Evidence,
not assurance
theatre.
Ryker Audit is a small, senior team performing cybersecurity and controls assurance for companies that take their attestations seriously. We write the report a regulator would write.

The audit is not a checklist. It is a narrative — a careful reading of how a system actually behaves under stress, scrutiny, and time. Our reports are written to be read, not merely filed.
We agree on what is in and out of scope in writing, before fieldwork begins.
Controls are tested against live artifacts — not screenshots, not assertions.
A written attestation defensible to your board, auditor, and customers.
Eight engagements,
performed seriously.
- 01SOC 2 Type IITrust Services Criteria audits with continuous evidence collection across the observation window.→
- 02ISO/IEC 27001Stage 1 readiness, Stage 2 certification, and surveillance audits aligned to Annex A controls.→
- 03HIPAA & HITRUSTSecurity Rule assessments for covered entities and business associates handling PHI.→
- 04PCI DSS 4.0Self-assessment guidance and Report on Compliance support for merchants and service providers.→
What clients say afterwards.
Notes from security leaders and finance officers whose reports we signed. Names withheld by request; roles, sectors and years are accurate.
- 01
“The scoping call alone reshaped how we thought about our observation window. By the time fieldwork began, there were no surprises.”
VP, Information SecurityHealthcare SaaS · SOC 2 Type II · 2025 - 02
“Fixed fee, fixed timeline, a partner in the room every week. Our third auditor in five years, and the first one we intend to keep.”
Chief Financial OfficerSeries B fintech · ISO 27001 · 2024 - 03
“The report reads like it was written by someone who actually understood the system. Our largest customer accepted it without a single follow-up question.”
Head of Trust & ComplianceDigital health · HITRUST r2 · 2025
Answers before the call.
The eight questions we field most often from buyers, security leaders, and procurement teams. If yours isn't here, write to hello@rykeraudit.com.
- 01What frameworks do you audit against?SOC 2 Type I and II, ISO/IEC 27001, HIPAA Security Rule, HITRUST CSF, PCI DSS 4.0, and NIST CSF. We also perform readiness assessments against any of the above.
- 02How long does a typical engagement take?Readiness work runs four to six weeks. SOC 2 Type II observation windows are three to twelve months. ISO 27001 Stage 1 to certificate is typically eight to sixteen weeks after readiness is complete.
- 03What does an engagement cost?Fees are fixed and quoted in writing after a scoping call. Most SOC 2 Type II engagements fall between USD 45k and 120k depending on scope, systems, and observation window. We do not bill hourly and there are no scope-creep surprises.
- 04Are you independent? Can you also remediate findings?We are an attest-only practice. We do not sell remediation services, managed security, or software. That independence is what makes the report defensible to your board, customers, and regulators.
- 05Who signs the report?A partner. The same partner who scoped the engagement leads fieldwork and signs the opinion. No hand-offs to junior staff mid-engagement.
- 06Will you accept evidence from our GRC platform?Yes. We work with Vanta, Drata, Secureframe, Tugboat Logic, and native ticketing exports. Automated evidence is sampled and independently verified against source systems — we do not accept dashboards as proof.
- 07Do you work with pre-revenue or early-stage companies?Occasionally, when there is a real customer or regulatory driver. For companies still building a control environment, we recommend a readiness engagement before pursuing an attestation.
- 08How do we start?Request a 30-minute scoping call. A partner responds within two business days with a written scope, timeline, and fixed fee. No sales cycle, no procurement gauntlet.