AI Compliance Engineer · SOC 2 · ISO 27001 · ISO 42001
For startups on Vanta, Drata, TrustCloud, or Secureframe without a security team to spare. Every failing control becomes a ready-to-approve pull request or ticket — with auditor-ready before-and-after evidence.
Read-only access to your environment, working continuously between audits. Every change ships as a pull request or ticket that your team approves.
fix(s3): block public access on 3 customer-data buckets
Closes failing test: “S3 buckets prohibit public access”
The problem
Every red test in your dashboard becomes an engineering task nobody planned for — pulled from your roadmap, or billed by the hour by a consultant.
“MFA not enforced.” “Branch protection disabled.” “Access review overdue.” The dashboard turns red and stays red.
Compliance fixes compete with the product roadmap and lose. The alternative is paying consultants by the hour to chase your team with checklists.
The observation window closes whether the gaps are fixed or not. What’s left is a scramble — and evidence assembled at the last minute.
Your compliance platform flags the gap and stops there. Even its AI agent won’t open the Terraform PR in your AWS, the ticket in your Jira, or the fix in your GitHub. IOthreat does — and keeps doing it continuously between audits, so you stay ready instead of scrambling.
How it works
It runs continuously, not just at audit time — new findings become fix PRs as they appear, so your posture stays green between audits.
We read the failing tests from your compliance platform and connect to your stack — AWS, GitHub, GitLab, Jira, Linear — with read-only credentials.
Each gap is mapped across every framework you run. One fix often closes the same control in SOC 2, ISO 27001, and ISO 42001 at once.
The engineer opens pull requests and tickets with the exact change, the reason, and the control it closes. Nothing touches production until your team approves.
Before-and-after evidence is captured for every change and written back to your platform, mapped to the control — ready for your auditor.
What it fixes
Built from six years of preparing startups for SOC 2 and ISO audits — starting with the findings that appear on nearly every gap report.
Block public access on S3 buckets holding customer data, via a Terraform or console-config PR.
Enforce reviews, status checks, and force-push protection on production repositories.
Require MFA across your identity provider, cloud console, and code hosting — and prove it.
Find accounts that should have been closed, open the removal tickets, and document the review.
Rotate long-lived IAM keys, switch on CloudTrail and retention, and encrypt what isn’t encrypted.
Draft the missing policies from your real configuration — including ISO 42001 AI-management controls.
Control references are representative examples (SOC 2 Trust Services Criteria and ISO 27001:2022 Annex A). Every remediation is mapped to your actual framework scope during onboarding.
Integrations
Reads findings from
Opens PRs & tickets in — via MCP or API
Cloud & infrastructure
Code & CI
Work tracking
Identity & access
Security & operations
IOthreat is an independent solution and is not affiliated with or endorsed by the platforms listed. All product names are trademarks of their respective owners.
Guardrails
Automation you can put in front of an auditor — because every action is real, reviewed, and documented.
We never hold write access to your production environment. Changes are proposed, not pushed.
Your team reviews and merges each PR and ticket. The approval itself becomes part of the evidence trail.
If a control isn’t actually implemented, it stays red. We fix the control — we don’t decorate the dashboard.
Every change is logged with its before state, after state, approver, and the exact control it closes.
A 30-minute walkthrough: we look at your current findings together and show you which we’d close first.

Uri Fleyder-Kotler
Founder & CISO, IOthreat
Who’s behind it
IOthreat isn’t a demo built by outsiders to security. It’s the work of a practitioner with 16+ years across both sides of cybersecurity — from adversarial research at RSA to leading security as a CISO — now taking startups through SOC 2, ISO 27001, and ISO 42001. The product does the engineering; an experienced CISO stands behind the judgment.
More about Uri →FAQ
Those agents work inside their own platform — drafting policies, answering questionnaires, flagging failing controls. They won’t open the Terraform PR in your AWS, the ticket in your Jira, or the fix in your GitHub. IOthreat does that remediation work across your stack, and keeps doing it continuously.
Read-only, on the basis you configure. We never hold write access to production. Every change is proposed as a pull request or ticket that your team reviews and approves before anything is applied.
Yes — that’s the point. Every change is logged with its before state, after state, approver, and the exact control it closes, and written back to your compliance platform. Nothing is fabricated: if a control isn’t actually implemented, it stays red until it’s fixed.
We start from your live gap report and open the first fix PRs within days. A full gap backlog is typically 40–100 hours of remediation work per audit — handled for you.
A consultant chases your team with a checklist and bills by the hour. IOthreat does the engineering itself, continuously, for a flat subscription — with a CISO standing behind the judgment. It replaces the consulting and DevOps time, not adds to it.
SOC 2, ISO 27001, and ISO 42001 today, read from Vanta, Drata, TrustCloud, Secureframe and more. We act across AWS, GitHub, GitLab, Jira, Linear, and the rest of a typical startup stack via API or MCP.
Founding customer program
We’re onboarding just a handful of founding customers this quarter, ahead of general availability. You get founding pricing locked in for good, direct access to the founder — a CISO who’s taken startups through these audits — and a say in what we build next.
Typical estimates that scale with your environment — a full gap backlog is 40–100 hours of remediation work per audit, plus the recurring evidence that comes due between them, handled for you. Your free scan reports the exact figures for your own environment before you commit to anything.