None of this is paperwork for its own sake. Every deliverable below exists because the alternative — an undocumented gap, an unverified vendor, an unmonitored portfolio — costs a specific, predictable amount more than building the record does.
An operator with zero documentation has uncapped exposure in a negligent-security suit — those settlements routinely run into seven figures. This tier exists to put a ceiling on that exposure before an incident, not after one.
A structured, on-site review — fencing, lighting, entry points, key and fob control, camera coverage, closing procedures — documented with photographs, dated findings, and a prioritized remediation plan across three tiers: immediate/no-cost, near-term, and capital. Every finding is scored, evidenced, and signed by the certified principal. This is not a walk-through with a clipboard; it is the first page of a record built to be read aloud in a courtroom.
For houses of worship and religious schools, this isn't an optional add-on — a vulnerability assessment is a mandated attachment to the federal Nonprofit Security Grant Program application. Findings are mapped directly to fundable line items, so the application reads as specific and well-supported rather than generic.
Independent review of an incident, the site, and the existing security posture; a written expert report suitable for discovery; deposition availability; trial testimony if the matter proceeds. This is the single best proof of everything else on this page — an attorney who watches the principal hold up on cross refers the next client before litigation ever starts.
Most operators are already paying a guard, camera, or monitoring vendor every month, with nobody independently checking whether that money buys actual performance. This tier isn't a new cost stacked on top of security spend — it's an audit of money already going out the door.
The rulebook your own staff follows: opening and closing procedure, key and fob control, incident escalation with a named chain, duress response, contractor access. We then train your staff on it directly and keep a signed attendance record — the piece most operators skip, and the piece that matters most in a deposition. It's also the same document your broker brings to underwriting for a premium credit.
Scheduled resurveys against the written standard, a site-score trend over time, quarterly findings on what the vendor fixed and what's still open, and a direct line to the principal between cycles. This is the recurring core of the practice — an advocate on your side of the table who wrote the standard your vendors are held to, and keeps checking.
A defensible, competitive process for hiring or replacing a guard, camera, or monitoring vendor — scope of work, bid comparison across at least three vendors, and a written recommendation from someone with no financial stake in who wins. You contract directly with the vendor; we never appear in that chain.
The independence rule, stated plainly: no compensation from any vendor, ever, in any form — no referral fees, no kickbacks, no cut of a contract we recommend. We are advisory only. We never staff guards, and we never take custody of a post. The only reason a client trusts our recommendation is that we are paid by them, and only by them.
Across a portfolio, liability accumulates silently at every site nobody is tracking — and one lawsuit at any single location costs more than the entire program. This tier replaces per-site guesswork with one archetype-based standard applied consistently everywhere.
One deep archetype assessment per site pattern, a written portfolio standard built from those findings, a standardized survey rolled out to every remaining location, scheduled recurring rounds, and an annual portfolio report — the single most valuable artifact for a healthcare risk manager or a dealer principal, showing the whole book scored and trended year over year.
Not one guard, not for a weekend. The moment we put a body on a post, we're a guard company — a different license, different insurance, and a defendant in the lawsuits we're supposed to protect clients from.
No referral fees, no commissions, no financial relationship with any vendor we recommend or oversee. This is the first question a plaintiff's attorney asks, and the answer is always a clean no.
Physical security only — not IT, not cybersecurity, not building maintenance. If something falls outside our scope, the report says so and the client is pointed to the right person.