SOC 2 · ISO 27001 · HIPAA · CMMC · NIST CSF 2.0
Nova Lim answers the questionnaire, sits on the buyer security call, and builds the evidence trail behind it. Fixed scope, published pricing, one senior advisor from intake to sign-off. No platform to buy and no vendor kickbacks, ever.
What we do
Security work only matters if it does something for the business. Every service below sits under the outcome it buys you — winning the deal, staying ready, or proving the thing actually holds.
PILLAR 01
Win the deal
Enterprise buyers now treat every vendor as a breach path. The security review is a revenue gate, and it is usually the founder or the CTO absorbing it at the worst possible moment.
Questionnaires, DDQs and buyer security calls, handled. We run intake, build an approved-claims library so nobody overstates anything in writing, track every exception you commit to, and represent you live on the call.
SOC 2 or HIPAA from nothing to audit-ready. Gap assessment, a policy set written for how you actually operate, remediation, and an indexed evidence package your auditor accepts.
Satisfy a mandatory pentest requirement without paying a markup on it. We scope the rules of engagement, select an independent certified tester, manage the engineering fixes, and assemble the auditor package.
PILLAR 02
Operate assurance
Compliance decays the day the audit ends. Access reviews slip, policies go stale, and twelve months later it is a fire drill again. This is the work that makes the next audit boring.
Control calendar, monthly evidence checks, access reviews, policy maintenance and auditor liaison. Your next SOC 2 or ISO 27001 cycle requires no panic and no scramble.
A vCISO who owns the roadmap, the board deck and the governance, at a fraction of an executive hire. Steering meetings, budget planning, and someone accountable when the board asks.
A vulnerability disclosure program that auditors accept and researchers actually use. Policy with safe-harbour language, security.txt, intake channel, triage of inbound reports, and remediation tracking. Graduates to a funded bounty when you are ready.
PILLAR 03
Validate security
Policies that have never been tested are not controls, they are documents. This pillar is where we find out whether the thing survives contact with reality.
Turn a static incident policy into a rehearsed decision system. Authority matrix, scenario runbooks, contact trees, and a facilitated two-to-four hour executive tabletop with an after-action plan.
A read-only audit of AWS, GCP or Azure. Identity and data-flow review, logging coverage, threat model, and a prioritised remediation backlog your engineers can actually work from.
Ship Copilots, LLMs and AI features without failing the next enterprise review. Model and tool inventory, data-flow review, acceptable-use policy, and a verified answer library for AI questionnaires.
The deal desk clock
Every engagement produces a dated record of what was answered, what was promised, and who owns it. You always know where you stand — and so does your buyer's security team.
Cloud architecture assurance
A coverage map from a real assessment. Every filled cell is a control with evidence behind it. Every empty one is a question an auditor or an enterprise buyer is going to ask.
Pricing
You should know whether this is worth a call before you get on one. Ranges reflect scope and complexity; your number is fixed in writing before any work starts.
Pass-through costs are never marked up. Penetration testers, bug bounty platforms and researcher payouts are contracted and billed directly to you at their own rates. Nova Lim accepts no referral fee, commission or reseller margin from any vendor, tester or platform.
The approach
Large firms sell you a partner and staff the work with people two years out of school. That model exists because it scales. It is also why security programs drift, why nobody can answer the auditor's follow-up, and why the invoice keeps arriving.
Nova Lim is deliberately small. The person who scopes your program answers the questionnaire, sits on the buyer call, and picks up the phone. If that stops being true, the price stops being fair.
Founder, Nova Lim LLC
Before you ask
A managed bug bounty runs thirty thousand to half a million a year once platform fees, triage and payouts are counted. That is why we start you on a disclosure program instead — the policy, the intake channel and the triage discipline. It satisfies the auditor, it costs a fraction, and it proves your remediation workflow works before you ever fund a bounty pool.
Good. They run your systems, which is a different job from proving to an auditor or an enterprise buyer that the controls exist and work. We stay in our lane and work alongside them.
A platform collects evidence. It does not decide what your controls should be, write answers that hold up under scrutiny, or defend them on a live buyer call. Bring your platform — we will use it.
Because we do not get paid for the pick. Testers, platforms and tools contract with you directly at their own rates, and we take no referral fee or margin on any of it. Our only incentive is that the finding gets fixed.
Thirty minutes. Tell us which deal is blocked and which framework you are being asked for. You will get a fixed-price proposal within 24 hours, or a straight answer that you do not need us yet.