Skip to content

How we work

Diagnose, build, run. And never attest to our own work.

Three commercial models, one engagement sequence, and one structural separation that we treat as a feature of the firm rather than a line of small print.

The sequence

The order is not arbitrary.

You can enter at any stage. But building against a gap register you have never seen is how firms end up with an expensive system that closes the wrong things.

01 · Diagnose

Readiness assessment

Two to three weeks. A gap register, a remediation sequence, an evidence inventory and a build recommendation.

Suits Anyone who has not been through operational diligence recently, or who is about to be.

02 · Build

Institutional build

The systems that close the gaps, with control frameworks designed into the schema rather than documented alongside it.

Suits Firms whose process is settled and whose constraint is that nothing produces evidence.

03 · Run

Capital Intelligence Platform

Our own platform, configured for your firm, for the infrastructure without the build.

Suits Firms that want a working control environment faster than a custom build can deliver one.

Commercial models

Three ways to pay for it.

Fixed fee

Diagnostics and most first builds.

A defined scope at a defined price, with the scope written down in enough detail that both sides know what would constitute a change to it. This is how most engagements start and how most of them stay.
Platform licence

Firms that need infrastructure sooner than a build allows.

The Capital Intelligence Platform, configured and run for your firm. Priced per firm rather than per seat, because charging a six-person sponsor by the head penalises exactly the thing you want them to do.
Fee plus participation

A small number of engagements a year.

A reduced fee against a participation in the vehicle. We are selective about this, and it only works where the interests genuinely line up rather than where the fee is simply difficult.

Pricing philosophy

Prices are quoted before work starts and do not move because the work turned out to be harder than we estimated. Where a scope genuinely changes, it is priced as a change and agreed before it begins. There is no hourly billing on the diagnostic.

{{TODO: CLIENT INPUT}} Diagnostic fee, custom build price bands, and CIP licence tiers.

How independence works

We build to the framework. An independent firm attests.

Maxim is a CPA who has signed SOC 2 Type 2 opinions since 2002. That is exactly why Exalto will not audit what Exalto builds. Independence rules prohibit attesting to your own work, and an engagement structured that way would be worth nothing to the LP it was meant to satisfy.

What Exalto does

  • CC5.3EvidencedDesign the control environmentControls are specified against SOC 2 Trust Services Criteria, COBIT, ITIL and NIST CSF before the first schema is written.
  • CC5.2EvidencedBuild the system that enforces themSegregation of duties lives in the permission model. Approval chains live in the workflow. Neither lives in a policy document.
  • CC2.1EvidencedProduce the evidence continuouslyThe system generates the audit trail as work happens, so the evidence exists before anyone asks for it.

What Exalto never does

  • CC4.1OpenAudit or attest to its own workExalto issues no opinion, certificate or attestation on any system it has designed or built. Not on the same engagement, and not on a later one.
  • CC9.2OpenAct as your independent assessorAttestation is performed by a separate firm that you engage directly. Exalto’s own control environment is independently attested by BetterLeg.

Exalto does not describe itself, or anything it builds, as SOC 2 certified or SOC 2 compliant. A system is designed to the criteria; a firm is attested by an independent auditor. Anyone who blurs those two things is telling you something about how they work.

Start where it costs nothing.

The readiness scan is the free version of the diagnostic’s first hour. It is ungated, and the result is yours whether or not you ever talk to us.