IT for Firms Whose Customers Audit Them

Some California companies are not the ones sending security questions, they are the ones answering them. Agencies, accounting and professional services firms, SaaS vendors, and contractors whose enterprise customers send a security questionnaire or a vendor audit before signing a contract need an IT provider that can back up what is on that form, not just keep the lights on. Ghosxt runs managed IT and cybersecurity built around that reality: SOC 2 documentation for every platform in our stack provided during onboarding, a written policy suite (a WISP, an incident response plan, a business continuity and disaster recovery plan, an access control and acceptable use policy, a retention and destruction policy, and an AI acceptable use policy), an annual independent risk assessment arranged through a third-party assessor, and a 4-hour notification commitment on any actual or reasonably suspected critical incident. Pricing is published upfront, and you talk directly to the owner, not a support queue.

Transparent managed IT pricing is published upfront, so you know the range before booking.

What we deliver for companies that get audited

A customer's security questionnaire or vendor audit is usually asking about the same handful of things: who has access, how it is monitored, how it is backed up, what happens during an incident, and what is written down. This is the actual paperwork and controls behind those questions.

SOC 2 documentation for every platform in our stack

SOC 2 documentation for every platform in our stack, provided as part of onboarding, the subprocessor-level evidence a customer's security team typically wants to see about the systems we manage for you.

Learn more

A written policy suite

A written policy suite: a WISP, an incident response plan, a business continuity and disaster recovery (BC/DR) plan, an access control and acceptable use policy, a retention and destruction policy, and an AI acceptable use policy, the documents a customer's audit or questionnaire is actually looking for.

Learn more

Annual independent risk assessment

An annual independent risk assessment, arranged through a third-party assessor rather than graded by us, so the review your customers see is not just our own opinion of our own work.

Learn more

4-hour critical incident notification

A 4-hour notification commitment on any actual or reasonably suspected critical incident, the response-time line a customer's contract or questionnaire is usually asking about.

Learn more

Vendor security questionnaire support

When a customer's security questionnaire lands in your inbox, we help answer the technical sections about the controls we run for you.

Learn more

Customer DPA flowdown support

If your customer's Data Processing Agreement flows security obligations down to your vendors, we support the technical side of that flowdown for the systems we manage.

Learn more

Cyber liability insurance in force

Cyber liability insurance in force, $1M per occurrence and aggregate, plus general and professional liability, the kind of coverage line a vendor questionnaire usually asks a provider to confirm.

Learn more

SAM.gov registered, DoD-cleared leadership

Ghosxt is registered in SAM.gov, and the owner holds an active DoD clearance and has prior DoD and federal contractor infrastructure experience. We do not publish the clearance level.

Learn more

What happens when a customer sends you a security questionnaire

The paperwork itself is usually the easy part once the underlying controls exist; the hard part is answering it accurately and fast enough that it does not stall the deal.

Forward us the questionnaire or the audit request when it lands. We work through the technical sections together, identity and access, patching and monitoring, backup and incident response, using the controls we already run for you and the SOC 2 documentation for the platforms in our stack.

If the questionnaire or the underlying contract asks for a Data Processing Agreement that flows security obligations down to us as your IT provider, we complete the vendor side of that paperwork. The legal review of your own DPA language stays with you and your counsel; we support the technical controls and documentation, we do not provide the legal review.

Some questions on a customer's questionnaire are about your business specifically, such as data classification, staff training records, or your own policy acknowledgments, rather than about the IT stack; those stay yours to answer, and the written policy suite and risk-assessment documentation we provide are meant to support those answers.

Pricing for companies that get audited

Pricing is published upfront on our pricing page: Tiny Team is a flat $600 per month for 1 to 4 users. Core Managed IT is $125 per user per month, Secure Growth is $175, and Compliance & Continuity is $250. Onboarding is a one-time fee: $1,000 flat for a Tiny Team (1 to 4 users) or $1,500 for 5 to 15 users on the Microsoft 365 default scope; Google Workspace and Apple fleet onboarding is scoped and quoted separately. SOC 2 documentation for every platform in our stack, the written policy suite, and the annual independent risk assessment are contracted deliverables of working with us, not a separate line item.

Who this is for

This page is written for a specific shape of California business.

  • Agencies whose enterprise clients require a vendor security review before signing
  • Accounting and professional services firms whose clients send a security questionnaire
  • SaaS and technology vendors whose enterprise customers require SOC 2 evidence or a security review
  • Contractors and subcontractors whose prime or enterprise customer audits its vendor list

Service area

We are based in Salinas and work with businesses across California's Central Coast and the Bay Area, including San Jose, Santa Cruz, Monterey, Carmel, and Pacific Grove. Companies whose customers are outside California are supported the same way; the vendor documentation and controls on this page do not change based on where your customer is located.

Free IT assessment before your next customer audit

30 minutes with an engineer with DoD infrastructure experience. Walk away with a clear picture of where your identity, device, backup, and documentation posture stand against what a customer's security questionnaire actually asks, plus a written punch list of what to fix first. No sales script, no obligation.

Book your free assessment

FAQs about IT for firms whose customers audit them

Do you provide SOC 2 documentation we can hand to our customers?
We provide SOC 2 documentation for every platform in our stack as part of onboarding, the subprocessor-level evidence a customer's security team typically wants to see about the systems we manage for you. That covers the platforms in our stack; it is not a SOC 2 report on your own company, which is a separate engagement outside what we do.
What happens when a customer sends us a security questionnaire?
Forward it to us when it arrives. We work through the technical sections together, identity and access, patching and monitoring, backup and incident response, using the controls we run for you and the SOC 2 documentation for the platforms in our stack. Questions about your own business specifically, such as staff training records or your own policy acknowledgments, stay yours to answer.
Can you support a Data Processing Agreement (DPA) our customer wants us to sign?
Often, yes, at a high level. If your customer's DPA flows security obligations down to your vendors, we support the technical side of that flowdown, identity controls, device management, and monitoring on the systems we manage for you. Review the specific DPA language with your customer and your own counsel; we support the technical controls, we do not provide the legal review.
Do you carry your own cyber liability insurance?
Yes. Ghosxt carries cyber liability insurance in force, $1M per occurrence and aggregate, plus general and professional liability, and we are registered in SAM.gov.
Do you have a security clearance? Are you SAM.gov registered?
Yes to SAM.gov. The owner holds an active DoD clearance and has prior DoD and federal contractor infrastructure experience. We do not publish the clearance level.
Who do we actually talk to if something breaks?
Ulises Paiz, the owner, directly. There is no tier-1 queue. Critical incidents carry a 4-hour notification commitment, and you have a direct line to the person running your environment.
Call (831) 204-0501 Book free assessment