Engagement services. Platform licences. Your tier sets the scope.
Two commercial models. Three customer tiers. Every programme SecureITX delivers is explained before the sales call, scoped in writing within 48 hours, and priced without ambiguity.
- 2
- commercial models: engagement or platform licence
- 3
- customer tiers: SMB, Enterprise, Government & Regulated
- 30
- minutes to scope any engagement at no cost
Understand the model first
Two ways to work with SecureITX. Both start with one call.
The right model depends on whether you need a bounded assessment or a production system running continuously in your environment. Many organisations use both.
Scoped. Delivered. Closed.
A bounded engagement with defined objectives, methodology, scope, and deliverables. Begins with a scoping call. Closes with exploitation-validated findings and a remediation roadmap. No ongoing commitment required, though most organisations re-engage on a cadence.
- Penetration Testing
- Identity & Access Security
- AI Governance
- MCP Security
- Agent AI Security
- Compliance Automation (assessment)
Licensed. On-premises. Running continuously.
A production system deployed on your infrastructure. Your data never leaves your environment. Licensed annually and sized to your deployment: employee count, user count, or agent configuration. Begins with a free assessment or live demo before any commercial commitment.
- Security Awareness Training
- AI Business Intelligence
- Secure Enterprise Collaboration
- Compliance Automation (platform)
Your tier determines your programme
SMB, Enterprise, or Government & Regulated. Different threats. Different constraints. Different programmes.
Automated threat actor infrastructure does not filter by company size. Your defensive posture, budget, and regulatory obligations are specific to your tier, so every programme we build is specific to it too.
A programme built for SMB realities. Not an enterprise programme scaled down.
Ransomware affiliate programmes scan millions of IP addresses continuously, regardless of headcount. SMBs represent the highest-yield segment because lower defensive maturity means faster compromise and faster payment. Supply chain access compounds this: organisations of 50 to 500 employees routinely hold privileged access into larger enterprise clients, making them primary targets even when they are not the final objective.
SecureITX SMB engagements are scoped to the actual attack paths your environment exposes. Findings are written for a management team without a full-time CISO: plain language, ranked by the risk each remediation actually removes, with implementation steps that do not require translating a technical report into an action plan.
What an SMB engagement covers
Full-scope adversarial programmes built around your risk register and board reporting requirements.
Large organisations face adversaries that invest months in reconnaissance before a single exploit is executed. Defending against sophisticated, persistent threat actors requires continuous testing, mature identity governance, and compliance programmes that operate without manual intervention.
SecureITX enterprise engagements are structured around your most critical assets, not a standard checklist. We work alongside your existing security team, integrate with your tooling, and deliver findings that map directly to your risk register and board reporting requirements.
What an enterprise programme covers
Sovereign delivery, cleared assessors, and evidence packages formatted for the regulators who will actually review them.
Government and regulated industry requirements are not enterprise requirements with an additional compliance layer. Data must remain in-jurisdiction by law. Regulatory evidence must follow prescribed formats. Assessors in restricted environments require clearances. SecureITX assessments are structured for government procurement frameworks and the most demanding regulated sectors globally.
Regulated sectors and frameworks covered
Platform services
Every platform starts with a free assessment before any commitment.
Platform services are licensed annually and sized to your deployment. Every one has a zero-cost entry point so you can verify fit before a commercial conversation begins.
Security Awareness Training
Email, SMS, and voice simulation. AI-adaptive difficulty per individual. Micro-training at the moment of failure. Measurable behaviour change.
- Phishing, smishing, and vishing campaigns from live threat feeds
- AI-adaptive difficulty on a 1 to 10 Goldilocks scale per employee
- Compliance evidence for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST CSF
- Individual risk scores and department benchmarks
AI Business Intelligence
Four specialist agents — Finance, HR, Projects, Sales — trained on your domain rules and data structures. Answers in under 7 seconds with 4-component explainability.
- Deployed on your infrastructure — data never leaves your network
- 150+ intent patterns with 79 to 95% confidence scoring
- Role-based data authorization enforced at the query layer
- Full audit log of every query, response, and data access event
Secure Enterprise Collaboration
AES-256-GCM per-message encryption. 45 DLP patterns across 6 categories. Local AI that never contacts an external service. Built for organisations that cannot afford a data leak.
- 45 DLP patterns: financial, PII, healthcare, credentials, network secrets, custom
- 13 named roles, 47 granular permissions, 5 sensitivity classification levels
- eDiscovery with legal hold, configurable retention (7 days to indefinite)
- GDPR, SOC 2, and HIPAA controls built in, not bolted on
Compliance Automation
2,109 controls. 16 frameworks. 48 AI agents monitoring every 5 minutes. Audit-ready evidence generated automatically with no manual evidence collection.
- SOC 2, ISO 27001, PCI DSS, FedRAMP, HIPAA, NCA ECC, ADHICS and more
- 48 AI agents across 48 integrated security systems
- Evidence generated automatically with no manual collection
- Deployed on your infrastructure: no data leaves your environment
Transparency on pricing
We do not publish prices. Here is why, and what determines your quote.
Every engagement is scoped to your actual environment. Publishing a price list would mean either overcharging straightforward environments or under-scoping complex ones. Neither outcome serves you well.
Engagement services — what determines your quote
Platform services — what determines your licence
Every programme begins with a 30-minute call at no cost.
Tell a senior engineer what you are trying to solve. We will recommend the engagement or platform that fits your tier, sector, and current risk posture, and scope it in writing within 48 hours.
Schedule a scoping call