Starting well
Startups
Founders establishing business-controlled email, accounts, devices, sharing, backups, and employee procedures.
For one small business
Get a clear view of what matters most without committing to a long assessment or burying the owner in a compliance report. The result is a short list of priorities the business can actually sequence and operate.
When this is useful
It works for regulated and unregulated businesses alike. Customer expectations, insurance questions, growth, contracts, or a general sense that security has become too ad hoc can all be valid reasons to establish a baseline.
Starting well
Founders establishing business-controlled email, accounts, devices, sharing, backups, and employee procedures.
Finding the baseline
Owners who know security matters but do not know which weaknesses are most important or how to sequence improvements.
Supporting growth
Businesses adding staff, vendors, cloud services, customer expectations, or more complicated access and data-sharing workflows.
Preparing for pressure
Businesses facing questionnaires, insurance questions, supplier onboarding, contract expectations, or a new need to explain current practices.
Three tracks, one practical system
The assessment and reporting backbone stays consistent. The questions and recommendations change with the business stage and the reason security work matters now.
Existing small businesses that need a practical starting point.
Find the weaknesses that matter most and turn them into a manageable 90-day sequence.
New businesses establishing their first real technology environment.
Build minimum viable security early, while accounts, devices, sharing, and operating habits are still taking shape.
Suppliers and contractors facing customer, insurer, public-sector, or prime-contractor questions.
Understand the requirement, avoid unsupported claims, and organize the next practical readiness steps.
What the business receives
The point is not to create a large technical report. The point is to help an owner see what matters, what can wait, who should own the next action, and what outside support may be useful.
Short owner-friendly intake
60 to 75-minute guided assessment
Category-based red, yellow, and green scorecard
Five prioritized recommendations
30-day, 60-day, and 90-day action plan
30-minute confidential results discussion
What to expect
01
Share basic business context, choose a track, and confirm the limited scope.
02
Trawvid Sec checks program fit, sponsor criteria, capacity, and any routing concerns.
03
Gather high-level provider details and ordinary business records without sending secrets.
04
Work through a guided 60 to 75-minute review grounded in how the business actually operates.
05
Get the scorecard, five priorities, and a sequenced 90-day action plan.
06
Use a private 30-minute conversation to clarify ownership, effort, and the next decision.
Confidentiality by design
Trawvid Sec keeps participant advisory records separate from sponsor program reporting. A participant controls its individual report and action plan.
Direct engagement
$950 to $1,250
The final price depends on business size, complexity, and the track selected. The standard scope is interview-based and does not require system access, scanning, file uploads, or custody of sensitive evidence.
Discuss fit and scopeIncluded
A 60 to 75-minute discussion focused on the selected track and the way the business actually operates.
Included
A category scorecard, five practical priorities, and a 30-day, 60-day, and 90-day action sequence.
Included
A 30-minute discussion to answer questions, clarify ownership, and decide what should happen next.
Scoped separately
Hands-on changes, deeper evidence review, technical testing, expanded documentation, and ongoing advisory are separate engagements.
Program questions
Ordinarily, no. Individual interview notes, scorecards, findings, evidence, recommendations, and action plans stay between Trawvid Sec and the participating business. Sponsors receive approved aggregate, non-identifying program outcomes unless a participant separately authorizes a specific disclosure.
No. The program is an interview-based health check with limited review of appropriate, non-sensitive evidence examples. It does not include exploitation, scanning, social engineering, forensic acquisition, continuous monitoring, or formal audit work.
No. It provides practical readiness guidance and next steps. It is not a certification, formal CMMC assessment, audit opinion, legal conclusion, insurance determination, contract-award guarantee, or promise that an incident cannot occur.
The program can support startups, existing small businesses, manufacturers, suppliers, professional services firms, and businesses facing customer, contract, insurance, or public-sector expectations. A sponsor can set additional service-area or membership eligibility.
Basic business and technology context, major providers, the IT support model, current business pressure, and ordinary records that help explain current practices. The intake does not accept passwords, multi-factor authentication codes, recovery codes, restricted data samples, detailed network diagrams, contracts, insurance records, or file uploads.
Yes. Follow-on advisory or implementation support can be scoped separately when the participant wants it. A sponsor is not told whether a participant buys additional work unless the participant separately authorizes that disclosure.
Supporting more than one business?
Explore endorsed resources, co-branded programs, and sponsored cohorts without sorting through the individual-business engagement.
Choose your next step
If a Cyber Health Check is not the right fit, the introductory call should make that clear before you commit to anything.