FirmProof

The thesis

The advisor is already inside the client. Give them the platform.

A public version of the reasoning behind FirmProof. Written for CPA firm principals, PE operating partners, and the technical evaluators who ask hard questions.

The proof gap in SMB security

Every SMB now has a cyber problem it did not have five years ago. Cyber insurance carriers ask for controls the client cannot describe. Enterprise customers push down security questionnaires with 300 questions. Regulators publish frameworks that were written for a company an order of magnitude larger. None of this is optional. All of it lands on a business owner who does not have a security team, does not want a security team, and does not read framework language for pleasure.

The current answer is that the SMB either lies on the questionnaire, hires a consultant for a one-off engagement, or buys a self-serve GRC tool built for the venture-funded startup that owns its own CTO. The consultant leaves a binder that goes stale in 60 days. The self-serve tool assumes an internal security team to operate it. The lie catches up eventually.

The proof gap is not a tooling gap. It is a delivery gap. The SMB needs somebody to run the work continuously, not somebody to sell them software.

Why the accounting firm is structurally the right advisor

The CPA relationship is annual at minimum, quarterly for the engaged firm, and monthly for the outsourced-CFO relationship that is now common in mid-market. That relationship is already regulated, already fiduciary, already trusted to see the client’s general ledger, payroll, tax posture, and financial exposure. The mental model of privileged access and stewardship of sensitive records is already in place. Extending it to security posture, control evidence, and compliance attestation is a smaller step than starting a new vendor relationship from scratch.

Firms have been quietly building this practice already. The pattern shows up as an "advisory services" line, a "risk services" partner, a fractional CISO offering. Every one of these firms has hit the same wall: the underlying platform tooling is built for the end customer, not the firm that serves the customer. Pricing is per-seat. Onboarding assumes one company. Reporting rolls up to one board. The firm ends up hand-stitching a practice out of tools designed for someone else, and the margin never quite works.

Why current GRC tools do not fit the firm-plus-client model

The incumbent GRC platforms are excellent at what they were built for: helping a single technology company get through a SOC 2 audit. They are architecturally direct-to-customer. Multi-tenancy exists, but it exists to let one company run multiple environments, not to let one firm run 50 different clients under 50 different frameworks with 50 different auditors.

Pricing is per-seat. That is fine when the buyer has 500 employees. It is unworkable when the buyer is a 12-person firm that would need to add every one of its clients as a seat.

Reporting is per-instance. The partner who wants a single view across 30 clients has to build it themselves, in spreadsheets, every quarter.

Branding is fixed. The client logs in and sees the vendor’s logo, not the firm’s. The firm becomes a middleman visible only in the invoice.

Retrofitting any of these platforms to a channel model is not a feature request. It is a redesign of the tenancy model, the pricing model, and the reasoning layer at the same time. The incumbents have not made that architectural commitment, and it is not the kind of commitment made under quarterly-earnings pressure.

What FirmProof does differently

Four commitments the product is built around.

Two-level tenancy from day one. The channel partner owns a workspace. Every end client is a fully isolated sub-tenant inside that workspace. One operator, one console, many clients. The isolation is architectural rather than a policy line in the terms of service. It is verified by automated tests.

Per-client pricing, not per-seat. Firms grow by adding clients, not by adding operators. Pricing tracks the actual unit of value. A firm managing 40 clients pays for 40 clients, not for 40 licenses of a tool bought once for one operator. Revenue share to the partner grows as the client count grows, so the partner’s incentive to sell the firm’s services aligns with the platform’s incentive to power more of them.

Grounded AI, always with human approval. Every AI output traces to a specific control condition in the platform’s underlying knowledge layer. Outputs that cannot be traced are flagged, not shown as complete. Every draft carries model version, evidence, and confidence. No output moves from draft to delivered without a named human approving. That approval is logged, replayable, and defensible in an audit.

Evidence is the artifact, not the report. The valuable thing is the evidence artifact and the traceable claim built on it. Reports are generated from evidence, on demand, in whatever framework a client’s auditor or insurer needs. Evidence never goes stale in a binder because the binder is not the artifact.

What we mean by continuous assurance

Continuous assurance is a machine-verifiable, always-current picture of a client’s control posture, delivered through the advisor the client already trusts.

Three properties matter.

First, machine-verifiable. Every control condition maps to specific evidence the platform can pull, classify, and time-stamp. A human reviews, but the human is not the source of the ground truth.

Second, always-current. The picture updates as the underlying evidence changes. A control that was passing yesterday and failing today shows as failing today, not as passing until the next audit.

Third, advisor-delivered. The picture reaches the client through the firm the client already works with, in the firm’s own brand, on the firm’s own cadence. The advisor is the interpreter, the operator, and the point of accountability. The platform is the infrastructure that makes the advisory practice economically viable.

What comes next

The first cohort of design partners is now recruiting. The commitment is a 90-day working relationship: a small number of the firm’s clients onboarded to the platform, weekly working sessions with the founder, product feedback that shapes the roadmap, and pricing locked at design-partner terms for the first year of paid usage.

If your firm is already having cyber conversations with clients and has felt the ceiling on how far you can take that without building a security practice, the design partner cohort is the door.

Talk to us about the design partner cohort