Obsidian Ridge

Trust & transparency

Trust & Transparency

Security work only means something if the security company is honest about itself. This page reflects what is true and active today. If something isn't in place yet, it isn't listed here — and if you ever find a gap between what we say and what we do, tell us and we'll fix it.

Aligned with
NIST CSF 2.0ISO 27001SOC 2HIPAAPCI-DSS
CISSP-led — senior practitioner on every engagementHuntress Secure Partner

Who we are

ObsidianRidge.io is operated by Obsidian Ridge LLC, based in Cary, North Carolina.

Principal: Kfir Yair, CISSP. We provide direct communication and accountable delivery.

Contact: security@obsidianridge.io · 964 High House Rd, PMB 2086, Cary, NC 27513 · (984) 999-7785

How we deliver security

We are a boutique practice. We are honest about what that means.

  • A senior operator scopes and performs the work directly.
  • We are not a 24/7 staffed SOC of our own. Monitoring and around-the-clock containment are delivered by the SOC behind the managed detection platforms we operate; escalations come to us and we review them within one business day. We tell you exactly what is covered and what isn't.
  • We tell you when you don't need us. If a problem is a 30-minute fix you can do yourselves, we'll say so.

Partner posture

Huntress Secure Partner

Obsidian Ridge is a Huntress MDR Partner. That means we operate the Huntress Managed EDR, Managed ITDR, Managed Security Awareness Training, and Managed SIEM platforms end-to-end for covered organizations:

  • Deployment
  • Alert triage
  • Escalation handling
  • Incident response coordination
  • Compliance evidence packaging

Huntress operates the 24/7 SOC behind the detection platforms; we add the practitioner program that turns the platform into an outcome.

Huntress Secure Partner

Read the Huntress partner explainer →

Partner posture

Fortinet Partner

Obsidian Ridge is a Fortinet Engage Advocate Partner.

Fortinet Engage Advocate Partner

Sub-processors

Every vendor that touches your data.

Published in full because clients with privacy obligations (HIPAA, GDPR, CCPA) need to list every party that handles their data. Anything not on this list does not see your data. Changes here trigger a 30-day notice to clients before activation.

Sub-processorPurposeData handled
VercelWebsite hostingSite content, form submissions in transit
SupabaseApplication databaseContact, assessment, and calculator submissions
ResendEmail deliveryEmail address, message content
CloudflareBot protection (Turnstile)Connection metadata
NamecheapDomain registration and DNSDomain records only, no customer data
PlausibleCookieless site analyticsAggregate page-view and event counts
ProtonBusiness emailCorrespondence with us

We review this list on a regular basis.

Cross-border note: where a US-hosted sub-processor handles personal data of an EU or UK data subject, the EU / UK Standard Contractual Clauses are incorporated by reference via the relevant DPA.

Where a sub-processor is added or replaced, existing clients receive written notice at least 30 days before activation.

Plausible, our active analytics processor, is EU-based and EU-hosted, keeping visitor analytics within EU jurisdiction and outside the US CLOUD Act's reach.

Payments & contracting

The agreements behind every engagement.

Engagements are governed by a written agreement and, where applicable, a Business Associate Agreement or Data Processing Addendum.

Data residency

Where your data lives.

Application data (briefing requests, assessment responses, newsletter subscribers) is stored in the United States at Supabase (US East). Email delivery uses US-region Resend.

Where a US-hosted sub-processor handles personal data of an EU or UK data subject, the EU / UK Standard Contractual Clauses are incorporated by reference through the relevant DPA. No client data is transferred to a jurisdiction without an approved transfer mechanism in place.

Vulnerability disclosure

Found a security issue? Tell us privately.

We publish an RFC 9116 security.txt at /.well-known/security.txt, and its Policy field points here. Send coordinated vulnerability reports to Obsidian Ridge LLC at security@obsidianridge.io — encrypted over PGP on request. Please give us a reasonable chance to fix an issue before disclosing it publicly.

In scope: this website — obsidianridge.io and its subdomains — and its forms and API endpoints.

Out of scope: any client environment or system we manage on a client's behalf; the third-party platforms we use as sub-processors (report those to the vendor — we'll help coordinate); denial-of-service or volumetric testing; physical attacks; and social engineering of the operator, clients, or vendors.

What to expect: we acknowledge a report within 2 business days, give an initial assessment within 5, keep you updated through resolution, and — with your permission — credit you once the issue is fixed.

Safe harbor: if you make a good-faith effort to follow this policy, we will treat your research as authorized, we will not pursue or support legal action against you for it, and we will work with you to resolve the issue quickly.

We link the sources behind our security and compliance content.

Founder credentials

The practitioner behind every engagement.

Obsidian Ridge is led by a CISSP-certified security practitioner with a decade of cybersecurity experience spanning:

  • The IDF
  • The Israeli Government Tax Authority, as Production Technical Lead
  • Deloitte, in Digital Forensics & Risk Analytics
  • Varonis, as a Cyber Security Architect
  • Cypress Creek Renewables, as a Cloud Security Analyst
  • TEKRiSQ, as Director of Security Solutions

Today he architects security for a large enterprise. Work spans individual protection, small business security, and enterprise environments.

CISSP • CCFH (CrowdStrike) • ZDTA (Zscaler) • CySA+ (CompTIA) • Security+ (CompTIA) • Network+ (CompTIA) • CC (ISC²)

Each credential is verifiable through its issuing body on request. The full bio, employment history, and engagement scope live on the About page.

Operating principles

What we never do.

Sales-driven security firms tend to communicate what they do. We find it more useful to tell you what is off the table — in writing, on a page you can link to and hold us against.

We don't sell, rent, or share client data.

Briefing intake, newsletter sign-ups, and service operational data are used only to deliver the work you hired us for. Our revenue is service fees and channel partnerships — not data.

We don't lock clients into multi-year auto-renew contracts.

Ridge Core is month-to-month. Ridge Plus and Ridge Reserve run on annual terms with an explicit renewal opt-in, not silent auto-renew. You see the renewal date before it happens, every time.

We don't recommend tools we wouldn't deploy for ourselves.

Affiliate and reseller relationships are disclosed at the link, on the privacy page, and at the routing layer (/go/<vendor>). If a payout would change our honest recommendation, we walk away from the deal — not from the recommendation.

We don't fabricate testimonials, case studies, or credentials.

Every case study is real and either named with written consent or anonymized at the client's request. Every credential listed below has a verification path on request. No stock-photo founders, no AI-generated reviews, no inflated headcount.

We don't run cross-site advertising pixels.

No Meta Pixel, no Google Ads remarketing, no X tracking. Site analytics run on Plausible — cookieless, no cross-site tracking, no personal data sold. No third-party advertising trackers reading your visit.

We publish tier prices in public.

Ridge Core $25, Ridge Plus $50, Ridge Reserve $70, each per person per month, and Ridge Log at $8 per data source per month: all listed on /pricing along with fixed onboarding fees and Sprint pricing. No 'call for pricing' gating, no hidden minimums. What's on the page is what the proposal will show.

We don't pretend to be bigger than we are.

Obsidian Ridge is a CISSP-led practice with one senior practitioner on every engagement. We don't claim a 30-person SOC we don't have — Huntress operates the 24/7 SOC behind the detection platforms, and that relationship is named openly on every page that depends on it.

We don't use scare-tactic sales motions.

Briefings are free, 30 minutes, and we tell you when you don't need us. No urgency timers, no fake renewal pressure, no fear-driven upgrade emails. If the fit isn't there, we'll point you to something simpler — no hard feelings.

If you see us doing any of the above, email security@obsidianridge.io and call it out. We'll confirm, fix, or explain — in writing — within two business days.

A note on our published research

What our KEV tracker, advisories, and industry pages are — and aren't.

Our KEV tracker, advisories, and industry pages are informational and reflect the best available public sources at the time of writing. Each links to primary sources. Nothing on this site is legal or compliance advice.

Related policies

Privacy & Affiliate Disclosure

How we handle data, what we collect, the affiliate and reseller relationships behind our revenue, and how we're paid in plain English.

Read the policy →

Terms of Use

The terms that govern the website, the assessment tool, the blog, and the briefing intake — including the DMCA procedure and export-controls notice.

Read the terms →

Refund & Cancellation

How refunds, cancellations, and pro-rations work across Ridge Core, Ridge Plus, and Ridge Reserve, plus the policy for fixed-fee sprints and incident response blocks.

Read the policy →

Accessibility

Our WCAG 2.2 AA target, known limitations, and how to request an accessible alternative or report a barrier — with a two-business-day response commitment.

Read the statement →

Next step

Want to talk?

The briefing is free, 30 minutes, and we tell you when you don't need us. Where an engagement calls for a written agreement, BAA, or DPA, we share the executable version during the briefing.

Not ready to talk? Score yourself first →

Talk with us