Skip to content
Papa Corporation

What cybersecurity covers

The whole security function, in whichever pieces you need.

Seven years in enterprise cybersecurity, where a single miss takes the whole company down, brought to a team your size. It is not one service. Take the whole function or just the part you are missing.

  • +
    Email and account securityA continuous audit of Gmail and Microsoft 365: hidden forwarding rules, risky outside apps, and who can see what, without ever reading your mail.
  • +
    Threat detection and responseWatching your accounts for the signals that come before a breach, and acting before they spread.
  • +
    Incident responseYour worst day, handled. You reach me within 30 minutes, with records that hold up for an insurer, an auditor, and a lawyer.
  • +
    Security auditsA full check of email, accounts, and cloud, with a short list of fixes ranked by priority, not a 200-page report.
  • +
    Compliance readinessThe paperwork a contract demands: the audit your customers ask for (SOC 2) and the one a defense contract requires (CMMC).
  • +
    Identity and access hardeningMulti-factor, least privilege, and locking down the accounts an attacker goes for first.

Also available

Work you can book on its own.

Most of these fold into a larger project. You can also book any of them on their own when you need a security check, breach coverage on standby, or defense paperwork ready by a deadline.

01

Breach response

When something goes wrong, you reach me within 30 minutes, we aim to stop the damage within two hours, and you get a clear written account that holds up in front of your board, your insurer, and a lawyer.

Discuss this
02

Security audits

A full check of your email, accounts, and cloud: hidden forwarding rules, outside apps connected to your email, who can see what. You get a short list of fixes ranked by priority, not a 200-page report.

Discuss this
03

Audit readiness

Help getting ready for the security paperwork your customers and contracts require, including the security audit your customers ask for (SOC 2), the health-data rules (HIPAA), and the security paperwork a defense contract requires (CMMC). Plain policies that match how your team actually works.

Discuss this

How an engagement runs

Four steps. Dates you can plan around.

The steps stay the same whether you are getting an AI assistant or a defense security package. Long enough to deliver something real, short enough that you always know where things stand.

01Week 0

We talk for an hour

I learn your systems, your process, and your constraints. You learn whether I can help and whether I am the right fit.

02Week 1

You get the plan in writing

A written plan and timeline in your inbox by Friday. Sign it or don't. No drawn-out research phase, no change orders, no surprise line items.

03Weeks 2-X

You get working software every Friday

Something that actually runs at the end of every week, not a slide deck. You have my cell, and you see progress as it happens.

04Week X+1

You get the keys

Plain instructions, a clean handoff, and the option to keep me on call. Nothing locks you in.

What you can count on

  1. 01Priced by the project and agreed in writing. No hourly billing.
  2. 02A written plan by Friday of week one.
  3. 03One point of contact from start to finish. You always know who to call.
  4. 04Full handoff with documentation and optional support after.
Record 01 / Real EstateAI · Permit Automation
$100K

saved by closing the project early

The permit agent that paid for itself in a week

Problem

A Miami real-estate developer was losing hours every week chasing reviewer comments across half a dozen Miami-Dade permits. Manual logins, copy-paste into spreadsheets, responses drafted by hand. Comments slipped through. Deadlines slipped after them.

What I built

An agent now checks the permit system every business hour. It catches every change, drafts the response to the reviewer, and sends three emails: an instant alert when a comment lands, a morning briefing, and an evening digest. One dashboard shows every permit on a single screen and updates after every check. If one AI service slows down, it switches to a backup automatically, so it never goes dark. A board shows whose turn it is to act, and the full reviewer conversation opens right on the page.

Inside the build

  • +Live dashboard updates after every check
  • +Every permit on one screen
  • +Runs on its own, no manual checking

Outcomes

  • Project closed weeks ahead of schedule, cutting the financing and holding costs that pile up on a stalled site and saving the developer over $100,000.
  • Zero reviewer comments missed since deploy.
[ AI Agent ][ Permit Automation ][ Real Estate ]
Record 02 / DistributionAI · Sales Automation
6 min

typical time from request to finished quote

An AI sales agent that does not get bored

Problem

A rigging-and-cable distributor built every quote by hand, one emailed request at a time, across thousands of products. Wire rope, cable, chain, and hardware come in dozens of variations, and customers send abbreviations, typos, names in more than one language, and phone photos with the formatting mangled. The team was losing deals to faster competitors.

What I built

The agent reads each request line by line, whether it arrives as text, a PDF, a spreadsheet, or a photo of a handwritten form, and matches every line to the right product. It prices against the company's own cost and last-paid floor, checks live stock across the warehouses, and a second pass catches contradictions before they reach a customer. A rep reviews and sends from the email. Behind that, it keeps learning from every sale and watches its own health hour by hour.

Inside the build

  • +Reads text, PDFs, spreadsheets, even scanned and handwritten forms
  • +Over 16,000 product names learned, and growing every night
  • +Prices every line against the company's own cost and last-paid floor, with a confidence score

Outcomes

  • The median time to quote dropped to six minutes, from days of manual work.
  • Three times the volume, with the same headcount.
[ AI Sales Agent ][ Quote Automation ][ Systems Integration ][ Distribution ]
Record 03 / DistributionCustom Software · Systems Modernization
Zero

days of downtime, replaced one screen at a time

A 1990s system, replaced without the rip-and-replace

Problem

The same rigging-and-cable distributor ran its business on a 1990s ordering system. Green-screen, brittle, and nobody left who wanted to touch it. The usual fix is a year-long rip-and-replace that risks the whole operation going dark. Meanwhile freight was priced by hand and product paperwork was assembled order by order.

What I built

Instead of a big-bang rebuild, the old system gets replaced one screen at a time, each new piece running next to the old one until it is trusted. Along the way the rest got automated too: freight is now priced across four carriers so the cheapest route wins on every order, and the product paperwork for each order is matched and emailed overnight without anyone touching it. All of it runs on the company's own data and was handed over, documented and clean.

Inside the build

  • +Replaced one screen at a time, no big-bang cutover
  • +Each new piece runs next to the old until it is trusted
  • +Freight priced across four carriers, cheapest route wins

Outcomes

  • A 1990s system retired with no day of downtime.
  • Freight cost down by always taking the cheapest route.
[ Custom Software ][ Systems Modernization ][ Integration ][ Distribution ]

On the numbers

Every number on this page is measured from the systems the client runs, and agreed before kickoff. Not estimates.

Record 04 / Financial ServicesSecurity · Email Defense
47

hidden forwarding rules surfaced

What a financial firm was missing across 200 mailboxes

Problem

A financial services firm had no real view into what was happening inside their 200-plus mailboxes. Hidden forwarding rules, the kind that quietly copy every CFO message to a personal Gmail, slip past the built-in security. Nobody had ever looked.

What I built

InboxWatch checked every mailbox for danger signs without reading the actual emails: a hundred checks per inbox across ten threat types. Forty-seven hidden forwarding rules surfaced in the first pass. One had been copying invoices and signed contracts to an outside address for the better part of a year. We shut it off the same hour and kept the paper trail an auditor would ask for.

Inside the build

  • +100+ checks per inbox across 10 threat types
  • +Hidden forwarding rules surfaced instantly
  • +Risky outside apps connected to email flagged

Outcomes

  • 47 hidden forwarding rules and 12 risky outside apps caught in the first scan.
  • All findings remediated within 72 hours.
[ InboxWatch ][ Email Security ][ Identity Hardening ]
Record 05 / Aerospace & DefenseCompliance · CMMC
Weeks

to a filable CMMC Level 1 package, not quarters

Defense security paperwork, ready to file in weeks

Problem

A Florida aerospace manufacturer had sensitive contract information moving through email, customer portals, their ordering system, and Dropbox. Their next contract required the security paperwork a defense contract demands (CMMC), at Level 1. That meant 17 specific safeguards, and they had nothing written down to prove they had any of them.

What I built

A complete Level 1 package: a review of where they stood against all 17 safeguards, five plain-English policies anyone can read, a written security plan ready to file, a fix-it list that tracks proof as each item is handled, and a fillable scoring worksheet for the government's contractor portal (SPRS). Every policy reflects how the team actually works. Thirty days of support after delivery to walk through the submission and answer questions during rollout.

Inside the build

  • +All 17 Level 1 safeguards covered
  • +5 plain-English policies anyone can read
  • +Written security plan ready to file

Outcomes

  • Full documentation package delivered in weeks, not quarters.
  • The team can read and follow every policy without outside help.
[ Defense Compliance ][ CMMC ][ Aerospace & Defense ]

Let's talk

Tell me what your team does by hand, or what you want to build.

Plain language, no runaround. By Friday at the latest you get a real reply: whether this is a fit, what the scope would look like, and a number you can plan around. If it is not a fit, you will hear that too, along with who to call instead.

Reply by
Friday
First call
One hour