AI Assist runs inside Claude
U.S.-based resourcing
Force onshore delivery for a domain. When on, the delivery model for those services is set to Onshore and locked.
Engagement details
Scoping questions
These answers position each managed service inside its catalog price range.
Start from a package (optional)
Managed services
- No servers to provision, patch, or scale: managed indexer, server & dashboard.
- Elastic storage & compute that grow with log volume and retention.
- Automatic platform updates, security patching, and managed backups.
- High-availability architecture and 24/7 platform health monitoring.
- Onboarding in days, not weeks: and lower total cost of ownership.
- Managed ITSM (per ticket): full IT service desk: onboarding/offboarding, access requests, incident routing, user support, device troubleshooting and service-catalog operations. Priced per ticket, tiered by monthly volume.
- Security ITSM: security-operations ticketing & workflow: incident tracking, vulnerability-remediation tickets and alert escalation, integrated with the SOC/SIEM and vuln-management processes.
- Support tiers: T1: first-contact triage, password/access, routine requests, known-error workarounds. T2: deeper troubleshooting, escalations, change execution, incident resolution.
- Priority SLAs: P1 (critical / outage): respond ≤30 min, restore target ≤4 hrs. P2 (high): respond ≤2 hrs, ≤1 business day. P3 (normal): respond ≤1 business day, ≤3 business days.
EDR & MDM management
Configure, deploy and/or monitor commercial EDR and MDM platforms: together or individually.
Identity, Network & Access Management
Managed identity and network access operations - user lifecycle, CRL/certificate management, NAC policy, MFA enforcement, and access reviews. Ticketed requests stay under ITSM; this covers the tooling management and operational delivery.
Offensive Security
Add the assets the client wants tested. Priced on testing effort at your labor rates, so it stays margin-consistent with the rest of the catalog.
Infrastructure as Code (project)
Cloud security consulting (project)
WAF management & tuning
Federal & Regulatory Compliance Engineering
Engineering work toward government and regulatory authorizations: boundary design, control implementation, STIG validation, CJIS, HIPAA, IRS 1075, ITAR/EAR, and cloud authorization programs.
CUI / FCI Data Protection Engineering
NIST 800-171 Rev 3 technical control implementation for federal contractors handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). These obligations exist under FAR 52.204-21 and DFARS 252.204-7012 independent of CMMC program status.
CMMC L2 enclave build (project)
Contract term
Non-binding rough estimate for discussion. Managed-service prices reflect the Workstreet catalog (65% margin); PenTest & IaC are labor-based at margin-loaded rates. Final pricing requires a scoping review.