FAQ

The questions buyers ask us first

Can't find yours? Ask us directly. A person replies, usually the same day.

Is there a minimum size?+

We work with organisations from about 25 devices upwards. Below that, Trace on its own is usually the better fit.

You're a young company. Why should we trust you with our environment?+

Fair question. Our founders have run SOCs before, response permissions are scoped and contractual, and every action we take is logged in a console you can see. Our trust centre lists exactly what is certified and what is in progress.

What happens if you miss an SLA?+

You get service credits against that month’s fee, set out in the contract. We report our own SLA performance to you every month.

Do we need to replace our EDR or buy new tools?+

No. Pulse connects to the EDR, identity, cloud and email tools you already have. If you have no EDR, we will recommend options, but we do not resell.

Do you scan for vulnerabilities?+

Trace Exposure scans your internet-facing perimeter and cloud assets. For internal vulnerabilities, Trace ingests findings from the scanners you already run and ranks them by real risk.

What can you do without asking us?+

Only the actions you pre-approve at onboarding, such as isolating an endpoint or revoking sessions. Everything else needs your sign-off. See the full list on the Pulse page.

How long is the contract, and can we leave?+

12 months, billed annually. On exit you get a full export of your data in open formats, and we delete it within 30 days.

Is incident response included?+

Containment is included from the Assured tier. Full incident response and forensics, with no separate retainer, are included in Elite.

Where is our data stored?+

In the region you choose, and it does not leave that region. Telemetry is kept for 90 days; data linked to a major incident is retained for 13 months.

Which frameworks do you assess against?+

CIS 18 (v8.1), ISO/IEC 27001:2022, NIST CSF 2.0, SOC 2, NCSC CAF, NIS2, GDPR and UK GDPR, and the CCPA. If you need another framework, ask us.

Which framework should we start with?+

Start with whatever your customers, regulators or insurers ask for. If nobody is asking yet, CIS 18 at Implementation Group 1 is a practical first baseline that maps cleanly to the others.

How long does an assessment take?+

A baseline typically takes two weeks from kick-off to report. Larger scopes, multiple sites or several frameworks at once take longer, and we agree the timeline before we start.

What do you need from us?+

A named contact, two to four hours of interviews with the right owners, access to existing policies, and read access to the tools Pulse and Trace connect to. We collect the rest of the evidence directly.

Can one assessment cover more than one framework?+

Yes. We map each control once across frameworks, so evidence collected for CIS 18 also counts towards ISO 27001, NIST CSF and the others you hold.

Do you issue certifications or audit reports?+

No. ISO 27001 certificates come from an accredited certification body and SOC 2 reports from a licensed CPA firm. We get you ready, collect the evidence and support you through the audit.

How are controls scored?+

Against the framework’s own model where it has one, such as CIS Implementation Groups, NIST CSF tiers or CAF outcome ratings. Every score is backed by evidence you can review.

What happens after the assessment?+

You get a prioritised roadmap with owners and dates. Results stay live in Attest, so scores update as you remediate, and we can re-assess at each phase gate.

Is the CCPA or GDPR assessment legal advice?+

No. We assess the security measures behind your privacy obligations and work alongside your privacy counsel or DPO, who remain responsible for legal interpretation.