Rates and margin. Enforced on the server.
Who may see rates and margin is granted by the owner and enforced on the server. Client names never leave your tenant.
Industries · Security consultancies and vCISOs
YSecurity built Ceed to run its own books: capped retainers, engineers across clients, contractors paid from the same hours. We run on it today.
The record YSecurity runs on. Not a demo tenant.
22.0 of 20 h
Mon 9 Mar · 2.0 h · Phishing incident triage · Alex D.
Held for approval. 2.0 h over the client’s budget.
$6,000
the monthly fee
20 h
the hours behind it
$300
the hour past it
$6
Ceed, this month
A vCISO retainer is twenty hours a month until a phishing email lands and the month is gone by the ninth. Every hour of the response is on the record. The one that crosses the cap waits for a decision, and the client hears about the extra before the invoice, not on it.
The hour that would push a client over budget is saved, marked, and waits for a yes or no. Nothing is billed quietly. Nothing disappears.
2.0 h · Kestrel Medical · Incident triage
Over the 20 h budget. Waiting for Dana.
On the March invoice, at $300 an hour.
Who may see rates and margin is granted by the owner and enforced on the server. Client names never leave your tenant.
The tester’s payout statement is computed from the entries the invoice used. One log, two documents.
Tickets, chat and your compliance tooling stay where they are. Ceed is the record of hours and money they work from.
Computed from the agreement dated 15 Sep 2025. Nothing typed.
What security consultants and vCISOs say in public about capped retainers, incident hours and pricing. Linked and dated. Not our words.
Arguably pentest pricing should be decided after the engagement. … I’ve tested small apps / networks with a ridiculous number of vulns. I’ve tested huge apps / networks that were amazingly secure.
No doubt pentest pricing is all over the place and of course it varies depending on the engagement. From premium to super cheap.
But the price of a pentest, in my opinion, should not be solely dependent upon static numbers like IPs. Just because theres only a handful of IPs doesn’t mean the effort is small.
RiskAware’s fractional vCISO service operates on a virtual retainer model that allocates a bucket of hours you can apply to capabilities as you see fit.
Invoice $6,000 this month for Kestrel Medical Devices and Ceed costs $6. A month you invoice nothing costs nothing. No seats, no tiers, no minimum.
No. The hold holds the billing question, never the work. The hours are logged and held, and a named person decides in the morning.
In your tenant, on Google Cloud. Client names never leave it. Rates and margin are visible only to the people you grant, and the server enforces it. Write to hello@ceed.so for the security posture in full and a person replies.
No. Tickets stay where they are. Ceed is the record of hours and money: the cap, the hold, the invoice, the payout, the close.
Yes. Payout statements come from the same entries as the invoice.
No. The hold is yours. The client sees what the agreement puts on the invoice.
From the blog: Held. Not hidden. The agreement said 40 hours. The month said 47. Other firms Ceed is for: Security MSSPs · IT MSPs · IT consulting · all nineteen.