About Lantern · Piqua, Ohio

Quiet,
and thorough.

Lantern is one thing done carefully: finding the ways into your systems before someone less friendly does, then writing it down so a person can actually fix it. Here is who's behind that and how we think about the work.

A small consultancy desk at dusk — a laptop terminal, a printed report and a notebook, lit by one warm lamp
One office · S Wayne St · Piqua Request a scope
Hands at a keyboard beside an open security report, lit by a faint magenta screen glow

01 · Why We Started

A thinner report that got read

Lantern began after too many years of watching good work go unopened — 200 pages of scanner output that nobody on a busy team ever had time to sort.

So we kept two things small on purpose: the scope, and the writing. We test the two or three systems that would actually hurt if they broke, exploit what we find by hand rather than trusting a tool's guess, and hand back a document an on-call engineer can follow at 2am. Then we come back and retest once you've patched — that part isn't a second invoice.

We're on S Wayne St in Piqua, and most of the work is remote across Ohio and the Miami Valley. When an engagement genuinely calls for someone in the room, we drive.

02 · What We Hold To

Four things, kept simple

01

The report is the product

Findings written for the engineer who has to fix them, ranked by what an attacker reaches first — plus a summary a board can read without a translator.

02

Fixed scope, fixed fee

Everything is quoted up front against a written scope. If the work grows, we agree on it before touching it. You never open a surprise invoice.

03

We stay out of the audit

The SOC 2 audit itself has to come from a licensed CPA firm — and keeping that separate is the point. We get you ready; someone independent signs it.

04

Small by choice

There's no account manager to route you through. Scoping, testing, and the write-up are the same set of hands from the first call to delivery.

03 · How We Keep Current

Methodical, not mysterious

Testing

OWASP, applied by hand

Web and API work follows the OWASP Testing Guide as a floor, not a ceiling — the interesting bugs live in the logic a checklist skips.

Cloud & Config

Benchmarked, then reasoned

We map cloud and access review against the CIS Benchmarks, then rank findings by what someone could actually reach — not by count.

Compliance

Mapped, not recited

SOC 2 work is mapped to the Trust Services Criteria and HIPAA work to real safeguards, written to survive an actual question rather than tick a box.

Rules Of Engagement

Agreed in writing first

Windows, targets, and boundaries are signed off before anything runs. We avoid destructive tests on production and stay reachable throughout.

After Delivery

A retest, included

Once you've patched, we come back and confirm the fix held. That verification is part of the engagement, not a fresh line item.

Where We Work

Piqua & remote

Based at 435 S Wayne St. Remote across Ohio and the Miami Valley, on-site when the scope makes it worth the drive.

04 · Start The Conversation

Request a scope

Tell us what you're running and what's driving the timeline. We'll reply within one business day with a scope, a fee, and a start date — no sales sequence, no follow-up drip.

Or call (937) 980-9035

05 · The Short Version

One office, four engagements

Penetration tests, security audits, SOC 2 and HIPAA readiness — each fixed-scope and fixed-fee. See exactly what's inside each one and what it costs.

See the services
A single beam of light cutting through a dark, hazy room

06 · Prefer To Talk First

A 30-minute scoping call

Not sure which engagement fits, or whether you need one at all? A short call sorts it. If a test would be overkill, we'll say so.

Call (937) 980-9035
A printed security report open on a desk beside a keyboard, lit by a warm lamp
Call Request a scope