Est. 2019 · Independent practice

Evidence,
not assurance
theatre.

Ryker Audit is a small, senior team performing cybersecurity and controls assurance for companies that take their attestations seriously. We write the report a regulator would write.

Architectural blueprints arranged on a light surface, representing audit documentation
Fig. 01 — Working papers, Q3 engagement
FrameworksSOC 2 Type IIISO/IEC 27001HIPAAPCI DSS 4.0NIST CSFHITRUST
§ 01 — Method

The audit is not a checklist. It is a narrative — a careful reading of how a system actually behaves under stress, scrutiny, and time. Our reports are written to be read, not merely filed.

01
Scope

We agree on what is in and out of scope in writing, before fieldwork begins.

02
Evidence

Controls are tested against live artifacts — not screenshots, not assertions.

03
Report

A written attestation defensible to your board, auditor, and customers.

They asked harder questions than our previous auditor and produced a report our board actually read end to end. The findings were specific enough that we could fix them on Monday.
Head of Security
Series C fintech, 2024 engagement
§ 03 — Testimonials

What clients say afterwards.

Notes from security leaders and finance officers whose reports we signed. Names withheld by request; roles, sectors and years are accurate.

Fig. 02 — Representative engagements · select a mark to read the case study
  1. 01
    The scoping call alone reshaped how we thought about our observation window. By the time fieldwork began, there were no surprises.
    VP, Information Security
    Healthcare SaaS · SOC 2 Type II · 2025
  2. 02
    Fixed fee, fixed timeline, a partner in the room every week. Our third auditor in five years, and the first one we intend to keep.
    Chief Financial Officer
    Series B fintech · ISO 27001 · 2024
  3. 03
    The report reads like it was written by someone who actually understood the system. Our largest customer accepted it without a single follow-up question.
    Head of Trust & Compliance
    Digital health · HITRUST r2 · 2025
§ 04 — Questions

Answers before the call.

The eight questions we field most often from buyers, security leaders, and procurement teams. If yours isn't here, write to hello@rykeraudit.com.

  1. 01
    What frameworks do you audit against?
    SOC 2 Type I and II, ISO/IEC 27001, HIPAA Security Rule, HITRUST CSF, PCI DSS 4.0, and NIST CSF. We also perform readiness assessments against any of the above.
  2. 02
    How long does a typical engagement take?
    Readiness work runs four to six weeks. SOC 2 Type II observation windows are three to twelve months. ISO 27001 Stage 1 to certificate is typically eight to sixteen weeks after readiness is complete.
  3. 03
    What does an engagement cost?
    Fees are fixed and quoted in writing after a scoping call. Most SOC 2 Type II engagements fall between USD 45k and 120k depending on scope, systems, and observation window. We do not bill hourly and there are no scope-creep surprises.
  4. 04
    Are you independent? Can you also remediate findings?
    We are an attest-only practice. We do not sell remediation services, managed security, or software. That independence is what makes the report defensible to your board, customers, and regulators.
  5. 05
    Who signs the report?
    A partner. The same partner who scoped the engagement leads fieldwork and signs the opinion. No hand-offs to junior staff mid-engagement.
  6. 06
    Will you accept evidence from our GRC platform?
    Yes. We work with Vanta, Drata, Secureframe, Tugboat Logic, and native ticketing exports. Automated evidence is sampled and independently verified against source systems — we do not accept dashboards as proof.
  7. 07
    Do you work with pre-revenue or early-stage companies?
    Occasionally, when there is a real customer or regulatory driver. For companies still building a control environment, we recommend a readiness engagement before pursuing an attestation.
  8. 08
    How do we start?
    Request a 30-minute scoping call. A partner responds within two business days with a written scope, timeline, and fixed fee. No sales cycle, no procurement gauntlet.
§ 05 — Begin

A 30-minute call is
the cheapest part of the engagement.