Services
Four service lines. One team. Zero handoffs.
AI handles the repetitive work: reconnaissance, scanning, evidence collection, reporting. A senior operator reviews and stands behind every result. You get the depth of a specialist firm at a price that fits a small or mid-sized budget, with evidence behind every finding.
I. Security Testing
Find the weaknesses before someone else does.
A manual, human-led penetration test, not a scanner export with a logo on it. We test your networks, web apps, and cloud the way a real attacker would, chaining small issues into the ones that actually hurt. AI runs the reconnaissance and scanning, so more of your budget goes to the hands-on testing that finds real problems.
- /01Penetration Testing
Authorized, scoped testing of your networks, applications, and cloud environments. You get findings you can verify, not a scanner export with a cover page.
- /02Exposure Snapshot
A passive review of what your organization already shows the internet: forgotten subdomains, exposed services, leaked addresses, lookalike domains. Built entirely from public records. Requires nothing from you but a domain name.
- /03Threat Modeling & Security Reviews
A structured walkthrough of your product or environment that answers three questions: what are we protecting, who would come after it, and where would they get in.
What you get
A report your engineers can act on, a severity you can defend to leadership, and a free retest once you have fixed the findings. If it cannot be reproduced, it does not go in the report.II. Compliance
Compliance without the year of thrash.
SOC 2, HIPAA, and PCI are how customers decide they can trust you with their data. We run the readiness work end to end: gap assessment, policies, controls, and evidence collection. AI assembles and organizes the evidence, the slow and expensive part, so you reach audit-ready in weeks instead of quarters.
- /01Readiness Assessments
A gap analysis against the framework you need, with a sequenced plan to close each item in priority order.
- /02Policies & Controls
Policy sets and control implementations matched to how your team actually works, not templates nobody reads or follows.
- /03Evidence & Audit Support
We help you collect proof, prepare your team, and stay at the table through auditor questions.
What you get
A passed audit and a posture that still holds up after the auditor leaves. Not a binder nobody opens.III. Managed Security
Ongoing coverage without building a security team.
Hiring a security team is slow and expensive. We become yours: watching your external surface and critical systems, triaging new vulnerabilities against your environment, and picking up the phone when something looks wrong. Automated monitoring runs around the clock; a human decides what actually matters.
- /01Continuous Monitoring
Ongoing watch over your external surface and critical systems for new exposures, unexpected changes, and signs of trouble.
- /02Vulnerability Management
New vulnerabilities triaged against your actual environment, so your team patches what matters first instead of chasing every headline.
- /03Incident Support
When something happens, you have someone to call who already knows your environment and can act immediately.
What you get
A plain monthly report of what we watched, what we found, and what we did about it. Month-to-month, no long lock-in, and you keep the documentation if you leave.IV. AI & Automation
Put automation to work inside your business.
The automation that keeps our security work affordable is a service in its own right. We build AI workflows that take repetitive work off your team, intake, reporting, document handling, follow-up, with the permissions, logging, and human checkpoints that keep them safe to run.
- /01Workflow Automation
AI systems that handle the repeatable work in your operations: intake, reporting, document handling, follow-up.
- /02Implementation & Integration
Connecting AI tools to the systems you already use, scoped and logged from the first run.
- /03Practical Guidance
A straight read on what is worth automating now, what is not, and what it takes to close the gap.
What you get
We run our own firm on these systems. It is why we can price the way we do, and why nothing ships to a client that we would not run ourselves.Advisory
A senior security voice when you need one.
Not every problem needs a project. Sometimes you need an experienced operator in the room: to set direction, to evaluate a purchase, or to keep a deal moving when security questions show up.
/01
Security Advisory
A standing advisor for your leadership team. We help you set the security roadmap, prioritize spend against real risk, and report posture to your board and customers in plain language.
/02
Vendor & Product Selection
The security market is crowded and loud. As a reseller with operator experience, we help you choose tools that earn their cost, source them well, and configure them so they actually get used.
/03
Sales Security Support
Security questionnaires, customer audits, and trust reviews stall deals. We answer them fast and accurately, build your evidence library, and keep your sales cycle moving.
Manifesto
The Black Lantern
Our name comes from the dark lantern, an old watchman’s tool: a flame with a shutter on it. Light exactly where you need it, darkness everywhere else. Watchmen carried them. So did thieves. You cannot defend a system well unless you understand how it gets attacked.
We started Black Lantern Labs because good security priced most small and mid-sized businesses out. The firms that do it well are expensive. The cheap options are checkbox scans and PDF mills. AI changes that math. We automate the slow, repetitive work and put a senior operator behind every result, so serious security fits a real budget.
We take a small number of clients and go deep. You talk to the people doing the work, because the people doing the work are the firm. Either a finding has evidence or it stays out of the report. Either a control works or it does not. Either we would stake our name on the work or we do not ship it.
Operating standards
How we hold ourselves to account
Double Rule Security
Our dedicated practice for CPA and accounting firms.
Tax and accounting practices hold some of the most sensitive data a business can carry, and regulators require a written security program to match. Double Rule Security is Black Lantern Labs’ dedicated offering for CPA firms: the security plan, the compliance work, and the ongoing protection behind it, delivered in the same plain language as everything we do.
Contact
Start with a conversation.
Thirty minutes, no deck, no pressure. Tell us what you are trying to protect and we will give you a straight read on where to start.
Most clients start with an Exposure Snapshot.
A passive review of what your organization already shows the internet, built entirely from public records. It requires nothing from you but a domain name, and it produces evidence you can act on the same week.