Security leadership, without hiring a security team.
Omalu gives growing companies a security program strong enough to survive enterprise procurement and pass an audit — as a one-off engagement, as a monthly subscription, or as a service your own AI agents can call before they act. Led by a CISSP-certified advisor with over a decade in the field.
No sales team. You talk to the person who does the work.
Security debt catches up with you at the worst possible time
A big customer sends a security questionnaire, and there's no one who can answer it with confidence. The deal stalls, or it closes with a list of promises attached to a deadline.
A compliance requirement — SOC 2, ISO 27001, GDPR, NIS2, DORA — becomes contractual, and there's no one in the building who owns it. Engineering picks it up between sprints, or it gets outsourced to whoever answers the RFP fastest.
And now there's a new version of the same problem. Teams are shipping AI agents that touch customer data, take actions, and make decisions — faster than anyone can review them. When a customer or regulator asks who signed off on that, someone has to have an answer.
Hiring a full-time security leader is expensive and slow, and the role is often needed for twenty hours a month, not forty. Omalu covers the same ground three different ways, depending on what you actually need.
Three ways to work with Omalu
Same person, same standards. Pick the one that matches your situation.
Talk to a CISO
For a specific problem you need solved now.
A focused engagement with a security leader. Bring the stalled deal, the questionnaire you can't answer, or the audit deadline in your contract. You get a plain-language assessment, a prioritised plan, and someone who will get on the call with your customer if that's what unblocks it.
Starts with a free 30-minute call.
How advisory works →CISO as a Service
For companies where security has no owner.
Your security function on a monthly subscription. A named advisor, the policies and documents your customers ask for, and a chat channel that's always open. Ask a question at any hour: the AI assistant answers routine questions in minutes, and anything high-stakes is answered or reviewed by a human consultant.
Monthly subscription. Cancel any time.
What's included →Agent Security Reviews In private beta
For teams building their own AI products.
Your AI agents can ask Omalu for a security review before they act. Connect over MCP — the standard way AI assistants plug into outside tools — and your agent gets a clear verdict on a risky action, an architecture decision, or a compliance question, plus a written record you can show an auditor.
Subscription, priced by volume.
How it works for AI teams →Talk to a CISO
Sometimes you don't need an ongoing relationship. You need one experienced person to look at your situation and tell you the truth about it.
What we do most often
Security posture assessment
A plain-language review of where you actually stand: what's a real risk, what's a checkbox, and what's blocking deals. You get a prioritised list, not a 90-page report to file away.
Compliance readiness
Gap analysis, policies, and evidence collection for ISO 27001, SOC 2, GDPR, NIS2 and DORA — including the security requirements now appearing around AI systems. Built to fit around your team.
Customer security questionnaires
The 200-question spreadsheet that arrived with your biggest deal. We answer it, we tell you which answers are weak, and we fix the ones that would fail a follow-up.
Incident response planning
A plan written before you need it: who does what, who gets told, and in what order. So a bad day stays a bad day instead of becoming a bad quarter.
Most engagements start with a 30-minute call and a fixed-scope assessment. If it turns into something ongoing, it turns into option two.
Book a callCISO as a Service
A full-time security leader costs [TODO: figure, e.g. €180k+] a year and takes months to hire. Most companies at your stage need the role about a day a week. This is that day a week, plus a chat channel that never closes.
What you get
- A named security advisor who knows your company, not a ticket queue.
- Unlimited questions, answered fast. Submit anything through the chat: "can we use this vendor?", "the customer wants our data retention policy", "is this a breach?". The AI assistant answers routine questions in minutes, drawing on our own playbooks and your company's context.
- A human behind every answer that matters. Anything unusual, high-risk, or contractually binding is escalated to a human consultant. You can ask for a human on any question, at any time, and you'll always be told which one answered you.
- A policy and documentation pack your customers and auditors will accept — written for your company, not a downloaded template.
- Security questionnaires and vendor reviews handled, so your sales cycle doesn't stall.
- A monthly review call, and reporting your board or investors can read without translation.
- Compliance programme ownership: SOC 2, ISO 27001, GDPR, NIS2, DORA — we run it, you approve it.
How the AI part works In private beta
The assistant is trained on our security playbooks and your company's setup, so it answers the routine questions — the ones that make up most of the volume — immediately and consistently. It's told to escalate rather than guess. Every conversation is visible to your advisor, and anything that carries real risk gets a human answer before it reaches you. It's there to make the answers faster, not cheaper to fake.
Plans
Starter
For pre-audit teams that need the documents and someone to ask.
[TODO price] / month
Growth
For companies inside an active audit or enterprise sales cycle.
[TODO price] / month
Scale
For regulated or multi-entity companies with a real programme to run.
Custom
Not sure which tier? Book a call and we'll tell you the smallest one that solves your problem.
Security reviews your AI agents can call In private beta
If you're building a product with AI agents in it, those agents are making decisions all day: what data to touch, what action to take, what to build next. They're confident whether or not they're right, and nobody is reviewing them at the speed they run.
Omalu gives your agents somewhere to check. Before an agent takes a sensitive action or commits to a design, it asks us — and gets back a clear answer, a reason, and a timestamped record.
What's MCP?
Model Context Protocol is the standard way AI assistants and agents connect to outside tools. If your product already uses it, connecting Omalu takes an endpoint and a key. If it doesn't, we have a plain REST endpoint that does the same thing.
What your agent can ask
Before a risky action
"I'm about to grant this integration access to the customer database." → Approved, flagged, or blocked, with the reason.
On an architecture decision
"We're planning to store session recordings in this region and process them with this sub-processor." → Whether that creates a data protection problem, which rule applies, and what to change.
On a compliance question, mid-build
"Does this feature need a data protection impact assessment before launch?" → A yes or no you can act on, and the record that shows you asked.
What comes back
- A verdict: approve, flag for review, or don't do this.
- The reason, in language a non-engineer can read.
- The specific control, regulation or standard it maps to.
- A logged, timestamped record of the question and the answer, exportable for an auditor.
Why not just ask your own model
Your own model will answer confidently either way, and it's grading its own homework. What you're buying here is an independent second opinion, backed by a named, certified security professional who stands behind the methodology, and an evidence trail that doesn't come from the system under review. When a customer's security team asks how you control what your agents do, "we built our own prompt for it" is a harder answer than this one.
- Human escalation. Reviews that come back uncertain, or that cross a risk threshold you set, are routed to a human consultant and answered within [TODO: SLA]. You see which answers were automated and which were reviewed.
- Integration. MCP server endpoint plus an API key. Works with Claude, Claude Code, and any MCP-compatible agent framework. REST available if you're not on MCP. [TODO: confirm before publishing.]
- Pricing. [TODO — monthly subscription with an included review volume, then per-review after.]
Which one do I need?
| Question | Talk to a CISO | CISO as a Service | Agent Security Reviews |
|---|---|---|---|
| Best when | You have one urgent problem | Nobody owns security | You're shipping AI agents |
| You get | Assessment and plan | An ongoing security function | Reviews on demand, via API |
| Answers come from | A human | AI first, human where it counts | AI first, human where it counts |
| Speed | Days | Minutes to hours | Seconds |
| Commitment | Per project | Monthly, cancel any time | Monthly |
| Starts with | A free 30-minute call | A free 30-minute call | A free 30-minute call |
All three start the same way — a call, no pitch deck.
How it works
Discovery call
30 minutes. Where you are, what's driving it — a deal, a deadline, a board request — and which of the three actually fits. If none of them do, we'll say so.
Scope and setup
A fixed scope and price before any work starts. For subscriptions, that includes onboarding your context so the answers are about your company, not generic advice.
Ongoing
A prioritised plan with owners and dates, a channel that's open when you need it, and reporting you can hand to a customer, an auditor, or your board.
About
Omalu is led by Fedor Bulatovskii, Founder and Principal Security Consultant. He has spent over ten years in security, holds the CISSP certification, and works with growth-stage companies that need credible security leadership before they're ready to hire it full-time.
Omalu's AI services run on the same playbooks he uses in client work, and he reviews the answers that matter.
Questions
I'm not technical. Will I understand what you send me?
Yes. Everything is written for a founder, not an engineer. If a document is meant for your engineering team, we'll say so, and we'll give you the version you need too.
What's the difference between booking a call and the subscription?
The call is for one problem. The subscription is for when the problems keep coming and nobody in the company owns them.
Can you get us SOC 2 or ISO 27001 certified?
We get you ready and we run the programme. The certificate itself is issued by an accredited external auditor — anyone who tells you they can issue it themselves is selling you something else. We'll help you choose one.
Who actually answers my questions?
Routine questions get an immediate answer from the AI assistant, trained on our playbooks and your setup. Anything high-stakes goes to a human consultant. You can always ask for a human, and you'll always be told which one you got.
Is what I send private?
[TODO — answer honestly and specifically: where data is stored, who can see it, whether it's used for model training, retention period. Do not publish this answer until it's true.]
We already have a security tool, a pen test, or a compliance platform. Do we need this?
Those tell you what's wrong. This decides what to do about it and owns the outcome. Most clients keep their tools and add the leadership.
What is MCP and do I need it?
MCP is the standard connection between AI assistants and outside tools. You only need it if you're building an AI product of your own. If you're not, ignore that section.
We're building AI agents. Isn't this what guardrails are for?
Guardrails stop the obvious. This answers the judgement calls — the architecture, the compliance question, the action that's technically allowed but a bad idea — and leaves a record that you asked.
How fast can you start?
[TODO — real answer.]
How much does it cost?
[TODO — either publish the numbers or say: engagements start at X and subscriptions at Y.]
Let's talk
Tell me what's driving the need — a deal, an audit, a deadline, or an AI product you're about to ship — and we'll figure out which of the three fits. If none of them do, I'll tell you that too.