Security Testing · Compliance · Managed Security · AI & Automation

See what attackers see. Fix it before they use it.

Black Lantern Labs is a security firm built for small and mid-sized businesses. We use AI to run the slow, repetitive parts of testing, monitoring, and compliance, then put a senior operator behind every result. That keeps serious security work at a price a growing company can afford, with proof you can hand to a customer, a board, or an auditor.

Services

Four service lines. One team. Zero handoffs.

AI handles the repetitive work: reconnaissance, scanning, evidence collection, reporting. A senior operator reviews and stands behind every result. You get the depth of a specialist firm at a price that fits a small or mid-sized budget, with evidence behind every finding.

I. Security Testing

Find the weaknesses before someone else does.

A manual, human-led penetration test, not a scanner export with a logo on it. We test your networks, web apps, and cloud the way a real attacker would, chaining small issues into the ones that actually hurt. AI runs the reconnaissance and scanning, so more of your budget goes to the hands-on testing that finds real problems.

  • /01
    Penetration Testing

    Authorized, scoped testing of your networks, applications, and cloud environments. You get findings you can verify, not a scanner export with a cover page.

  • /02
    Exposure Snapshot

    A passive review of what your organization already shows the internet: forgotten subdomains, exposed services, leaked addresses, lookalike domains. Built entirely from public records. Requires nothing from you but a domain name.

  • /03
    Threat Modeling & Security Reviews

    A structured walkthrough of your product or environment that answers three questions: what are we protecting, who would come after it, and where would they get in.

What you get

A report your engineers can act on, a severity you can defend to leadership, and a free retest once you have fixed the findings. If it cannot be reproduced, it does not go in the report.

II. Compliance

Compliance without the year of thrash.

SOC 2, HIPAA, and PCI are how customers decide they can trust you with their data. We run the readiness work end to end: gap assessment, policies, controls, and evidence collection. AI assembles and organizes the evidence, the slow and expensive part, so you reach audit-ready in weeks instead of quarters.

  • /01
    Readiness Assessments

    A gap analysis against the framework you need, with a sequenced plan to close each item in priority order.

  • /02
    Policies & Controls

    Policy sets and control implementations matched to how your team actually works, not templates nobody reads or follows.

  • /03
    Evidence & Audit Support

    We help you collect proof, prepare your team, and stay at the table through auditor questions.

What you get

A passed audit and a posture that still holds up after the auditor leaves. Not a binder nobody opens.

III. Managed Security

Ongoing coverage without building a security team.

Hiring a security team is slow and expensive. We become yours: watching your external surface and critical systems, triaging new vulnerabilities against your environment, and picking up the phone when something looks wrong. Automated monitoring runs around the clock; a human decides what actually matters.

  • /01
    Continuous Monitoring

    Ongoing watch over your external surface and critical systems for new exposures, unexpected changes, and signs of trouble.

  • /02
    Vulnerability Management

    New vulnerabilities triaged against your actual environment, so your team patches what matters first instead of chasing every headline.

  • /03
    Incident Support

    When something happens, you have someone to call who already knows your environment and can act immediately.

What you get

A plain monthly report of what we watched, what we found, and what we did about it. Month-to-month, no long lock-in, and you keep the documentation if you leave.

IV. AI & Automation

Put automation to work inside your business.

The automation that keeps our security work affordable is a service in its own right. We build AI workflows that take repetitive work off your team, intake, reporting, document handling, follow-up, with the permissions, logging, and human checkpoints that keep them safe to run.

  • /01
    Workflow Automation

    AI systems that handle the repeatable work in your operations: intake, reporting, document handling, follow-up.

  • /02
    Implementation & Integration

    Connecting AI tools to the systems you already use, scoped and logged from the first run.

  • /03
    Practical Guidance

    A straight read on what is worth automating now, what is not, and what it takes to close the gap.

What you get

We run our own firm on these systems. It is why we can price the way we do, and why nothing ships to a client that we would not run ourselves.

Advisory

A senior security voice when you need one.

Not every problem needs a project. Sometimes you need an experienced operator in the room: to set direction, to evaluate a purchase, or to keep a deal moving when security questions show up.

/01

Security Advisory

A standing advisor for your leadership team. We help you set the security roadmap, prioritize spend against real risk, and report posture to your board and customers in plain language.

/02

Vendor & Product Selection

The security market is crowded and loud. As a reseller with operator experience, we help you choose tools that earn their cost, source them well, and configure them so they actually get used.

/03

Sales Security Support

Security questionnaires, customer audits, and trust reviews stall deals. We answer them fast and accurately, build your evidence library, and keep your sales cycle moving.

Manifesto

The Black Lantern

Our name comes from the dark lantern, an old watchman’s tool: a flame with a shutter on it. Light exactly where you need it, darkness everywhere else. Watchmen carried them. So did thieves. You cannot defend a system well unless you understand how it gets attacked.

We started Black Lantern Labs because good security priced most small and mid-sized businesses out. The firms that do it well are expensive. The cheap options are checkbox scans and PDF mills. AI changes that math. We automate the slow, repetitive work and put a senior operator behind every result, so serious security fits a real budget.

We take a small number of clients and go deep. You talk to the people doing the work, because the people doing the work are the firm. Either a finding has evidence or it stays out of the report. Either a control works or it does not. Either we would stake our name on the work or we do not ship it.

Operating standards

How we hold ourselves to account

100%Of findings reviewed & verified by a human operator, with a fix path
AI + operatorAutomation does the repetitive work; a senior operator stands behind every result
Built for SMBSpecialist-grade testing priced for small & mid-sized budgets
No lock-inEvery engagement includes documentation & an exit plan

Double Rule Security

Our dedicated practice for CPA and accounting firms.

Tax and accounting practices hold some of the most sensitive data a business can carry, and regulators require a written security program to match. Double Rule Security is Black Lantern Labs’ dedicated offering for CPA firms: the security plan, the compliance work, and the ongoing protection behind it, delivered in the same plain language as everything we do.

Contact

Start with a conversation.

Thirty minutes, no deck, no pressure. Tell us what you are trying to protect and we will give you a straight read on where to start.

Most clients start with an Exposure Snapshot.

A passive review of what your organization already shows the internet, built entirely from public records. It requires nothing from you but a domain name, and it produces evidence you can act on the same week.