About
We prepare you for the audit. We don't run it.
Radcore Security is a small, 100% US-based team that fixes the SOC 2 and ISO/IEC 27001:2022 control gaps automation flags but doesn't close. We work remotely with clients nationwide.
Who's on it
Shawn Gay
Software Engineer
Builds and maintains the tooling and integrations Radcore's engagements run on.
Adrian Gonsalez
Project Manager
Runs the engagement: timeline, evidence tracking, and the single point of contact on your side.
Luke Witherow
Security Lead
Runs the gap review and leads the remediation work that closes what the tooling flags.
How we work
You get one point of contact for the length of the engagement: someone who tracks evidence, chases what's missing, and keeps the timeline honest. No rotating account team, no "we'll circle back."
There's one line we don't cross: Radcore prepares clients, we don't audit or certify them. Independence rules prohibit the same firm doing both. When you're ready, we introduce you to an independent CPA firm for SOC 2 or an accredited certification body for ISO/IEC 27001:2022, and sit on your side of the table through it.
Our GRC platform
Radcore runs your program on our own proprietary GRC platform: control monitoring, evidence collection, and policy management in one place. It's part of the engagement, not a separate compliance subscription stacked on top of our fee, which keeps your total cost down. We configure the monitors, write the policies automation can't, and close the gaps it leaves.
Find out which gaps are actually blocking your report.
Thirty minutes with Luke, our security lead. No charge.