Newsletter
Join the Community
Subscribe to our newsletter for the latest news and updates
Compliance & cybersecurity for seed-to-Series B startups, helping them achieve SOC2 and ISO 27001 certification fast.
www.secureleap.tech (powered by turbo0)
www.secureleap.tech (powered by turbo0)
Submit your own product to reach creators and founders looking for the next tool to try.

AI-powered study app that generates personalized spaced-repetition plans from uploaded materials to boost exam prep.

Get paid while your AI coding agent thinks — sponsored lines in the status bar.

Free Calorie Deficit Calculator by GetFIT App. Calculate your daily calorie target, macros, and estimated weight loss timeline in seconds based on your goals and activity level.

AI-powered platform for drafting scientific figures, diagrams, and graphical abstracts from text, sketches, references, or paper notes.

AI infographic generator that turns text, reports, and data-heavy content into polished HTML/CSS infographics with accurate, editable text and plain-language refinement.
SecureLeap is a cybersecurity and compliance consulting firm that helps seed-to-Series B startups achieve SOC 2, ISO 27001, and other certifications through a combination of expert-led guidance and automation tools.
SecureLeap delivers cybersecurity compliance consulting for startups, including compliance readiness, penetration testing, virtual CISO leadership, and audit facilitation. It takes a client's current security posture as input and produces certification readiness, policies, evidence packages, and audit support as output. Founded by Marçal Santos (CISM, CDPSE), former cybersecurity lead at Aircall, Citibank, and Talkdesk, the firm is based in Porto, Portugal, with US and EU presence.
Engagements follow four phases: (1) Gap analysis to map current state against the chosen framework, (2) Implementation of policies, controls, and evidence collection, (3) Audit preparation including auditor selection and evidence packaging, (4) Audit support and post-audit maintenance. SOC 2 Type 1 typically takes 8–12 weeks; ISO 27001 takes 4–6 months. Every engagement is led directly by founder Marçal Santos, with vetted senior specialists brought in for penetration tests and internal audits.
SecureLeap uses transparent modular pricing: SOC 2 consulting from $8,000–$12,000 for a full program, penetration testing from $4,000 per assessment, virtual CISO retainers from $2,000/month scaled to monthly hours. ISO 27001 and combined-framework programs are scoped per engagement. The first consultation is free. No bloated retainers or hidden fees.
Yes. Your first consultation is free and includes a compliance readiness review, framework recommendation, rough timeline, and a personalized roadmap. Most calls take 30 minutes. Book directly through the link, no sales rep in between.
SecureLeap is led by Marçal Santos, who holds the CISM (Certified Information Security Manager) and CDPSE (Certified Data Privacy Solutions Engineer) certifications from ISACA. Prior roles include cybersecurity lead at Aircall, Citibank, and Talkdesk. SecureLeap is also a partner of Drata, Vanta, and Secureframe, with implementation and reseller status.
Before your first enterprise sales conversation or institutional fundraising round. Compliance work takes weeks to months, but enterprise procurement teams ask for a SOC 2 report on the first call. Starting early turns compliance into a sales accelerator instead of a sales blocker.
Yes. SecureLeap is based in Porto, Portugal, with US and EU presence, and serves clients globally. They tailor compliance programs to your jurisdiction (US, EU, UK, APAC) and any industry-specific overlays such as HIPAA, GDPR, or DORA.
You work directly with Marçal Santos, the Founder and CISO, who scopes and delivers your program. For specific deliverables such as penetration tests or internal audits, he coordinates with a network of vetted senior specialists. No junior consultants and no account manager handoffs.