Security services and software, from Vancouver.
Frontier Cyber tests, advises, governs and prepares organizations for what is coming, and builds the software that makes the work repeatable. Evidence, not assurances.
Four things we will not trade away.
They are the reason the method looks the way it does, and the reason the reports are shorter than you expect.
Evidence over assurance
A finding is something a second person has reproduced. A rating is something with the reasoning written next to it. If we cannot show it, we do not say it.
Written down
Scope, method, rules of engagement, price. All of it on paper before the work starts, so the only surprises in an engagement are the ones we find in your environment.
Named people
You know who is doing the work before it begins, and the same people see it through. Consultants, not account managers, answer your questions.
Built from the work
When a task repeats, we build the tool. RiskTrace and Frontier Verify exist because the consulting practice needed them first.
One practice, two products, three companies.
Frontier Cyber is the parent. RiskTrace and Frontier Verify stand alone under it, each with its own roadmap and customers, all run on the same method.
Frontier Cyber
The consulting practice. Nine practices from external testing and fractional CISO to AI governance and post-quantum encryption, delivered on one method.
See the practicesRiskTrace
Cyber risk and GRC software built around the tabletop exercise. Multi-tenant risk register, control mapping and board reporting.
Visit risktrace.aiFrontier Verify
External security testing you scope and pay for online, with a consultant verifying every finding and a report inside a week.
Visit frontierverify.comConsultants, not account managers.
Every engagement names its consultants in the scope. The person who tests your perimeter, assesses your program or sits in your leadership meeting is the person you talk to, from the first call to the retest.
Behind each of them is the rest of the practice: testers, assessors, incident responders and the engineers who build RiskTrace and Frontier Verify. A second analyst reproduces every finding before it reaches you, and an independent consultant reviews every long-running program each quarter.
We are based in Vancouver, Canada, and work on site and remotely with public sector, healthcare, professional services and technology organizations.
Tell us what you need tested, assessed or governed.
A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.
Start on Frontier VerifyReceived. A consultant will reply within one business day.
You will get a written scope and a fixed price, not a call booking link.