Compliance platforms
Goldline works inside whichever compliance platform you use, or without one. Platform licences are quoted separately and set out in full in your engagement letter. Without a platform, more of the reserved hours go to evidence collection.
Modules
Vulnerability scanning
What it is
Monthly external and quarterly internal scanning.
What it produces
Findings entered in your nonconformity register, each with an owner and a date.
Where Goldline runs scanning, the internal audit comes from someone else.
Priced at the diagnostic, fixed once agreed.
Annual penetration test
What it is
A CREST penetration test and a retest of the fixes.
What it produces
A test report and a retest report.
Carried out by a specialist tester, not by Goldline, and passed through at their fee, disclosed.
Priced at the diagnostic, fixed once agreed.
Reserved hours
What it is
Blocks of fractional security lead time.
What it produces
Decisions made and recorded, questionnaires beyond the retainer's quota answered, and audit sessions attended.
Goldline never audits a system it implemented.
Priced at the diagnostic, fixed once agreed.
Questionnaire desk
What it is
Human review of what your platform drafts, and the answers it can't give, on scope and exceptions.
What it produces
Reviewed answers ready for your sign-off.
Goldline reviews the answers; your organisation approves and sends them.
Priced at the diagnostic, fixed once agreed.
