Security, made legible.
Practical toolkits that respect your privacy — free self-assessments for the eleven situations small businesses and small product teams meet most, from GDPR and everyday security to the first hours of an incident. Start free — every assessment runs entirely in your browser.
Not sure where to start? Tell us what's in front of you.
Pick the situation that looks like yours and we'll point you to the right free assessment — or scroll down to browse all eleven toolkits.
Plain English — written the way a person would actually say it.
"The backup runs. The little icon is green. And no one has ever tried to bring a file back from it."
Compliance and security advice should not require a six-figure budget.
Most small businesses cannot afford a Data Protection Officer, a fractional Chief Information Security Officer (CISO), or a full Product Security Incident Response Team (PSIRT). They need the same documents, decisions, and routines those roles produce. Ours are built in plain language, priced for one-person operators, and delivered as files they own forever.
Plain English
Acronyms expanded at first use. Jargon softened. Worked examples instead of abstract guidance.
Privacy-first by design
Every free self-assessment runs in your browser. Scores and answers never leave your device.
You decide what to adopt
Every recommendation is optional: a widely accepted way to reduce a common risk. You adopt, adapt, or decline.
Your files, yours forever
One-time purchase. Lifetime access to the files you bought. No subscription. Updates within your edition are free while it is in our catalogue.
Start free with an assessment, then take the kit for your situation.
Every toolkit begins with a free, in-browser assessment and pairs it with a practical, plain-language pack of guides, templates, worksheets, and worked examples. Score where you stand first; then pick up the kit built for the job in front of you. Paid editions are a one-time purchase from $49 — no subscription — backed by a 30-day money-back guarantee.
Eleven situations — find yours below to jump straight to its toolkit.
- IA solid security baseline, start to finish.
- IIShadow AI is spreading through the business.
- IIINobody's tracking what's running in the cloud.
- IVThe renewal asked for proof.
- VA customer asked for a SOC 2 report.
- VIThe last scan found thousands of findings.
- VIIA personal-data breach, right now.
- VIIIEuropean customers or data, no programme yet.
- IXSomething's happening right now.
- XA vulnerability report just landed.
- XIA customer sent a security questionnaire.
SMB Security Assessment
For owners of small businesses (2–50 people) and the consultants who serve them.
A 12-question check of the basics — who can log in and how, how your data is protected, whether your backups actually work, and whether your software is up to date. It comes with a full toolkit of policies, templates, and training decks.
AI Security Assessment
For the person who owns AI security — often alongside every other job.
A 28-question self-assessment across eight areas, from shadow AI to board reporting. The toolkit adds the inventory registers, policy templates, vendor checks, incident runbooks, and board packs to back it up.
Cloud Security Assessment
For the people who look after cloud estates — from one account to multi-cloud.
A 28-question self-assessment of how your cloud estate is run today, across ten working parts from identity and inventory to compliance evidence. It includes the registers, runbooks, baseline packs, and board-reporting packs to operate it.
Cyber Insurance Readiness Assessment
For the owner whose renewal just asked for proof.
A 9-question readiness check across the controls carriers actually ask about — multi-factor authentication, endpoint detection, tested backups, and the written incident plan. Ships with the renewal-form decoder, the evidence pack checklist, and the broker call cards.
SOC 2 Audit-Readiness Assessment
For the team that just got asked for a SOC 2 report.
A 24-question readiness assessment, grouped into the eight plain-English control areas our checklist covers on the way to a SOC 2 examination: scope, governance, access, change, vendors, monitoring, availability, and evidence. It ships with the checklist, policy set, evidence tracker, and audit-prep kit to close the gaps before you spend $20,000+.
Vulnerability Management
For the people who run scanning, triage, and patching — from IT generalist to programme lead.
A 28-question self-assessment of how your programme runs today, across the eight working parts from asset inventory to board reporting. You also get the registers, runbooks, deadline frameworks, and reporting packs to run it.
GDPR Breach Response
For Data Protection Officers handling the first 72 hours of a personal-data breach.
A nine-question triage that returns a notifiable-or-document verdict and the Article 33 deadline computed from your awareness time. It also returns the required notification contents and a starter draft you can hand to counsel.
GDPR Checklist
For small businesses with European customers, visitors, or staff.
A 30-question self-assessment that scores your readiness across five areas (data collection, processing, storage, sharing, breach response). Then it walks you through closing the gaps, in order.
First 4 Hours Incident Response
For businesses and product teams handling — or preparing for — an incident.
A branching triage assessment that splits into an infrastructure-incident path and a product-vulnerability path. Returns a four-hour priority sequence, a do-not-touch list, and the legal deadlines that apply.
PSIRT Response
For product-security practitioners, founder-CISOs, and small product teams.
A 17-question readiness self-assessment for receiving and handling vulnerability reports before the first one arrives. It pairs with the working runbooks, communication templates, and regulatory decision trees for when it does.
The questions people ask before they buy.
Can I see a sample before I buy?
Yes — every product has a free, in-browser assessment, and each offers a free take-away written to the same standard as the paid edition: a tailored guide, a battle-card, or a starter template, sent to an email if you choose to leave one. If you like how it reads, you'll like the toolkit.
What does "files you own forever" mean?
Once you buy a tier, those files are yours to use indefinitely — no subscription, no annual renewal, no per-seat fee, and we never expire or revoke them. Updates within your edition are free for as long as the toolkit is in our catalogue.
What if it isn't for me?
Every paid edition has a 30-day money-back guarantee. Email us within 30 days and we refund in full — no questions asked, no form to fill in.
Do the free assessments send my answers anywhere?
No. Every assessment scores you entirely in your browser — read the page's JavaScript yourself, or watch your browser's network panel while you take one: no request carries your answers or score. A strict Content-Security-Policy (verifiable in your browser's developer tools, under response headers) keeps the page from talking to anyone but us and blocks third-party scripts outright. If you choose to enter your email for a free guide, that email address is the only thing ever sent.
Do you use Google Analytics or other trackers?
No — none of them, and no substitutes. Privacy-first is the architecture here, not a slogan; behavioural analytics would break it.
Built at Sylvan Assurance — the toolkits we wish had existed earlier.
Sylvan Assurance, LLC publishes compliance and security toolkits drawn from widely recognised standards. These include General Data Protection Regulation (GDPR) guidance and the National Institute of Standards and Technology (NIST) Cybersecurity Framework. They also include the Forum of Incident Response and Security Teams (FIRST) PSIRT Services Framework. We translate them into plain language for organisations that do not have a dedicated compliance team.
We are not a law firm, a security audit firm, or a certification body. We publish working templates and self-assessment tools you can use directly. We are explicit in every document about what those templates are and are not.
Questions? Email support@sylvanassurance.com. You'll get a reply from a person, not an autoresponder.