We read it first.
Three weeks. Fixed fee. You get the findings the way your regulator, your auditor or your enterprise customer would have written them, while there is still time to fix what they would have found.
₹1,25,000 · three weeks · a senior partner in every session
We bundle findings with recommendations because separating them is how diagnostics get commoditised.
- 01The findings, written the way the reader would write them.Not four hundred rows of severity ratings. The specific things a regulator, auditor or enterprise buyer would raise, in the order they would raise them, with the reasoning attached so you can argue with any of it.
- 02Your score on the Security Read Index.Twenty-two controls mapped across RBI, SEBI CSCRF and MAS TRM, scored zero to four, with the peer band for entities of your size and tier.
- 03A remediation plan with owners and dates.Sequenced by what actually blocks you, costed, and shaped to go to an audit committee without being rewritten.
- 04An answer to whatever was asked of you.If a customer sent a questionnaire, a regulator sent a letter, or an investor sent a list, you leave with the response, not a document about the response.
- Days 1 to 3You pay, then we send the intake pack. In that order, deliberately: the work goes faster when the people gathering evidence are doing it as a client rather than as a prospect.
- Days 4 to 10We read what you have the way a reviewer reads it, which is not the order it was written in, and then we go where the documents point and check whether the controls actually operated. This is where the story either holds or comes apart.
- Day 11. The readout.Ninety minutes with your team. We put the findings on the table, in priority order, with three routes forward. This meeting is the product. We do not email the report ahead of it.
- Days 12 to 15The written artefact, short, with owners and dates against every item.
Day 11 is a closing meeting rather than a delivery, which is the difference between a diagnostic that goes somewhere and one that ends. The written artefact stays short on purpose.
No variation for hours or scope. If the readout does not give you at least one decision you can act on, tell us and we refund it in full. We have never had to.
We charge for the Read because a serious examination of your security is not something we can do properly for someone who is not serious about the answer, and because a firm that gives its thinking away free has told you what it thinks that thinking is worth.
From ₹1,00,000 a month in India, SGD 4,500 in Singapore.
Most firms do not need advice. They need somebody to own this. The Security Office is the function on retainer: a named senior partner accountable for the outcome, our agents doing the volume work underneath, and the tools, platforms and OEM licences you actually need, packaged and run by us rather than bought and managed by you.
That last part is the difference. You are not hiring a consultant and then separately buying five products and then discovering nobody owns the space between them. One line, one accountable name.
We are month-to-month and we are not built to be sticky. When you are ready to bring this in-house, we help you do it.

I have been working in offensive and defensive security since 2015. Since then: ISO 27001 inside the Bank of Montreal CISO office, sovereign security architecture for a department of the Netherlands government, ransomware response for regional enterprises, and board-level risk work for banks across six countries.
For a large part of that I was the person on the other side of the table, reading a company’s security before the regulator did, before the deal closed, before the investor’s technical team started asking questions. What undoes companies in that room is almost never a missing control. It is that the policy, the systems and the answer someone gives in the meeting are three different stories, and nobody inside had ever read them together in the order a reviewer reads them.
That is the entire reason Birchlogic exists, and it is the whole of what the Read does.
Karan Bhandari · Co-founder · Delhi and Singapore
- 2026Founding partner, the world's first Sustainable AI Centre of Excellence. The Indian Express
- 2026Speaker and exhibitor, India AI Summit. India AI Summit
- 2025India's first Sustainable IT Centre of Excellence. The Times of India
We already have a compliance platform.
Keep it. It collects evidence, which is real work. It cannot tell you whether your scope was drawn around the right systems, whether a control showing green actually operated, or how a specific regulator will read what you built.
We just passed an audit.
Then a defined set of controls operated inside a defined scope for a defined window. The question is what sits outside that boundary, and in most programmes we read, something significant does.
Can we just get the findings without the recommendations, cheaper?
No. We do not separate them.
Will you sign an NDA first?
Yes, ours or yours.
How fast can you start?
Two weeks normally. Seven days if you are holding a letter with a date on it.
What if we do not take the retainer?
Then you keep the findings and the plan, and if your own team can execute it we will say so.
Bring whatever is bugging you to a thirty-minute call. We will tell you what we would do and in how many weeks, or point you somewhere better and wish you well.