Does Cobalt perform the independent SOC 2 or ISO 27001 audit?
No. Cobalt supports technical readiness, control design, evidence workflows, and remediation planning. Independent reports and certifications must be issued by qualified third-party assessors or certification bodies.
Can you work with Vanta or Drata?
Cobalt can advise on evidence-collection workflows and integrations involving these platforms when they are part of the client environment. Platform names do not imply a formal partnership or endorsement.
Do you support AWS, Azure, and Google Cloud?
Yes, the advisory scope can include identity, segmentation, configuration, and control design across these environments. The exact scope depends on architecture, access, and the systems included in the engagement.
Will an engagement guarantee compliance or prevent a breach?
No. Security and compliance outcomes depend on implementation, ongoing operations, third parties, evolving threats, and independent reviewer decisions. Cobalt provides professional recommendations, not guaranteed outcomes.
What should we send in an initial request?
Share the business objective, target framework or security concern, cloud environment, approximate timeline, and decision owners. Do not submit credentials, regulated records, vulnerability details, or other sensitive data through the public form.