You're an agency shipping AI-built apps to clients. Their security questionnaire is your bottleneck.

Updated

Per-client SOC 2 + DPA + AIBOM evidence at agency scale. Securie's attestation chain produces auditor-defensible artifacts per client.

This is for you if…

  • Running a digital agency or contracting solo
  • Shipping vibe-coded apps for clients (Lovable + Bolt + v0 stacks)
  • Clients are mid-market+ B2B who ask security questions
  • Spending hours per project on security questionnaires

The moments you feel this

First client security questionnaire

200 questions per client. Ten clients per quarter. Your weekend goes.

Client asks for AIBOM

You don't know what an AIBOM is. You Google. You realize the EU AI Act Aug 2 2026 deadline applies to your clients.

Client breach traced back to your code

The contract has indemnity clauses. Your weekend goes.

What Securie does for you

Per-client attestation chain

Every PR ships DSSE-signed in-toto v1 attestations. Auditor verifies with cosign verify-blob. Same evidence works for SOC 2 + EU AI Act + GDPR.

Pre-filled security questionnaire

Use /templates/security-questionnaire-response. 80% pre-filled per the canonical SIG-Lite + VSAQ patterns.

AIBOM emission per client release

CycloneDX 1.6 AIBOM on every release alongside the SBOM. EU AI Act Article 11 + Annex IV machine-readable supplement.

What you don't need to know

  • What CycloneDX YAML looks like
  • What in-toto v1 means
  • How DSSE envelopes work
  • What Annex IV section 5 requires

What you actually do

  1. Install Securie on every client repo
  2. Hand the client the auditor bundle URL on contract close
  3. Pre-fill security questionnaires from /templates/security-questionnaire-response

Dozens of agencies use Securie for per-client security evidence at agency scale.

But wait…

Per-client pricing — does it scale?

Securie's Solo Founder ($49/mo) covers 10 repos = 10 clients. Startup ($299/mo) covers 50 repos. Scales with agency size.

Clients want to see evidence themselves

/api/auditor/bundle/<commit> serves the full DSSE-signed bundle. Hand the client the URL.

What about the indemnity clause?

Securie's prove-don't-flag invariant + auditor-defensible chain is the strongest evidence-position you can offer in indemnity disputes.