FAQ
Frequently asked questions
Last updated 1 September 2026
Questions we get before an engagement starts. If you are already working with us in the workspace, the help page covers access, exports, and support. For anything not answered here, book a scoping session.
- Is Baseline Telemetry Advisory one person, or a team?
- Right now, Baseline Telemetry Advisory is Harold. Penetration testing, legal review, and other framework-specific specialist work are brought in as needed, rather than delivered in-house. You always work directly with the person named on this site as your lead advisor, not a rotating account team.
- Have you done this before?
- Baseline Telemetry Advisory as a practice is new. The person running it isn't: twelve years leading ISO 27001, SOC 2, HIPAA, and DORA programs inside a global social media platform, a project management software company, and the European operations of a multinational insurance group. Alongside that, freelance engagements with early-stage teams who needed the same readiness work but had no internal team to do it is what led to Baseline Telemetry Advisory: a more structured way to deliver that work, instead of doing it engagement by engagement on the side. You are getting that experience applied to your company directly, not a junior team learning on your engagement.
- Are you an audit firm?
- No, and that is deliberate. Certification bodies have to stay independent of the work they audit, so a firm cannot both build your controls and issue your certificate without a conflict of interest. We do the readiness work, remediate the gaps, and support you through the audit. An accredited, independent certification body issues the actual attestation.
- Do you replace a vCISO, or work alongside one?
- For most clients, we are the vCISO function: fractional security leadership without the cost of a full-time hire. If you already have a CISO or security lead in-house, we work alongside them instead, taking the execution load off their plate rather than duplicating their role.
- What exactly do we get, and in what format?
- Structured deliverables you own: policies, control mappings, risk and vendor registers, and a buyer-ready evidence pack. Delivered in our workspace, these export as PDF, XLSX, DOCX, or a full ZIP handover bundle. Delivered embedded in your tools, the same registers land inside the tools you already run.
- Which frameworks do you cover, and which are added on request?
- SOC 2, ISO 27001, and GDPR are the core baseline for nearly every buyer conversation. DORA, the EU AI Act, ISO/IEC 42001, and HIPAA get scoped in the moment a specific buyer or regulator actually asks for them, not sold upfront as a bundle you do not need yet.
- Do you work in our tools, or in your workspace?
- Either, and which one fits is part of the scoping conversation, not something you have to decide upfront. Clearing one deal, we run delivery entirely in our own workspace, no new tooling required. Ongoing compliance, we work embedded directly inside your stack, Jira, Linear, Vanta, Drata, or whatever you run, under named accounts, scoped access, and a full audit trail. No background sync, no standing access left behind.
- Will you push us toward buying Vanta, Drata, or a similar platform?
- Only if your situation actually calls for it. If you're clearing a single enterprise deal, buying a recurring compliance platform to get there once is usually the wrong spend, our workspace handles that without new tooling. If you're heading into ongoing audits with a growing footprint, an automation platform earns its cost, and we'll say so plainly. Either way, the recommendation is based on what you need, not on what's easiest for us to sell.
- How long does SOC 2 or ISO 27001 readiness take?
- It depends on your current posture and which framework a buyer is asking about. What is fixed is the first step: a scoping session gets you a mapped buyer perimeter and a fixed statement of work within a week, so you know the real timeline before you commit to anything.
- Can you act as our Data Protection Officer?
- Not by default. We build and run the privacy programme a DPO would oversee, records of processing, DPIAs, breach procedures, which covers what most venture-stage teams actually need. A formal Article 37 DPO appointment can be scoped separately if your risk profile requires it.
- What happens to our data when the engagement ends?
- Handover exports are yours outright, downloadable at any point during the engagement, not just at the end. Workspace access is revoked on completion. Retention and deletion timelines for anything Baseline Telemetry Advisory holds afterward are set out in full on our Trust page.
- How does pricing work?
- Scope-based, quoted after a scoping call, not a public rate card. Every engagement is different enough in starting posture and framework mix that a fixed number without that conversation would be a guess dressed up as a quote.
Still deciding
The fastest way to get a real answer for your situation is a scoping session. It ends with a mapped buyer perimeter and a fixed statement of work, not a proposal deck. See the sample workspace for what delivery looks like, or the trust page for how we handle your data.
FAQ / last updated 1 September 2026
