Questions, answered

Including the ones that are awkward for us. If something here is vague, tell us and we will fix the answer.

The basics

What is Certivar?
A compliance service, not compliance software. You do not log in to manage your own program — we run it. We scope it, write your policies, connect to your systems and collect the evidence, chase your team only for the things a person genuinely has to do, and deal with your auditor. Certivar is operated by Neo-2 Consulting Limited, Saskatoon, Saskatchewan.
What does it cost?
$990 a month for one framework, everything included. $1,990 a month for multiple frameworks plus security questionnaires answered for you. There is no per-seat pricing, no setup fee, and no free trial — an engagement produces a scoped program and a full policy set in its first weeks, which is real work rather than a demo.
Which frameworks do you run?
SOC 2 Type II, ISO 27001:2022, HIPAA Security Rule and PCI DSS v4.0, drawing on 127 pre-built controls. One piece of evidence can satisfy several frameworks at once. Custom frameworks are supported.
Who is this for?
Companies that need a certification to close deals and would rather not turn an engineer into a part-time compliance manager. Typically seed to mid-market with no dedicated compliance hire. Most people comparing us are looking at a fractional CCO or a consultant, not at compliance software.
How do we start?
With a conversation, not a setup wizard. An intake interview establishes what you build, what you run it on, what data you hold and why you need the certification. That produces a scope proposal, which a Certivar reviewer reads before you see it.

The two things called “agents”

Do you install monitoring agents on our machines?
No. Nothing is installed on your infrastructure. We read your cloud, source control and identity systems through scoped, read-only API connections that you authorise and can revoke at any time.
But Certivar is AI. Aren't those agents too?
Yes, and the word doing double duty here causes genuine confusion, so we will be precise. There are two different things called agents. A monitoring agent is software a compliance vendor installs on your servers and laptops to watch them continuously — that is what Vanta and Drata do, and what we mean when we say nothing is installed. An AI agent is a model given tools and a task. Certivar is built on AI agents, and they are how the work gets done: scoping your program, drafting policies, reviewing test results, answering questionnaires.
Where do your AI agents run?
On our infrastructure, not yours. They reach your systems only through the read-only API connections you have authorised. Nothing executes on your machines, and nothing needs root, an install, or an exception from your security team.
So why does not installing anything matter?
Because a monitoring agent is a permanent third-party process, usually privileged, on every machine you own. It watches everything, including customer data and source code. It consumes resources on production hosts. It is another way in if the vendor is compromised. For healthcare, legal and financial customers, and for anyone in a regulated environment, that alone can make a vendor impossible to approve.
Doesn't reading our systems through an API amount to the same access?
No. Read-only API credentials are scoped, enumerable, revocable in one click, and logged by the provider. An installed agent runs code on your host with whatever privileges it was granted. Those are different risks, and your security reviewer will treat them differently.

How the work actually gets done

How much of this is AI and how much is people?
The AI does the volume: the interview, the scoping, the drafting, the daily test runs, the first pass at questionnaire answers and auditor requests. People own the judgement. A Certivar reviewer reads anything that attests before it leaves us, and a named person at your company signs anything that states a fact about your organization.
How do I know the AI didn't make something up?
Because a claim without evidence behind it is rejected before it is stored, not flagged afterwards. Any action that attests to something must cite artifacts that actually resolve within your account — a test result, a document, a policy version. If the citation does not resolve, the write fails. Every action the AI takes is recorded in an append-only log you can read.
Are the policies just templates with our name in them?
No, and there is a check in the pipeline specifically to stop that. Each policy starts from a baseline, is rewritten against your actual stack and named systems, and is compared to the baseline it came from. A draft that has not meaningfully diverged is rejected rather than shipped. You can see the baseline and the diff for every policy we produce.
What happens every day?
Each morning we review the automated test results from your connected systems, propose evidence for the controls it supports, open tasks for anything only a person can resolve, update your readiness, and write a short report citing what it was based on. Evidence is never linked to a control automatically — a reviewer approves that mapping.
What will you need from us?
Less than you expect, but not nothing. Some things cannot be automated: commissioning a penetration test, running background checks, sitting through a risk assessment, approving policies as the accountable owner. We chase you for those and nothing else.
Which systems can you connect to?
AWS, GitHub, Google Workspace and Okta today, tested daily against the controls they support. Azure, GCP and MDM providers are next. Anything not connected is collected the ordinary way, and gaps are reported as gaps rather than quietly skipped.

Auditors and outcomes

Do you issue the report or certificate?
No, and no vendor who prepares you can. A SOC 2 report must come from an independent CPA firm; an ISO 27001 certificate from an accredited certification body. You engage them separately. We prepare you, answer their requests, and hand over the evidence package.
Do you take referral fees from auditors?
No. No referral fee, no commission, no payment for placement in any list we give you. If that ever changes we will say so before it takes effect. An auditor recommendation is worthless if we are paid to make it.
Can you guarantee we pass?
No, and anyone who does is telling you something they cannot know. The audit opinion belongs to an independent firm. What we can do is make sure nothing in your package is unsupported, and that gaps are visible to you long before they are visible to your auditor.
How fast can we be audit-ready?
It depends on what you already have, and for SOC 2 Type II there is an observation window that cannot be shortened by anyone at any price. We give you a specific date after scoping, and we will not move it to win the engagement. If you need something faster than the framework allows, we will tell you that on the first call.
What does our auditor actually get?
Their own portal, with scoped read-only access, no shared drive and no zip files over email. Information requests get drafted responses built only from verified artifacts. The audit package is assembled from database state rather than generated by a model: every file carries a SHA-256 digest, N/A decisions carry their written rationale, and gaps are listed as gaps.

Data, security and commitments

Where does our data go?
Our infrastructure runs in AWS in the United States. Your data is also processed by Anthropic, for the models that draft and reason, and Voyage AI, for search across your own corpus. Stripe handles billing. All of these are named in our privacy policy — an undisclosed AI subprocessor is exactly the finding we would raise against one of our own clients.
Do you train models on our data?
No. Your data is used to deliver your engagement and nothing else. It is not used to train AI models and it is not sold.
We're Canadian, or in the EU. Is US processing a problem?
It is a disclosure you should make a decision about rather than discover later. Neo-2 is a Saskatchewan company, but the service currently operates in the United States, which means your data crosses the border and is reachable by US authorities. Our privacy policy states this plainly. If cross-border processing is not acceptable for your organization, tell us before you start.
What if we cancel?
You can end the engagement at the end of any billing period. You keep the policies and documents we produced for you, and you have thirty days to export your evidence and audit material.
Who is behind Certivar?
Neo-2 Consulting Limited, a corporation registered in Saskatchewan, Canada, with its office in Saskatoon.

Still not sure?

The longer version of how the work gets done is on the how it works page, including where AI ends and a person starts.