Services & Products

Security services built around your business.

Focused assessments, ongoing vulnerability management, compliance readiness, and AI security — scoped to what you actually run. Every engagement is delivered by the practitioner who scoped it.

Platform AgnosticFrom maximizing your current tech stack and deploying our proprietary tools, to implementing enterprise-grade solutions, we build a plan tailored to all your needs in any budget.

Plain languageReports your board and your insurer can read, and a queue your engineers can work.

Senior deliveryThe engineer who scopes your work is the one who delivers it. No handoff to a junior, no account manager in between. English or Español.

Category 01

Vulnerability Management

Our core practice, built on VM3 — our own published maturity model. For teams that scan but can’t prove risk is going down.

VM3 Maturity Assessment

We score your vulnerability-management program across five levels and five operational dimensions, then hand you a ranked roadmap to the next level.

Best forTeams with a scanner and no program

VM Program Buildout

We stand up the whole loop: asset coverage, scan cadence, triage rules, SLAs, exception handling, and reporting that survives an audit.

Best for25–250 staff, post-assessment

Managed Vulnerability Management

We run the scan-to-fix loop on your existing tooling every cycle: triage, prioritized queue, remediation validation, and a VM3 re-score. We are not a SOC and this is not 24/7 monitoring — it is a program, run properly.

Best forOrganizations with no internal security staff

Category 02

Assessments & Testing

Where most engagements start. Find out what you’re actually exposed to, in language you can take to a board or an insurer.

Small Business Security Risk Assessment

A full picture of your security posture: cloud and identity configuration review, external exposure scan, interviews, and a prioritized remediation plan with a plain-language readout.

Best forFirst-time buyers, 10–200 staff, insurer or customer driven

Cloud Security Review

Configuration and identity review across Microsoft 365, Entra ID, AWS, or GCP: privileged access, conditional access, logging coverage, external sharing, and misconfiguration remediation.

Best forCloud-first teams that grew faster than their config review

Application Security Test

Hands-on testing of a web or mobile application: authenticated and unauthenticated testing, access-control and business-logic flaws, API surface, and a report you can hand to a customer. Mobile testing available as an add-on.

Best forSaaS and product teams facing a customer security review

We do not offer internal network penetration testing or red-team engagements. When an engagement needs them, we say so and refer you to a vetted partner rather than stretching to cover it.

Category 03

Compliance & Advisory

For when a customer, an auditor, or a prime contractor is asking questions you can’t answer yet.

SOC 2 Readiness

End-to-end Type I readiness: system description, Trust Services Criteria mapping, the full policy suite, evidence collection, vendor carve-outs, and auditor liaison. We take you to the audit, we don’t perform it.

Best forB2B SaaS with enterprise deals stalled on a report

CMMC / NIST 800-171 Gap Assessment

Scope your CUI boundary, assess against NIST SP 800-171, calculate your SPRS score, and leave with an SSP outline and a POA&M. Led by a CyberAB Registered Practitioner.

Best forDefense subcontractors under DFARS pressure

PCI DSS Readiness Assessment

We scope your cardholder data environment, assess it against PCI DSS v4.0, and hand you a gap report, a prioritized remediation plan, and support completing your SAQ. Our founder has run three full PCI DSS audit cycles across 300+ controls, so you get someone who has been through it rather than someone reading the standard for the first time. We prepare you for your assessment. We are not a QSA, we do not perform certified assessments, and we do not issue an Attestation of Compliance.

Best forMerchants and service providers facing an acquirer deadline or an annual SAQ

vCISO / Fractional Security Leadership

Senior security ownership without a full-time hire: roadmap, policy upkeep, vendor reviews, customer questionnaires, and a quarterly summary your board can read.

Best for25–250 staff making security decisions with nobody qualified to make them

Also available — usually added to an engagement rather than bought alone

  • Policy & Documentation PackageThe policy suite an auditor or client questionnaire expects, mapped to your framework and written for your actual environment — not templates with your logo on top.
  • Incident Response ReadinessThe plan, playbooks, roles and a tabletop that satisfy a control such as PCI DSS 12.10. Preparation and documentation.
  • Security Awareness TrainingA live session built for your staff and your risks, with materials and a knowledge check you keep as evidence. Available in English or Spanish.

Category 04

AI Security & Enablement

Two different problems. Securing the AI you’ve already switched on, and finding where AI would actually pay for itself. We do both, because we build agentic tooling ourselves — with containment boundaries and audit logging — and then we secure it.

AI Security Readiness Review

You turned on Copilot, a chatbot, or an agent. We inventory where your data actually flows, review it against the OWASP LLM Top 10 and NIST AI RMF, check guardrails and audit logging, and tell you what to fix first.

Best forAnyone who adopted AI faster than they reviewed it

AI Opportunity Map

A time inventory of what your team repeats, scored on impact, confidence, and ease, and returned as a ranked automation roadmap. You find out what to automate first — and what to leave alone.

Best forOps-heavy small businesses; the buyer here is usually the owner, not IT

Secure AI Automation Build

We build the workflow you picked from the map, with the security engineering baked in: explicit containment boundaries, human intervention points, least-privilege access, and append-only audit logging. Automation you can show an auditor.

Best forClients ready to build after an Opportunity Map

Questions

Frequently asked

Do you do network penetration testing or red-teaming?

No. We test applications — web, mobile and API. Internal network penetration testing and red-team engagements are a different discipline and we don’t staff them. If your engagement needs one, we’ll say so and refer you to a vetted partner.

Do you provide 24/7 monitoring or emergency incident response?

No. We are not a SOC and we don’t hold an incident response retainer. What we do is build and run vulnerability management programs, and prepare you for incidents — plans, playbooks and tabletop exercises that satisfy compliance controls like PCI DSS 12.10.

Are you independent and vendor-neutral?

Yes. Invictus is independent and product-agnostic — a proud supporter of any and all security tooling and vendors. The right tool is the one that’s best for you. We run programs on the tools you already own, and if something new genuinely helps, we tell you what to look for and leave the choice to you.

What if we have no security staff at all?

That’s our typical client. Most of our work is with organizations where security is somebody’s third job. We write for that reader, and we hand your engineers a queue rather than a PDF.

Remote or on-site?

Both. We’re based in San Antonio and work on-site across the metro. Everything we deliver is remote-capable, and we work with clients outside Texas.

¿Ofrecen servicios en español?

Sí. Podemos realizar la evaluación, la capacitación y los informes en español. No es parte de la promoción — es algo que siempre ofrecemos. / Yes. Assessments, training and reporting are available in Spanish year-round, not as a limited-time offer.

How fast can you start?

Usually within two days of a signed scope. We take on a limited number of engagements at a time deliberately — the person who scopes your work is the person who does it.

Are you insured? Will you sign an NDA?

Yes to both. We carry errors and omissions, professional liability and general liability coverage, and we sign NDAs before scoping conversations as a matter of course.

Contact

Talk to Invictus

Tell us what you're working on and we'll follow up. A real engineer reads every message.

Send us a note

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use your details to reply to you and nothing else. We don't sell or share them.