Restoring integrity to compliance - one company at a time

Why I started BrightLine

For most of my career, I built and led security and compliance programs — implementing controls, preparing for audits, translating technical requirements for boards, and facing the pressure to “just get certified,” whether the work was truly done or not.

At my last company, I saw the breaking point. We had SOC 2 and ISO 27001 certifications — on paper. Leadership used them to close deals and satisfy investors, but the controls weren’t maintained. Certifications had become marketing tools, not protections. That’s when I realized the industry needed advisors who wouldn’t compromise.

BrightLine was built on one principle: if you’re going to say you’re certified, the controls must be real. No shortcuts. No theater. No crossing the bright line between compliance and marketing spin.
brightline img

The standard that defines how we work

What "bright line" means

In legal terms, a bright line is clear and non‑negotiable you must be 21 to drink, 18 to vote, 16 to drive. There’s no ambiguity. That’s the philosophy behind BrightLine Readiness: clear standards, no shortcuts, and integrity that doesn’t bend under pressure.

That's integrity. And that's the only way I work.
If a company claims SOC 2 or ISO certification, the controls should actually be implemented and maintained not documented for the auditor and then ignored. Not “good enough for now.” They must be real, functioning, and defensible.
globle
Three decades of hands‑on security and compliance leadership.

What I bring to the table

Over 30 years, I’ve worked across every stage of security and compliance — from hands‑on implementation to executive advisory. I’ve guided startups through their first SOC 2 audits, helped mid‑market companies navigate SOC2, and partnered with enterprises on FedRAMP and ISO 27001 programs. I know what auditors look for, what corners companies try to cut, and what it truly takes to build defensible compliance.
Sunset behind silhouetted seagulls sitting on a boat railing at sea.

Security & Compliance

Blue hexagonal icon with left and right white arrows inside a white circle.
SOC 2 Type I & II
Blue hexagonal icon with left and right white arrows inside a white circle.
ISO 27001
Blue hexagonal icon with left and right white arrows inside a white circle.
HIPAA & HITRUST
Blue hexagonal icon with left and right white arrows inside a white circle.
FedRAMP
Blue hexagonal icon with left and right white arrows inside a white circle.
PCI-DSS
Blue hexagonal icon with left and right white arrows inside a white circle.
State compliance
Blue and orange fan blade icon with six curved blades forming a symmetrical shape.

Industry Experience

Blue hexagonal icon with left and right white arrows inside a white circle.
SaaS & cloud-based platforms
Blue hexagonal icon with left and right white arrows inside a white circle.
Healthcare & life sciences
Blue hexagonal icon with left and right white arrows inside a white circle.
Financial services
Blue hexagonal icon with left and right white arrows inside a white circle.
Government contracting
Blue hexagonal icon with left and right white arrows inside a white circle.
Professional services
Blue hexagonal icon with left and right white arrows inside a white circle.
Regulated technology companies
Blue square with a lighter blue rounded square inside, centered on a blue background.

How I Deliver Results

Blue hexagonal icon with left and right white arrows inside a white circle.
Readiness & gap reviews
Blue hexagonal icon with left and right white arrows inside a white circle.
Board-level compliance insights
Blue hexagonal icon with left and right white arrows inside a white circle.
Audit preparation & validation
Blue hexagonal icon with left and right white arrows inside a white circle.
Control strategy advisory
Blue hexagonal icon with left and right white arrows inside a white circle.
Implementation support
Blue hexagonal icon with left and right white arrows inside a white circle.
Vendor selection guidance

Compliance done properly - not performatively

Built for companies that want to do it right

BrightLine isn’t for everyone. If you’re looking for a consultant to rubber‑stamp your compliance and move on, I’m not your guy. If you want someone to do all the work while your team stays uninvolved, that’s not how I operate.

But if you’re a CEO, CTO, or executive who understands that certification matters — and wants to achieve it with integrity — we should talk.

I work with mid‑market companies in SaaS, healthcare, financial services, and other regulated industries. These are organizations that need SOC 2, ISO 27001, HIPAA, or FedRAMP to close deals, satisfy investors, and meet regulatory requirements — and that value doing things properly, without shortcuts.
Abstract white geometric eight-petal star on grainy blue and green gradient background.
Snow-capped mountains behind a forest of yellow autumn trees under a blue sky with clouds.

Local roots. National reach. Same integrity everywhere."

Colorado-based, available nationwide

BrightLine is headquartered in Colorado, and I’m always happy to meet in person with local clients. But compliance readiness doesn’t depend on geography. I work remotely with companies across the country. Whether you’re in Denver or Delaware, the process, advisory approach, and deliverables are identical.

If your team prefers face‑to‑face meetings, great. If remote collaboration works better, that’s fine too. The goal is the same either way: get you certified with integrity.

et’s make compliance clear — not complicated.

Ready to talk?

If you’re facing a certification deadline, stuck mid‑audit, or not sure where to start, let’s talk. I’ll give you honest feedback on what it’ll take to get certified — and whether BrightLine is the right fit.
Schedule a Conversation