Cloud Sentry
Security & compliance

Get audit-ready. Stay audit-ready.

Nobody grows up wanting to own the risk register. Yet here you are. Compliance built into operations from the start: we build the controls, collect the evidence, and run the program. Passing your next audit is the beginning.

Frameworks we support

We help clients build, operate, and maintain the controls required by these frameworks. Logos identify the frameworks themselves, not a Cloud Sentry certification.

SOC for Service Organizations

SOC 2

The trust framework enterprise buyers expect. We build the controls and automate the evidence so you stay certified year after year.

Learn more
HIPAA

HIPAA

Technical safeguards, risk assessments, and ongoing monitoring for any company handling protected health information.

Learn more
HITRUST

HITRUST

The gold standard for healthcare security. We guide you from readiness assessment through certification.

Learn more

Why companies choose Cloud Sentry

The usual answer is four vendors: a compliance platform, an MSP, a consultant, and a fractional CISO. Each can be good at its slice, and none of them owns the outcome. You need one partner that runs all of it.

Compliance platforms

Compliance automation software

  • Automate evidence collection
  • ×You build and maintain the controls yourself
  • ×No security operations or monitoring
  • ×No strategic guidance or leadership
  • ×Software-only. Still need a team to run it

Great dashboards. But a dashboard doesn't build the controls it measures.

MSPs & MSSPs

IT and security providers

  • Run IT and security operations well
  • ×Audit readiness is a separate engagement
  • ×Board-level reporting rarely in scope
  • ×Compliance program management not included
  • ×No fractional CISO attached

Strong at what they are hired to run. Compliance programs and audits are a different scope, which is why we often work underneath one.

Cloud Sentry

Advisory + execution in one

  • Builds the controls AND automates the evidence
  • Runs your security operations 24/7
  • Manages compliance programs end-to-end
  • Fractional CISO who sets strategy and reports to the board
  • One partner covering operations, security, compliance, leadership

The team that advises AND operates. Your compliance program runs on autopilot.

What's included

Controls implementation

We build the technical and administrative controls your framework requires: the actual infrastructure behind the checklist.

Evidence collection automation

Automated evidence gathering connected to your real environment. No screenshots. No spreadsheets.

Policy development

Policies written for your business from how it actually runs. Reviewed, versioned, and mapped to controls.

Audit preparation

We manage the auditor relationship, prepare your evidence packages, and handle questions so your team stays focused.

Ongoing monitoring

Continuous control monitoring that catches drift before your next audit cycle. No annual scramble.

Gap assessments

Clear-eyed assessment of where you stand today, what needs to change, and exactly how long it takes to get there.

The team inside

The people who run this with you.

Named operators, reachable in the portal, answering you directly.

  • Dirk Vander Noot, Co-Founder & Operating Partner

    Dirk Vander Noot

    Co-Founder & Operating Partner

  • Jason Bowen, Cloud Operations Specialist

    Jason Bowen

    Cloud Operations Specialist

  • Ken Hanson, Founder & CEO

    Ken Hanson

    Founder & CEO

  • John May, Fractional CIO & Advisor

    John May

    Fractional CIO & Advisor

  • Emil Diaz, Fractional CTO

    Emil Diaz

    Fractional CTO

More than a dashboard

The evidence, and the team that builds it.

A compliance platform hands you a dashboard and leaves you to build the controls yourself. We build and run the controls, then hand a buyer or auditor the proof through the platform: a scoped, time-bounded Evidence Vault that opens on the first click. One operated front door, with nothing extra to manage.

Stop preparing for audits. Start passing them.

Tell us which frameworks you need. We'll show you exactly how to get there, and how long it takes.

Published structure with a written annual escalator cap. Read what each tier covers before anyone calls you.

The whole function run end to end: controls, evidence, audits, and one accountable lead who answers for the outcome.