Eedee Naku

Built fast.
Now make it enterprise-ready.

Security and compliance help for modern SaaS, including AI-generated code. When a big prospect sends you a security questionnaire, I get you from “we should look into that” to audit-ready. And since I’m an engineer, you won’t be left alone with a checklist. If you want the findings fixed, I can fix them.

Book a discovery call
How I can help
Security & Compliance Audit
€750 – €1,500 fixed
48-hour turnaround

For codebases that shipped fast, AI-generated or not. I find the exposed secrets, missing auth, and broken access control before someone else does.

  • Full review of your code and cloud setup
  • A plain-English report, mapped to SOC 2 and OWASP
  • A fix list any engineer can pick up, sorted by priority
  • Want the fixes done too? We scope that from the report
SOC 2 / ISO 27001 Readiness Sprint
€3,500 – €5,000 fixed
3 to 4 weeks

A focused push to get you audit-ready. By the end you know exactly where you stand, and your evidence is already collecting.

  • Gap assessment against your framework
  • A remediation plan, sorted by priority
  • Your compliance platform set up (Vanta, Secureframe, or your pick)
  • Evidence collection up and running before I leave
Compliance Retainer
€1,500 – €2,500 / month
Ongoing

Compliance doesn't stop after the audit. I keep your controls running and your next audit boring.

  • Monitoring and triage of failing checks
  • Evidence upkeep, access reviews, vendor reviews
  • Auditor and questionnaire support
  • A set block of engineering hours each month for fixes

Where you land in a range depends on how big your codebase is and how many systems we're looking at. You'll know the exact price before we start.

Need something that's not on this list? A quick security question, a review before a big release, help with a customer questionnaire. Reach out anyway, and we'll figure out if I can help.

Send me a message
Why an engineer

I spent three years building SOC 2, ISO 27001, and GDPR controls inside engineering teams. The cloud config, the access management, the logging auditors actually check. Compliance platforms tell you what's failing. I make it pass.

How I work
Fixed scope, fixed price
You know the deliverables and the cost before we start. No hourly meters, no scope creep.
Async by default
No standing meetings. You get written findings, pull requests, and clear next steps.
Results, not hours
Every engagement ends with something you can hold: a report, merged fixes, a check that passes.
Ready when you are

A 30-minute call is usually enough to tell whether you need an audit, a sprint, or neither. I only take a few engagements per quarter.

Book a discovery call
Let's Connect!
Have a question or an idea? Let’s chat
© 2026 Eedee NakuPrivacy