Skip to main content

About the practice

EK Treasure is an enterprise trust advisory. We exist because good companies lose winnable deals for reasons that have nothing to do with their product.

The practice was built in environments where trust is the whole game: government programs, enterprise cloud, regulated infrastructure. What we learned there is now applied to the companies enterprises are trying to buy from — AI and SaaS businesses whose growth has outrun their evidence.

We are deliberately small, principal-led, and engagement-based. No bench, no body shop, no annuity assessments. The goal of every engagement is a program your team runs without us — which is why clients come back by choice, not by contract.

The practice, on paper

Credentials, stated plainly.

Practice model
PRINCIPAL-LED
Sector history
GOV + ENTERPRISE
Core disciplines
CLOUD · SECURITY · AI GOV
Frameworks
SOC 2 · ISO 27001
Engagement style
SCOPED · GATED
Base of operations
TORONTO, CA

How we work

Five commitments, in writing.

01

The person who scopes it, runs it

No bait-and-switch to a junior bench. The principal in your Triage call is the principal at your decision gates.

02

Fixed scope and fee, agreed before week one

Investment is based on scope, complexity and required outcomes, confirmed in writing before we start. It moves only when scope does — and scope only moves at a gate you approve.

03

We recommend “not yet” out loud

If an Enterprise Trust Triage debrief or a DIY quarter serves you better than an engagement, that’s the recommendation. It’s why the advice is worth taking.

04

Built to be left behind

Every engagement ends with a handover your team can run. Retainers are an option, never a dependency.

05

Evidence over adjectives

We don’t say “secure”. We produce artifacts a buyer’s security team can review — and we rehearse the review before it counts.

Where the practice comes from

Disciplines, not job titles.

Public-sector delivery experience

Founder experience includes public-sector environments where documentation, accountability and audit are the operating norm.

Enterprise cloud architecture

Hands-on design of the platforms enterprises run on — the same foundations their security teams probe.

Security & compliance practice

SOC 2 and ISO 27001 readiness treated as an operating program, not an annual scramble.

AI governance

Early practice in the discipline enterprises are now writing into procurement: model risk, provenance, oversight.

Representative engagements

The pressure, the work and the result.

Anonymized examples from prior principal-led consulting experience. They do not imply undisclosed EK Treasure corporate client engagements.

REPRESENTATIVE PRINCIPAL-LED ENGAGEMENT · PRIOR CONSULTING EXPERIENCE

Approximately 2.5 million dollars in commercial value faced SOC 2 pressure.

The pressure
A client had committed to SOC 2 Type II but had not completed the program. Two major telecom customers tied preferred-vendor status or renewal to visible progress.
What principal leadership did
Readiness assessment, control-gap identification, remediation planning, policy and control work, evidence preparation, management coordination and audit-readiness support.
The result
The organization reached readiness in approximately three months and later completed a clean SOC 2 Type II audit after the required operating period, supporting customer renewals and restoring confidence.

REPRESENTATIVE PRINCIPAL-LED ENGAGEMENT · PRIOR CONSULTING EXPERIENCE

An eight-month contractual window needed a credible readiness path.

The pressure
A client faced SOC 2 and contractual compliance pressure with a defined delivery window and competing implementation priorities.
What principal leadership did
Current-state assessment, roadmap creation, prioritization and readiness planning aligned the work to ownership and business urgency.
The result
The engagement produced a current-state assessment and prioritized readiness plan. No certification, audit or commercial outcome is implied beyond those verified work products.

The best way to evaluate an advisory firm is to ask it a hard question.