Skip to content

Third-party risk, governance, and the tools to make them work.

Entelechy Security is a founder-led boutique consultancy that helps organizations understand risk, make defensible decisions, and put effective security programs into practice. The practice specializes in third-party risk, audit readiness, AI governance, and building tools that make those programs easier to run.

EST. 2024

Where I can help

Most engagements combine two or three of these. Scope follows a conversation about your situation, not a package.

Third-party risk and compliance

The core of the practice. I build and run vendor-risk programs end to end, and get you ready for the audit that follows: intake and tiering, evidence review, remediation tracking, and a register your auditor can follow.

AI governance and operational resilience

A clear position on AI use — what’s allowed, what needs review, who signs off — alongside continuity and incident work that gets tested before an incident does.

Security workflow engineering

The integrations and internal tools that take the manual work out of GRC, without moving anyone’s review or approval authority.

How I work

Every finding names its source; where the evidence isn’t there, it stays an open question. Automation handles the retrieval and the chasing, and a named person owns each decision.

I do the work myself, and leave behind a process your team can run without me.

Veritas

In development

Veritas connects assessment findings to their source evidence and flags unsupported conclusions for human review. It works across the documents a vendor sends — SOC 2 reports, questionnaires, and penetration-test summaries — and the judgment stays with a person.

How a finding stays tied to its evidence

Source — vendor SOC 2 report (sample passage)

§4.2 Logical Access. Access to production systems requires multi-factor authentication for all personnel. Access rights are reviewed on a quarterly basis by the security team. …

Finding, linked to source

The report states that production-system access requires MFA for all personnel.

Cited: SOC 2 Type II report · p. 24, §4.2

Pending review — a person confirms whether this reflects the control in operation.

Illustrative. Sample content, not a screenshot of a working product.

Tell me what you’re working through.

The framework and the deadline, the size of the portfolio, or the process that keeps stalling.

Discuss a project