Plain-English compliance & security toolkits

Security, made legible.

Practical toolkits that respect your privacy — free self-assessments for the eleven situations small businesses and small product teams meet most, from GDPR and everyday security to the first hours of an incident. Start free — every assessment runs entirely in your browser.

Prefer to read first?

Plain English — written the way a person would actually say it.

"The backup runs. The little icon is green. And no one has ever tried to bring a file back from it."
— from The First 5 Backup Mistakes Small Businesses Make, a free guide. Every toolkit and book reads like this.
Why we exist

Compliance and security advice should not require a six-figure budget.

Most small businesses cannot afford a Data Protection Officer, a fractional Chief Information Security Officer (CISO), or a full Product Security Incident Response Team (PSIRT). They need the same documents, decisions, and routines those roles produce. Ours are built in plain language, priced for one-person operators, and delivered as files they own forever.

Plain English

Acronyms expanded at first use. Jargon softened. Worked examples instead of abstract guidance.

Privacy-first by design

Every free self-assessment runs in your browser. Scores and answers never leave your device.

You decide what to adopt

Every recommendation is optional: a widely accepted way to reduce a common risk. You adopt, adapt, or decline.

Your files, yours forever

One-time purchase. Lifetime access to the files you bought. No subscription. Updates within your edition are free while it is in our catalogue.

Toolkits

Start free with an assessment, then take the kit for your situation.

Every toolkit begins with a free, in-browser assessment and pairs it with a practical, plain-language pack of guides, templates, worksheets, and worked examples. Score where you stand first; then pick up the kit built for the job in front of you. Paid editions are a one-time purchase from $49 — no subscription — backed by a 30-day money-back guarantee.

Eleven situations — find yours below to jump straight to its toolkit.

  1. IA solid security baseline, start to finish.
  2. IIShadow AI is spreading through the business.
  3. IIINobody's tracking what's running in the cloud.
  4. IVThe renewal asked for proof.
  5. VA customer asked for a SOC 2 report.
  6. VIThe last scan found thousands of findings.
  7. VIIA personal-data breach, right now.
  8. VIIIEuropean customers or data, no programme yet.
  9. IXSomething's happening right now.
  10. XA vulnerability report just landed.
  11. XIA customer sent a security questionnaire.
See where you stand — six posture assessments
Flagship Small-Business Security

SMB Security Assessment

For owners of small businesses (2–50 people) and the consultants who serve them.

A 12-question check of the basics — who can log in and how, how your data is protected, whether your backups actually work, and whether your software is up to date. It comes with a full toolkit of policies, templates, and training decks.

Try it free →
AI Security

AI Security Assessment

For the person who owns AI security — often alongside every other job.

A 28-question self-assessment across eight areas, from shadow AI to board reporting. The toolkit adds the inventory registers, policy templates, vendor checks, incident runbooks, and board packs to back it up.

Try it free →
Cloud Security

Cloud Security Assessment

For the people who look after cloud estates — from one account to multi-cloud.

A 28-question self-assessment of how your cloud estate is run today, across ten working parts from identity and inventory to compliance evidence. It includes the registers, runbooks, baseline packs, and board-reporting packs to operate it.

Try it free →
Cyber Insurance

Cyber Insurance Readiness Assessment

For the owner whose renewal just asked for proof.

A 9-question readiness check across the controls carriers actually ask about — multi-factor authentication, endpoint detection, tested backups, and the written incident plan. Ships with the renewal-form decoder, the evidence pack checklist, and the broker call cards.

Try it free →
SOC 2 Readiness

SOC 2 Audit-Readiness Assessment

For the team that just got asked for a SOC 2 report.

A 24-question readiness assessment, grouped into the eight plain-English control areas our checklist covers on the way to a SOC 2 examination: scope, governance, access, change, vendors, monitoring, availability, and evidence. It ships with the checklist, policy set, evidence tracker, and audit-prep kit to close the gaps before you spend $20,000+.

Try it free →
Vulnerability Management

Vulnerability Management

For the people who run scanning, triage, and patching — from IT generalist to programme lead.

A 28-question self-assessment of how your programme runs today, across the eight working parts from asset inventory to board reporting. You also get the registers, runbooks, deadline frameworks, and reporting packs to run it.

Try it free →
Take the kit for your situation
Common questions

The questions people ask before they buy.

Can I see a sample before I buy?

Yes — every product has a free, in-browser assessment, and each offers a free take-away written to the same standard as the paid edition: a tailored guide, a battle-card, or a starter template, sent to an email if you choose to leave one. If you like how it reads, you'll like the toolkit.

What does "files you own forever" mean?

Once you buy a tier, those files are yours to use indefinitely — no subscription, no annual renewal, no per-seat fee, and we never expire or revoke them. Updates within your edition are free for as long as the toolkit is in our catalogue.

What if it isn't for me?

Every paid edition has a 30-day money-back guarantee. Email us within 30 days and we refund in full — no questions asked, no form to fill in.

Do the free assessments send my answers anywhere?

No. Every assessment scores you entirely in your browser — read the page's JavaScript yourself, or watch your browser's network panel while you take one: no request carries your answers or score. A strict Content-Security-Policy (verifiable in your browser's developer tools, under response headers) keeps the page from talking to anyone but us and blocks third-party scripts outright. If you choose to enter your email for a free guide, that email address is the only thing ever sent.

Do you use Google Analytics or other trackers?

No — none of them, and no substitutes. Privacy-first is the architecture here, not a slogan; behavioural analytics would break it.

See all frequently asked questions →

Your assessment data never leaves your device.

All eleven of our free assessments score you locally in the browser. No JavaScript analytics, no tracking pixels, no third-party trackers, no server that sees your answers. That holds even for the two tactical assessments where you're entering details of a live incident. If you choose to enter your email to receive a free guide, only that email is transmitted, nothing else.

About us

Built at Sylvan Assurance — the toolkits we wish had existed earlier.

Sylvan Assurance, LLC publishes compliance and security toolkits drawn from widely recognised standards. These include General Data Protection Regulation (GDPR) guidance and the National Institute of Standards and Technology (NIST) Cybersecurity Framework. They also include the Forum of Incident Response and Security Teams (FIRST) PSIRT Services Framework. We translate them into plain language for organisations that do not have a dedicated compliance team.

We are not a law firm, a security audit firm, or a certification body. We publish working templates and self-assessment tools you can use directly. We are explicit in every document about what those templates are and are not.

Questions? Email support@sylvanassurance.com. You'll get a reply from a person, not an autoresponder.

See where you stand — free, in your browser.

Take the free SMB security assessment →

or find your starting point ↑