Now hiring — 6 embedded roles open

Compliance that lives inside the startup.

We sit at the table between first funding and first audit — translating GDPR clauses, SOC 2 controls, and ISO frameworks into plain-language playbooks founders actually read.

0
Audits Navigated
SOC 2, ISO 27001, GDPR, HIPAA — across every sector
0
Startups Currently Embedded
We're inside the room, not on a retainer call
0
Enforcement Actions
Across our entire portfolio. Not a single one.
0.0
Avg Days: Kickoff → Controls Mapped
Because founders can't wait six weeks for a framework

These numbers need more people behind them.

01 — The Broken Reality

Every card is a real scene. Flip it to see where you'd fit.

Hover any card to see the role that solves it. Click to apply for that role directly.

Chaos: Security02:14 AM
🛡

Founder Googling SOC 2 at 2 a.m.

The Series A closed three weeks ago. The enterprise prospect wants a SOC 2 Type II report by Q3. Nobody on the team has ever written a security policy.

HOVER TO SEE THE ROLE →
CE-01OPEN ROLE

Compliance Engineer

You turn a panicked Notion doc into a working controls library in 4.2 days. You know which TSCs actually matter for a 12-person SaaS and which are theater.

Chaos: PrivacyWEEK 6
🗺

Series B Due Diligence Stalling

The lead investor's legal team asked for a data processing inventory. The answer was a spreadsheet last updated in 2023 with three rows and a column called "misc."

HOVER TO SEE THE ROLE →
PPL-02OPEN ROLE

Privacy Program Lead

You own the data map from day one. GDPR Article 30 records that are actually accurate. RoPA that an investor's counsel can read without a Xanax.

Chaos: LegalSINCE 2021
📋

Privacy Policy Copy-Pasted from a Competitor

The privacy policy references a DPA with a vendor they no longer use, mentions CCPA compliance they haven't implemented, and was last reviewed by someone who left in 2021.

HOVER TO SEE THE ROLE →
CEA-03OPEN ROLE

Client Embedded Analyst

You sit inside the client's Slack, attend their sprint planning, and catch the broken policy before it becomes a breach notification. You build systems, not slide decks.

Chaos: GovernanceQ4 AGAIN
📐

ISO 27001 Kicked Down the Road Again

The CTO said "we'll do ISO after the product launch." That was four product launches ago. Now a NHS contract requires it and the timeline is 90 days.

HOVER TO SEE THE ROLE →
GRC-04OPEN ROLE

GRC Program Manager

You've run ISO 27001 implementations in 90-day sprints. You know which controls to tackle first, which auditor relationships matter, and how to keep engineering actually engaged.

Chaos: Vendor RiskAUDIT DAY
🔗

Third-Party Vendor Risk? What Vendor Risk?

The startup uses 47 SaaS tools. Three process personal data. None have DPAs. One is headquartered in a country with no adequacy decision. The CPO found out during a customer audit.

HOVER TO SEE THE ROLE →
PPL-02OPEN ROLE

Privacy Program Lead

You build the vendor assessment process before the audit, not during it. You know which SCCs are current, which adequacy decisions cover which transfers, and which vendors just need a DPA email.

Chaos: Culture34% CLICK RATE
🧠

Security Training: One Video, Once, in Onboarding

The phishing simulation hit 34% click rate. The CEO clicked the test email twice. The "security culture" is a checkbox in the onboarding doc nobody reads after week one.

HOVER TO SEE THE ROLE →
CE-01OPEN ROLE

Compliance Engineer

You design security awareness that engineers don't resent — tabletop exercises that feel like product reviews, phishing simulations with post-mortems, controls that fit how the team actually works.

02 — The Kitchen Table

Pull up a chair. Everyone's working hard.

The people who come to work here are ex-Big Four consultants tired of billable-hour theater. Junior lawyers who want to build systems instead of review them. Ops generalists who light up when they find a broken process.

We sit inside the startup during the messy middle — between first funding and first audit. We're in the Slack channels, attending sprint planning, translating GDPR clauses into plain-language playbooks founders actually read at 2 a.m.

The conversation is sharp. The work is real. And there's a place already set for you.

🏠Fully remote, always
📅Async-first culture
🧰Build systems, not reports
No billable-hour targets
Priya Nambiar, Compliance Engineer, smiling professional woman with dark hair
Priya NambiarCompliance Engineer

Ex-Deloitte, 6 years. Left after billing 2,400 hours on a report nobody read.

"I wanted to fix the process, not just document it."

Marcus Webb, GRC Program Manager, professional man in business casual attire
Marcus WebbGRC Program Manager

Junior associate at a NYC law firm. Spent 18 months reviewing contracts he couldn't change.

"Building systems beats reviewing them. Every time."

Saoirse Ó Briain, Privacy Program Lead, woman with auburn hair in professional setting
Saoirse Ó BriainPrivacy Program Lead

Ops generalist at three Series A companies. Found a broken GDPR process at each one.

"Broken processes are just opportunities nobody's claimed yet."

03 — The Work

What an engagement actually looks like.

Four phases. No mystery. You'll know what we're doing, why we're doing it, and what good looks like before we start.

🪑Day 1–3

Embedded onboarding

We join your Slack, attend one sprint planning, review your current tool stack, and map every data flow we can find. No questionnaire. No slide deck. We just start.

🔍Day 4–7

Gap assessment

We deliver a plain-English gap report. Not a 60-page PDF — a prioritised list of what matters, what can wait, and what's actually fine. With a timeline attached.

🔧Week 2–4

Controls build

We write the policies. We configure the tooling. We run the vendor reviews. We train the team in ways that stick. You ship product. We close the gaps.

⚙️Ongoing

Embedded maintenance

Monthly reviews, evidence collection, audit prep, new vendor onboarding, incident response support. We stay embedded until you don't need us — then we hand off clean.

📖

We write playbooks founders actually read

No 40-page policy documents. No legal boilerplate. Every playbook is written for the audience — founders, engineers, and ops teams who need to act, not just acknowledge.

100%plain language
📅6 weeks

Average engagement

From kickoff to first clean controls evidence

🚀$2M–$50M

Startup stage

Seed to Series C. The messy middle is our home.

We stay until the audit passes

Not a fixed-term retainer. We measure success by the audit result, not the hours logged.

0
failed audits in portfolio

Frameworks we navigate daily

SOC 2 Type I & IIISO 27001GDPRCCPA / CPRAHIPAAPCI-DSSFedRAMP (Advisory)NIST CSFDORAUK GDPRISO 27701TISAX
04 — Voices From the Table

Founders who've been in the messy middle.

I thought SOC 2 would take us six months and a Big Four firm. Comply had us audit-ready in seven weeks. They were in our Slack every day — it felt like a team member, not a vendor.

Tariq Al-Rashidi, Co-founder and CTO, professional man in business setting
Tariq Al-Rashidi
Co-founder & CTO · Fieldstack (Series A, $8M)

Our Series B due diligence stalled for three weeks on the data map question. Comply fixed it in four days. Four days.

Nkechi Okonkwo, CEO, professional woman in business setting
Nkechi Okonkwo
CEO · Meridian Health (Seed, $3.5M)

The privacy policy they wrote is the first one I've seen that actually explains what we do. Our customers noticed.

Dmitri Volkov, Head of Legal, professional man in office environment
Dmitri Volkov
Head of Legal · Cloudpath (Series B, $22M)
Amara Mensah, VP Engineering, professional woman in tech environment

I was skeptical of embedded compliance. I thought it meant someone sitting in our office eating our snacks. What I got was someone who understood our product architecture better than most of our engineers did after a week.

Amara Mensah
VP Engineering · Arkive AI (Series A, $12M)
05 — The Open Seat

The table is set. Is this your seat?

No résumé on first touch. No cover letter theater. Just three questions and a conversation. We've set a place for the right person — tell us if that's you.

6 embedded roles · Remote-first · Response within 2 business days