you. Level four is the one that produces evidence a customer can read without asking you for it — a register, an artifact, a page. The distance between three and four is the entire business.
Engagements
What we do
One assessment that tells you where you stand and what to do about it, then a set of follow-on projects you can commission individually — or not at all.
Core
Security assessment and roadmap
A control register crosswalked across the SOC 2 Trust Services Criteria, ISO/IEC 27001, NIST CSF 2.0 and NIST SP 800-53 — and, where they apply to you, PCI DSS, FTC Safeguards § 314.4 and ISO/IEC 42001. Scored, prioritized and sequenced.
Follow-on
The projects the roadmap names
SOC 2 readiness, PCI DSS scope reduction, email authentication, a vulnerability disclosure program, a public trust page, customer contract terms, and a questionnaire answer bank. Each separately scoped and separately commissionable.
What we believe
Judge us on what changes
Anyone can hand over a report and leave. We would rather be measured by what is different three months later — the deal that stopped stalling, the questionnaire that took a day instead of two weeks, the control that finally has a record behind it. We move the ball down the field, and we scope the work so that something actually moves.
- Do the right thing. The reason to hire an advisor is that you cannot verify everything they tell you. We treat that as an obligation rather than an opportunity.
- Customers are partners. When the right answer is smaller than what we would like to sell, the right answer is what we recommend. We would rather be the firm you call again than the invoice you remember.
- Everything with quality. Work leaves here when it is right, not when the budget is used up.
- Safe, right-sized and frictionless. Security that gets quietly worked around protects nothing at all, so we design for how your people already work.
Where we go deepest
Automotive retail technology
Every dealership that finances or leases vehicles falls under the FTC Safeguards Rule. FTC Safeguards § 314.4(f) requires the dealer to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess the provider. That obligation is what generates the questionnaire traffic in this market — and we have spent years on the other side of it, inside a portfolio of dealer-facing brands.
We also published the only study we know of that measures what this market actually discloses. In August 2026 we assessed 101 vendor brands, operated by 87 independent companies, against two layers of entirely public signal. Nothing was scanned or tested. Every assessed brand receives its own scorecard before the aggregate is published.
Assessed on Faith · findings publish after vendor notification
Read the method