SecureLeap is a cybersecurity and compliance consulting firm that helps seed-to-Series B startups achieve SOC 2, ISO 27001, and other certifications through a combination of expert-led guidance and automation tools.
What is SecureLeap?
SecureLeap delivers cybersecurity compliance consulting for startups, including compliance readiness, penetration testing, virtual CISO leadership, and audit facilitation. It takes a client's current security posture as input and produces certification readiness, policies, evidence packages, and audit support as output. Founded by Marçal Santos (CISM, CDPSE), former cybersecurity lead at Aircall, Citibank, and Talkdesk, the firm is based in Porto, Portugal, with US and EU presence.
Key Features
- Compliance Consulting — Gap analysis, policy documentation, evidence collection, and audit preparation for SOC 2, ISO 27001, HIPAA, GDPR, and DORA. Every engagement led personally by a CISM-certified senior consultant.
- Compliance Tool Support — Implementation and reselling of Vanta, Drata, and Secureframe with a 20% partner discount, plus continuous cloud monitoring and live trust center setup.
- Penetration Testing — Web, mobile, API, and cloud pen testing with a comprehensive vulnerability report, remediation guidance, and re-test after fixes. Starts at $4,000 per assessment.
- Audit Facilitation — Introductions to pre-vetted audit partners (e.g., A-LIGN), evidence package preparation, auditor Q&A support, and ISO 27001 internal audits.
- Virtual CISO — On-demand security strategy, risk management frameworks, and board-level communication for startups lacking full-time security leadership. Retainers from $2,000/month.
- Free Initial Consultation — 30-minute call including a compliance readiness review, framework recommendation, rough timeline, and personalized roadmap, no obligation.
Who is it for?
- Startup founders needing to close enterprise deals that require SOC 2 or ISO 27001 certification. They use SecureLeap’s consulting to achieve audit readiness in 8–12 weeks.
- Technical founders who prefer to DIY compliance with automation but want expert backing. They leverage SecureLeap’s compliance tool support for Vanta/Drata implementation with a partner discount.
- Growing companies without internal security leadership (e.g., SaaS, fintech, healthtech). They hire SecureLeap’s virtual CISO to define security strategy, communicate risk to investors, and represent security in prospect calls.
What can you do with SecureLeap?
- SaaS startups: Achieve SOC 2 Type 1 in 8–12 weeks using SecureLeap’s consulting and partner auditors, then use the certification to accelerate enterprise sales.
- Fintech or healthtech companies: Tailor compliance programs with industry-specific overlays like HIPAA or GDPR, ensuring regulatory compliance for customer data.
- B2B companies: Use SecureLeap’s virtual CISO to stand in on security calls with enterprise prospects, shifting the dynamic from scrutiny to trust.
How does SecureLeap work?
Engagements follow four phases: (1) Gap analysis to map current state against the chosen framework, (2) Implementation of policies, controls, and evidence collection, (3) Audit preparation including auditor selection and evidence packaging, (4) Audit support and post-audit maintenance. SOC 2 Type 1 typically takes 8–12 weeks; ISO 27001 takes 4–6 months. Every engagement is led directly by founder Marçal Santos, with vetted senior specialists brought in for penetration tests and internal audits.
Pricing
SecureLeap uses transparent modular pricing: SOC 2 consulting from $8,000–$12,000 for a full program, penetration testing from $4,000 per assessment, virtual CISO retainers from $2,000/month scaled to monthly hours. ISO 27001 and combined-framework programs are scoped per engagement. The first consultation is free. No bloated retainers or hidden fees.
Pros and cons
- Pros: 100% audit pass rate across every certification taken to completion; founder-led delivery (no junior consultants or account manager handoffs); wide partner network including Drata, Vanta, Secureframe, and A-LIGN; serves international clients.
- Cons: Scope is limited to seed-to-Series B startups — larger enterprises may find the model insufficient; pricing, while modular, may still be a stretch for very early pre-seed companies.
FAQ
Do you offer a free consultation?
Yes. Your first consultation is free and includes a compliance readiness review, framework recommendation, rough timeline, and a personalized roadmap. Most calls take 30 minutes. Book directly through the link, no sales rep in between.
What credentials does SecureLeap hold?
SecureLeap is led by Marçal Santos, who holds the CISM (Certified Information Security Manager) and CDPSE (Certified Data Privacy Solutions Engineer) certifications from ISACA. Prior roles include cybersecurity lead at Aircall, Citibank, and Talkdesk. SecureLeap is also a partner of Drata, Vanta, and Secureframe, with implementation and reseller status.
How soon should a startup start compliance?
Before your first enterprise sales conversation or institutional fundraising round. Compliance work takes weeks to months, but enterprise procurement teams ask for a SOC 2 report on the first call. Starting early turns compliance into a sales accelerator instead of a sales blocker.
Do you work with international clients?
Yes. SecureLeap is based in Porto, Portugal, with US and EU presence, and serves clients globally. They tailor compliance programs to your jurisdiction (US, EU, UK, APAC) and any industry-specific overlays such as HIPAA, GDPR, or DORA.
Who will I work with on my engagement?
You work directly with Marçal Santos, the Founder and CISO, who scopes and delivers your program. For specific deliverables such as penetration tests or internal audits, he coordinates with a network of vetted senior specialists. No junior consultants and no account manager handoffs.









