Security leadership, without hiring a security team.

Omalu gives growing companies a security program strong enough to survive enterprise procurement and pass an audit — as a one-off engagement, as a monthly subscription, or as a service your own AI agents can call before they act. Led by a CISSP-certified advisor with over a decade in the field.

No sales team. You talk to the person who does the work.

Security debt catches up with you at the worst possible time

A big customer sends a security questionnaire, and there's no one who can answer it with confidence. The deal stalls, or it closes with a list of promises attached to a deadline.

A compliance requirement — SOC 2, ISO 27001, GDPR, NIS2, DORA — becomes contractual, and there's no one in the building who owns it. Engineering picks it up between sprints, or it gets outsourced to whoever answers the RFP fastest.

And now there's a new version of the same problem. Teams are shipping AI agents that touch customer data, take actions, and make decisions — faster than anyone can review them. When a customer or regulator asks who signed off on that, someone has to have an answer.

Hiring a full-time security leader is expensive and slow, and the role is often needed for twenty hours a month, not forty. Omalu covers the same ground three different ways, depending on what you actually need.

Three ways to work with Omalu

Same person, same standards. Pick the one that matches your situation.

Talk to a CISO

For a specific problem you need solved now.

A focused engagement with a security leader. Bring the stalled deal, the questionnaire you can't answer, or the audit deadline in your contract. You get a plain-language assessment, a prioritised plan, and someone who will get on the call with your customer if that's what unblocks it.

Starts with a free 30-minute call.

How advisory works →

CISO as a Service

For companies where security has no owner.

Your security function on a monthly subscription. A named advisor, the policies and documents your customers ask for, and a chat channel that's always open. Ask a question at any hour: the AI assistant answers routine questions in minutes, and anything high-stakes is answered or reviewed by a human consultant.

Monthly subscription. Cancel any time.

What's included →

Agent Security Reviews In private beta

For teams building their own AI products.

Your AI agents can ask Omalu for a security review before they act. Connect over MCP — the standard way AI assistants plug into outside tools — and your agent gets a clear verdict on a risky action, an architecture decision, or a compliance question, plus a written record you can show an auditor.

Subscription, priced by volume.

How it works for AI teams →

Talk to a CISO

Sometimes you don't need an ongoing relationship. You need one experienced person to look at your situation and tell you the truth about it.

What we do most often

Security posture assessment

A plain-language review of where you actually stand: what's a real risk, what's a checkbox, and what's blocking deals. You get a prioritised list, not a 90-page report to file away.

Compliance readiness

Gap analysis, policies, and evidence collection for ISO 27001, SOC 2, GDPR, NIS2 and DORA — including the security requirements now appearing around AI systems. Built to fit around your team.

Customer security questionnaires

The 200-question spreadsheet that arrived with your biggest deal. We answer it, we tell you which answers are weak, and we fix the ones that would fail a follow-up.

Incident response planning

A plan written before you need it: who does what, who gets told, and in what order. So a bad day stays a bad day instead of becoming a bad quarter.

Most engagements start with a 30-minute call and a fixed-scope assessment. If it turns into something ongoing, it turns into option two.

Book a call

CISO as a Service

A full-time security leader costs [TODO: figure, e.g. €180k+] a year and takes months to hire. Most companies at your stage need the role about a day a week. This is that day a week, plus a chat channel that never closes.

What you get

  • A named security advisor who knows your company, not a ticket queue.
  • Unlimited questions, answered fast. Submit anything through the chat: "can we use this vendor?", "the customer wants our data retention policy", "is this a breach?". The AI assistant answers routine questions in minutes, drawing on our own playbooks and your company's context.
  • A human behind every answer that matters. Anything unusual, high-risk, or contractually binding is escalated to a human consultant. You can ask for a human on any question, at any time, and you'll always be told which one answered you.
  • A policy and documentation pack your customers and auditors will accept — written for your company, not a downloaded template.
  • Security questionnaires and vendor reviews handled, so your sales cycle doesn't stall.
  • A monthly review call, and reporting your board or investors can read without translation.
  • Compliance programme ownership: SOC 2, ISO 27001, GDPR, NIS2, DORA — we run it, you approve it.

How the AI part works In private beta

The assistant is trained on our security playbooks and your company's setup, so it answers the routine questions — the ones that make up most of the volume — immediately and consistently. It's told to escalate rather than guess. Every conversation is visible to your advisor, and anything that carries real risk gets a human answer before it reaches you. It's there to make the answers faster, not cheaper to fake.

Plans

Starter

For pre-audit teams that need the documents and someone to ask.

[TODO price] / month

Growth

For companies inside an active audit or enterprise sales cycle.

[TODO price] / month

Scale

For regulated or multi-entity companies with a real programme to run.

Custom

Book a call to get set up

Not sure which tier? Book a call and we'll tell you the smallest one that solves your problem.

Security reviews your AI agents can call In private beta

If you're building a product with AI agents in it, those agents are making decisions all day: what data to touch, what action to take, what to build next. They're confident whether or not they're right, and nobody is reviewing them at the speed they run.

Omalu gives your agents somewhere to check. Before an agent takes a sensitive action or commits to a design, it asks us — and gets back a clear answer, a reason, and a timestamped record.

What's MCP?

Model Context Protocol is the standard way AI assistants and agents connect to outside tools. If your product already uses it, connecting Omalu takes an endpoint and a key. If it doesn't, we have a plain REST endpoint that does the same thing.

What your agent can ask

Before a risky action

"I'm about to grant this integration access to the customer database." → Approved, flagged, or blocked, with the reason.

On an architecture decision

"We're planning to store session recordings in this region and process them with this sub-processor." → Whether that creates a data protection problem, which rule applies, and what to change.

On a compliance question, mid-build

"Does this feature need a data protection impact assessment before launch?" → A yes or no you can act on, and the record that shows you asked.

What comes back

  • A verdict: approve, flag for review, or don't do this.
  • The reason, in language a non-engineer can read.
  • The specific control, regulation or standard it maps to.
  • A logged, timestamped record of the question and the answer, exportable for an auditor.

Why not just ask your own model

Your own model will answer confidently either way, and it's grading its own homework. What you're buying here is an independent second opinion, backed by a named, certified security professional who stands behind the methodology, and an evidence trail that doesn't come from the system under review. When a customer's security team asks how you control what your agents do, "we built our own prompt for it" is a harder answer than this one.

  • Human escalation. Reviews that come back uncertain, or that cross a risk threshold you set, are routed to a human consultant and answered within [TODO: SLA]. You see which answers were automated and which were reviewed.
  • Integration. MCP server endpoint plus an API key. Works with Claude, Claude Code, and any MCP-compatible agent framework. REST available if you're not on MCP. [TODO: confirm before publishing.]
  • Pricing. [TODO — monthly subscription with an included review volume, then per-review after.]
Request access

Which one do I need?

Question Talk to a CISO CISO as a Service Agent Security Reviews
Best when You have one urgent problem Nobody owns security You're shipping AI agents
You get Assessment and plan An ongoing security function Reviews on demand, via API
Answers come from A human AI first, human where it counts AI first, human where it counts
Speed Days Minutes to hours Seconds
Commitment Per project Monthly, cancel any time Monthly
Starts with A free 30-minute call A free 30-minute call A free 30-minute call

All three start the same way — a call, no pitch deck.

How it works

1

Discovery call

30 minutes. Where you are, what's driving it — a deal, a deadline, a board request — and which of the three actually fits. If none of them do, we'll say so.

2

Scope and setup

A fixed scope and price before any work starts. For subscriptions, that includes onboarding your context so the answers are about your company, not generic advice.

3

Ongoing

A prioritised plan with owners and dates, a channel that's open when you need it, and reporting you can hand to a customer, an auditor, or your board.

About

Omalu is led by Fedor Bulatovskii, Founder and Principal Security Consultant. He has spent over ten years in security, holds the CISSP certification, and works with growth-stage companies that need credible security leadership before they're ready to hire it full-time.

Omalu's AI services run on the same playbooks he uses in client work, and he reviews the answers that matter.

Connect on LinkedIn →

Questions

I'm not technical. Will I understand what you send me?

Yes. Everything is written for a founder, not an engineer. If a document is meant for your engineering team, we'll say so, and we'll give you the version you need too.

What's the difference between booking a call and the subscription?

The call is for one problem. The subscription is for when the problems keep coming and nobody in the company owns them.

Can you get us SOC 2 or ISO 27001 certified?

We get you ready and we run the programme. The certificate itself is issued by an accredited external auditor — anyone who tells you they can issue it themselves is selling you something else. We'll help you choose one.

Who actually answers my questions?

Routine questions get an immediate answer from the AI assistant, trained on our playbooks and your setup. Anything high-stakes goes to a human consultant. You can always ask for a human, and you'll always be told which one you got.

Is what I send private?

[TODO — answer honestly and specifically: where data is stored, who can see it, whether it's used for model training, retention period. Do not publish this answer until it's true.]

We already have a security tool, a pen test, or a compliance platform. Do we need this?

Those tell you what's wrong. This decides what to do about it and owns the outcome. Most clients keep their tools and add the leadership.

What is MCP and do I need it?

MCP is the standard connection between AI assistants and outside tools. You only need it if you're building an AI product of your own. If you're not, ignore that section.

We're building AI agents. Isn't this what guardrails are for?

Guardrails stop the obvious. This answers the judgement calls — the architecture, the compliance question, the action that's technically allowed but a bad idea — and leaves a record that you asked.

How fast can you start?

[TODO — real answer.]

How much does it cost?

[TODO — either publish the numbers or say: engagements start at X and subscriptions at Y.]

Let's talk

Tell me what's driving the need — a deal, an audit, a deadline, or an AI product you're about to ship — and we'll figure out which of the three fits. If none of them do, I'll tell you that too.

LinkedIn →