épreuveepreuve.io
$ book discovery
$ épreuve --pilot
private pilot brief | 1 september 2026épreuve --pilot > brief.txt

TERMS

--scopefull agreed SOC 2 control scope · technical, documentary and governance work · depth follows risk
--stages2 · initial examination, then remaining audit-period testing
--feefixed · quoted after discovery and feasibility checks · [YOUR PRICE]
--reviewadversarial · a named reviewer challenges favourable results and false alarms
--retest1 · bounded · within an agreed remediation window · the original finding is kept
--remediationyours · we guide, your team implements
--auditoryours · decides what to reuse · we hand over workpapers, versions and permitted evidence access
--discoveryfree · 45 minutes · no credentials, no confidential evidence
--retainernone required · you can finish with a complete handover

Proposed service in development. This is not an engagement agreement, an available-service announcement, or an issued assurance report.

THE OFFER

Rigorous control assessment and audit readiness for established security and GRC teams. We examine whether your controls deliver the protection your programme relies on, then challenge our own conclusions. You receive findings, remediation guidance and workpapers your auditor can inspect.

Keep your platform, workflows, risk register, and auditor. Your team operates the controls and owns risk and remediation decisions. Épreuve takes responsibility for its examination. Your external auditor decides what to reuse and remains responsible for their procedures and report.

WHY ANOTHER EXAMINATION?

An audit is approaching. A system has changed. Leadership needs to know whether a control still protects the business. We investigate the claims behind those decisions and finish with a reviewed assessment your team can act on. A smoother external audit is an additional benefit to establish.

THE CHECK PASSED. DID THE PROTECTION HOLD?

In our fictional offboarding example, the identity-provider account is disabled within 24 hours. That criterion is satisfied for the individual. Application records bind a surviving token to the departed user, and a separately authorized test confirms resource access after the deadline. The broader access-ended claim is unsupported for that application.

This is an authored example, not a customer finding or an executed test. It establishes only the illustrated path. Insufficient evidence remains an unknown. Any active verification requires its own explicit authorization.

WHO THE FIRST PILOT IS FOR

A Head of Security GRC under the CISO, with an established SOC 2 program and a prior audit to compare against.

SCOPE AND METHOD

We try to break our conclusions before you rely on them.

All agreed SOC 2 controls, including technical, documentary, and governance work. Testing depth follows risk and control purpose. Exclusions, unfinished work, and evidence gaps remain visible. Collection alone is not a test: procedures address population completeness, period coverage, the intended protection, and exceptions or bypass paths. Documents, interviews, and observation remain part of the method where needed.

Our delivery approach uses AI to investigate evidence, draft procedures and adapt collection software. Reviewed, versioned software performs defined checks. Named people remain accountable for judgment and review. The review challenges favorable conclusions and possible false alarms. You buy completed examination, not another tool to operate. No favorable result is promised.

We assess customer control operation separately from the quality of our own methods, evidence, coverage, and conclusions. A defensible assessment can find a failed control or an evidence limitation. A reassuring customer result cannot excuse unreliable assessment work.

PROPOSED DELIVERABLES

  • Reviewed control assessment with supported conclusions and explicit unknowns.
  • Decision brief for remediation priorities, risk assumptions, and board use.
  • Auditor handover with workpapers, procedure versions, and permitted evidence access, so an authorized examiner can challenge and repeat the work.
  • Machine-readable records consistent with the assessment.

YOUR TEAM'S PART

A sponsor, source owners, authorized evidence access, and a baseline for audit effort and cost. Access is scoped and time bounded. Its duration does not establish or limit the historical period the evidence must support.

QUESTIONS FOR THE FIRST CONVERSATION

Discovery is free and time bounded. It covers reported historical evidence availability, access constraints, and responsible owners. Reported availability is not verified coverage. No credentials or confidential evidence are collected on this call. Where feasibility is uncertain, a small, separately authorized evidence check precedes a firm quote. Substantial investigation needs separate scope and commercial terms.

  1. Which control claims need examination, for which systems and period?
  2. What evidence can source owners provide, and where are the known gaps?
  3. Who needs to use the result, and what would make it useful to them?

FIXED FEE AND INCLUDED RETEST

Agree a fixed engagement fee after discovery and the required feasibility checks. It covers the initial examination and remaining audit-period testing, adversarial review, reporting, auditor handover, and one bounded retest of the original findings within an agreed remediation window.

We provide guidance; your team implements the fixes. The retest records the changes, dates, evidence, and remaining limitations. It does not erase the original finding, establish operation before the fix, or replace remaining audit-period testing. Additional remediation cycles or materially changed scope require separately agreed pricing. Correcting our own assessment errors never consumes your included retest.

Payment is for completed examination, including adverse or inconclusive results. Within the agreed scope, Épreuve absorbs its delivery inefficiency. Our missing connector, unimplemented procedure, or lack of expertise cannot be counted as completed examination or relabeled as a client evidence gap.

You can finish with a complete handover, without a retainer commitment. Agree the fee amount, timing, access, evidence handling, recipients, professional arrangements, and review responsibilities before an engagement. No fee amount, delivery timetable, or recurring-service price has been selected.

LIMITS

This proposed pilot does not include remediation implementation, continuous monitoring, a hosted trust centre, or a SOC 2 attestation, and does not replace a penetration test. The external auditor decides what to reuse. Acceptance, favorable conclusions, and lower fees are not guaranteed. Measure customer effort, actual reuse, fees, and combined cost separately from the assessment's decision value.

PREVIEW ONLY

Downloading this fixed brief sends no inquiry and books no meeting. Do not send credentials or confidential evidence through this preview. The website's assessment examples are fictional, not customer findings or performed audits.

CONTACT

Contact Ayoub on LinkedIn: https://www.linkedin.com/in/ayoubfandi/ This opens his profile, not a booking or automatic message. Sign-in may be required. Keep the initial conversation high-level.

THE FOUNDER'S PUBLISHED WORK

About Ayoub and GRC Engineer: https://grcengineer.com/about/ Change-management evidence: https://grcengineer.com/p/the-pr-approval-is-decaying-your-change-management-control-hasn-t-noticed/

NEXT

$ book discovery free · 45 minutes · with Ayoub, not a sales team