About Lantern · Piqua, Ohio
Quiet,
and thorough.
Lantern is one thing done carefully: finding the ways into your systems before someone less friendly does, then writing it down so a person can actually fix it. Here is who's behind that and how we think about the work.
01 · Why We Started
A thinner report that got read
Lantern began after too many years of watching good work go unopened — 200 pages of scanner output that nobody on a busy team ever had time to sort.
So we kept two things small on purpose: the scope, and the writing. We test the two or three systems that would actually hurt if they broke, exploit what we find by hand rather than trusting a tool's guess, and hand back a document an on-call engineer can follow at 2am. Then we come back and retest once you've patched — that part isn't a second invoice.
We're on S Wayne St in Piqua, and most of the work is remote across Ohio and the Miami Valley. When an engagement genuinely calls for someone in the room, we drive.
02 · What We Hold To
Four things, kept simple
The report is the product
Findings written for the engineer who has to fix them, ranked by what an attacker reaches first — plus a summary a board can read without a translator.
Fixed scope, fixed fee
Everything is quoted up front against a written scope. If the work grows, we agree on it before touching it. You never open a surprise invoice.
We stay out of the audit
The SOC 2 audit itself has to come from a licensed CPA firm — and keeping that separate is the point. We get you ready; someone independent signs it.
Small by choice
There's no account manager to route you through. Scoping, testing, and the write-up are the same set of hands from the first call to delivery.
03 · How We Keep Current
Methodical, not mysterious
Testing
OWASP, applied by hand
Web and API work follows the OWASP Testing Guide as a floor, not a ceiling — the interesting bugs live in the logic a checklist skips.
Cloud & Config
Benchmarked, then reasoned
We map cloud and access review against the CIS Benchmarks, then rank findings by what someone could actually reach — not by count.
Compliance
Mapped, not recited
SOC 2 work is mapped to the Trust Services Criteria and HIPAA work to real safeguards, written to survive an actual question rather than tick a box.
Rules Of Engagement
Agreed in writing first
Windows, targets, and boundaries are signed off before anything runs. We avoid destructive tests on production and stay reachable throughout.
After Delivery
A retest, included
Once you've patched, we come back and confirm the fix held. That verification is part of the engagement, not a fresh line item.
Where We Work
Piqua & remote
Based at 435 S Wayne St. Remote across Ohio and the Miami Valley, on-site when the scope makes it worth the drive.
04 · Start The Conversation
Request a scope
Tell us what you're running and what's driving the timeline. We'll reply within one business day with a scope, a fee, and a start date — no sales sequence, no follow-up drip.
05 · The Short Version
One office, four engagements
Penetration tests, security audits, SOC 2 and HIPAA readiness — each fixed-scope and fixed-fee. See exactly what's inside each one and what it costs.
See the services
06 · Prefer To Talk First
A 30-minute scoping call
Not sure which engagement fits, or whether you need one at all? A short call sorts it. If a test would be overkill, we'll say so.
Call (937) 980-9035