Book call

Your enterprise deal is sitting in security review.

I answer the questionnaires that hold it there — SIG Lite, CAIQ, or whatever spreadsheet the buyer's risk team invented. Every answer cited to a document you already have. Every gap returned as a question, not a guess.

Book 20 minutes
Working with UK and EU software companies whose infrastructure doesn't fit the standard questions.Turnaround in 3 working daysHuman reviewed
WHO REVIEWS YOUR ANSWERS:
Rowan SterlingLead Practitioner & CISO Advisor
One practitioner with good tooling — not an analyst floor.
S
SIG Lite 2025 — returned
Backlog
3
SIG-LITEHigh

Tier-1 Global Bank 126-row Inbound

Custom risk spreadsheet sent by enterprise buyer. Ingested under mutual NDA.

Rowan Sterling reviewing evidence3d turn
CAIQ-v4Normal

Series B Buyer Cloud Assessment

Queued in vault48h SLA
Needs You
2
Q48 • GAPFounder Decision

Draft tenant isolation on multi-tenant GPU cluster

"Questionnaire asks about hypervisor boundaries. Our architecture uses Kubernetes pod isolation + Nvidia MIG."

Click to inspect discrepancy
Q84 • WATCHAging doc

Confirm backup retention window for deleted embeddings

Policy says 30 days; vector DB configuration shows 14 days snapshot cycle.

Waiting for founder10 min call
In Flight
4
CROSS-CHECKRowan Sterling

Quarterly enterprise vendor review

81% cited to SOC 292/114
EVIDENCEEvidence check

Bishop Fox Pen Test reconciliation

Verified 19 findingsPass
Done & Signed
6
SIG COMPLETEApproved

Global Fintech Tier-1 Security Schedule

Returned with full cell comments. 100% cited. Deal closed.

Zero ungrounded claimsReady
DIAGNOSTICReport

Blind Holdout Comparison Report

Delivered to CTO£500
7:04 AM:Your evidence store is synced. 42 cited answers verified. No ungrounded claims.
THE PROBLEM

The forty questions, again.

Your customer asks whether production data is encrypted. You answered that last month. The answer is in a policy, but the policy is fourteen pages long and nobody remembers which paragraph.

Then the questions get specific: whether your subprocessor list matches your data-flow diagram, whether a pen-test finding is closed, whether the scope of your SOC 2 actually covers the product they are buying.

The spreadsheet is not hard because the questions are new. It is hard because every answer is a representation your company has to stand behind.

THE OFFER

Start with a diagnostic, not a contract.

Send me one questionnaire you have already completed. I answer it blind from your documents, then compare my work with the answer your team approved.

  • What your evidence supports cleanly
  • Where the source is stale, ambiguous, or missing
  • Where my draft disagreed with your approved answer
£500
returned in 3 working days
BRING YOUR OWN EVIDENCE

Use any security documents you have, and as many as you have

#1

Connect the evidence you already own

SOC 2 Type II reports, ISO 27001 policies, pen test summaries, AWS architecture diagrams, and previous questionnaires. They stay under NDA, in your dedicated client vault.

#2

Stack evidence for complex architectures

When buyers ask about multi-tenant GPU isolation or vector encryption, cite your AWS spec, Kubernetes network policies, and pen test remediation in one cohesive response.

#3

Fallbacks so deals never stop on guesses

If an answer isn't supported by existing evidence, it is returned as a targeted question, not an automated guess. You get the exact document title that would solve it.

#4

A human principal deciding what's true

Rowan Sterling brings 11 years of infrastructure security experience. Tooling indexes and drafts; a human decides what represents your company.

YOUR EVIDENCE VAULT • 4 ACTIVE SOURCES

Zero retention on external models • Isolated client namespace

ACTIVE
S2
SOC 2 Type II Audit Report (2025)142 pages • Audited by Schellman • Valid to Dec 2026
68 citations
K8
AWS Multi-Tenant GPU Cluster Spec v3Architecture blueprint • Cilium CNI • Tenancy isolation
34 citations
PT
Bishop Fox Pen Test Summary (Nov 2025)External API & tenant breakout test • Zero critical findings
19 citations
Configured model: Claude 3.5 Sonnet (Zero Data Retention)
WORKS WITH ALL OF YOUR EVIDENCE

I work from the evidence you already have

Policies, architecture documents, audit reports, pen tests, previous answers, and operational records become a cited evidence store for the next questionnaire.

AWS Architecture
SOC 2 Type II PDF
Kubernetes CNI Policy
Pen Test Findings
CITING EVIDENCE • QUESTION 48
9:32 AM

@Rowan Sterling matched AWS Multi-Tenant GPU Isolation in Notion & AWS Spec. Cited hypervisor-free pod boundaries using Cilium eBPF network rules.

Confidence: 100% (Direct Match)Zero training retention
SIG Lite XLS
Terraform IAM Specs
CAIQ v4 Spreadsheet
AWSGCPKubernetesCiliumGitHubNotionGoogle DriveJiraSlackOktaCloudflareExcel / CSV+ 70 formats with per-client air-gapped isolation

Need fully air-gapped or local model execution?

Run via local Ollama/Mistral endpoint or zero-data-retention VPC proxy. Your policies never leave your hardware boundary.

Review trust architecture →
WHAT COMES BACK

Your spreadsheet, ready for your review

Green, amber, and red make the remaining work obvious. Every source stays attached to the answer it supports.

TIER1_BANK_SIG_LITE.XLSX • ROW 48
GREEN • CITEDRowan Sterling
BUYER QUESTION #48

"Describe tenant isolation mechanisms. Are customer workloads logically separated and how is cross-tenant memory access prevented?"

DRAFTED & VERIFIED ANSWER (READY FOR SIGNATURE)Citation in cell comment

"Customer training and inference workloads run in mutually isolated Kubernetes namespaces with Cilium eBPF network segmentation (zero egress between tenants). GPU compute is sliced using hardware-enforced Nvidia MIG partitions with independent memory controllers, preventing any cross-tenant memory bleeding."

Cell Comment • Verification Audit Trail

Source: AWS-ARCH-2025-V2.pdf §4.2 (Last reviewed 18 Jan 2026). Cross-referenced against Schellman SOC 2 §CC6.1 and Bishop Fox Pen Test §3.1. Verified by Rowan Sterling.

Inspect the returned spreadsheet
THE EVIDENCE

The number nobody publishes

Every tool in this category advertises how much it automates. None of them tell you how often they're confidently wrong. Across 16 questionnaires, run blind against answers the client had already approved:

80%

DRAFTED WITH A CITATION

Questions genuinely supported by the evidence set, with exact document paragraphs and review dates.

15%

RETURNED AS QUESTIONS

"An unverified claim isn't invented. It comes back as a targeted question with the exact policy needed to resolve it."

4%

DRAFTED AND WRONG

The number that matters. I report it so you know how much review your team still owes each answer.

3 working days

QUESTIONNAIRES TESTED

An answer with no supporting document comes back as a question, never a plausible sentence with nothing behind it.

FIT AND BOUNDARIES

One person with good tooling, not an analyst floor

That is a limit on volume and an advantage on judgement.

WHO THIS IS FOR

Software companies selling into serious buyers

UK and EU B2B software companies, roughly seed to Series B, selling into enterprise or regulated buyers — especially where the infrastructure does not fit a standard answer.

ML training, simulation, HPC, GPU tenancy, research compute, and complex multi-tenant SaaS.

WHO THIS ISN'T FOR

Not a self-serve answer machine

  • You need hundreds of questionnaires completed each quarter.
  • You need a self-serve platform with seats and SSO.
  • You want every box filled regardless of what the evidence says.
  • Your policy requires a SOC 2-certified supplier for this processing.
WHO YOU'RE ACTUALLY HIRING

Rowan Sterling

11 years in infrastructure security, including ML infrastructure, multi-tenant GPU clouds, and enterprise B2B SaaS architectures. I have written answers under deal pressure and reviewed answers written by people who had never touched the system.

The tooling drafts and cites. I decide what is actually true about your estate.

Book a call
HOW IT WORKS

Five steps, and the fourth one gets cheaper

I do the review. You make the representation to your customer.

STEP 1
NDA FIRST01

You send

Policies, audit reports, pen test summaries, architecture docs, and your last few completed questionnaires. NDA first, over a channel I name — not an upload form.

STEP 2
BUILT ONCE02

I build your evidence store

Every claim is indexed to its source document and that document’s review date. This happens once. It is what makes the fourth questionnaire faster than the first.

STEP 3
ANY FORMAT03

You forward the questionnaire

In whatever shape it arrived — SIG Lite, CAIQ, a bespoke spreadsheet, or a buyer portal export.

STEP 4
SAME FILE BACK04

You get your spreadsheet back

Same tabs, same columns, same formatting. Green where the answer is cited and current, amber where the source is aging, red where I need something from you. Sources sit in the cell comment.

STEP 5
HUMAN SIGN-OFF05

You review and sign

Your approved answers become evidence for the next one, and the next questionnaire costs less.

TRANSPARENT ENGAGEMENT

Simple, transparent pricing

Most clients start per-questionnaire and move to retainer once they have seen what the second one costs compared with the first.

START HERE — NOT WITH A CONTRACT

Blind Holdout Diagnostic

One completed questionnaire and one report showing what your evidence genuinely supports, what it does not, and where my draft disagreed with your team.

£500
fixed price + VAT
Turnaround: 3 working days
Cell comments: Verbatim citations and audit dates
Mutual NDA: Executed prior to any document review
Gaps as questions: No guesses or hallucinated policies
Direct access: Review with Rowan Sterling
Blind holdout report: Discrepancy % vs past answers
Full refund if not satisfied with diagnostic clarity
Book 20 minutes
REASONABLE QUESTIONS

Questions, answered

Straight answers about the person, the tooling, and where responsibility sits.

Yes, as disclosed tooling for indexing, retrieval, and first drafts. It does not decide what is true. I review every answer against its source before it reaches you, and unsupported claims come back as questions.

Send me one questionnaire you've already done

I'll tell you what your current evidence supports, where it falls short, and whether I can help. NDA first if you need it.

Book a call

No sales team • You speak directly with the person doing the work

TrustPalSecurity

Human-led security questionnaire response for ML infrastructure, multi-tenant GPU clouds, and enterprise B2B SaaS architectures companies.

Lead Practitioner: Rowan Sterling (11y exp)

PRODUCT & SERVICES

TRUST & COMPLIANCE

COMPANY & CONTACT

Company No. 14892011
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
© 2026 TrustPal. All rights reserved.
Zero-external-request design