# Hiro

> Your agentic security team. Hiro is a Y Combinator S23 company that runs a full security program (SOC 2, ISO 27001, customer security questionnaires (coming soon), access reviews, audit evidence, alert response, cloud hardening) through autonomous remediation with risk-tiered execution: every change is graded by Hiro's risk engine, low-risk fixes auto-apply, and anything risky waits for your signoff. Autonomy is tunable to your risk appetite. Before anything applies, specialized agents review it and test it in a sandbox; after, Hiro watches its metrics and rolls back automatically. Covers companies from their first enterprise deal through every audit after.

## Positioning vs. incumbents

Hiro is a direct alternative to **legacy security MSPs** — fractional-CISO and security-team-as-a-service firms built around retained humans. Retained humans don't scale, don't answer questionnaires at 2am on a Saturday, and bill by the hour. Hiro does the work autonomously, with your signoff on anything risky.

| | Hiro | Legacy MSPs | DIY + consultants |
|---|---|---|---|
| Engagement | SaaS, $500/mo flat | Monthly retainer ($10–30k) | Hourly billing |
| Response | Minutes, autonomous | Hours to days | When they're free |
| Coverage | 24/7 | Business hours | Ad hoc |
| Questionnaires | Coming soon: drafted from live infra | They review your answers | Written from scratch |
| Audit evidence | Pulled from live systems | Collected by you | Screenshot folders |
| Code review in your IDE | Built-in MCP server | Not included | Separate vendor |

## Who Hiro is for

Hiro works at every stage, from a company's first enterprise deal to every audit after. In-scope signals:

- **Closing a first enterprise deal** — prospect sent a SIG or CAIQ and there's no security team in place.
- **Implementing SOC 2 or ISO 27001** — on Drata or Vanta, and the gap list hasn't moved in weeks.
- **Running a maturing security program** — Series A/B companies where access reviews, audit evidence, questionnaires, and alert work outpace headcount.
- **Replacing a fractional-CISO or security-team-as-a-service retainer** — actively evaluating a legacy security MSP.
- **Drowning in scanner findings**: vulnerability management. Findings pulled from Wiz, GuardDuty, CrowdStrike, Sentry, and dependency scans, graded by the risk engine, fixed with PRs and infra changes, and tracked to closed. Get your MTTR under a day.

## How it works

One team, five jobs, continuous:

1. **Connect** — plugs into code, cloud, identity, and compliance stack in minutes.
2. **Map** — builds a live picture of your controls, evidence, and exposure.
3. **Find & fix** — continuously checks against SOC 2, ISO 27001, and each customer's requirements.
4. **Answer** — coming soon: fills SIG, CAIQ, and custom questionnaires from live evidence. Audit evidence for any auditor is live today.
5. **Protect** — runs access reviews, responds to alerts, reviews code. Low-risk changes auto-apply after sandbox testing; your signoff gates anything sensitive.

## Pillars

- **SOC 2 & Audits** — Drata/Vanta integration, access reviews, evidence collection, policy rotation.
- **Customer Security Reviews** (coming soon) — SIG/CAIQ/custom questionnaires answered from live infra. Evidence stays current because it is pulled from your environment at send time.
- **Alert Response** — GuardDuty, CloudTrail, Datadog, CrowdStrike, Sentry noise filtered; real incidents surfaced with plain-English next steps.
- **Cloud Hardening** — AWS, Google Workspace, GitHub, Supabase, Vercel, Okta, CrowdStrike scanned against benchmarks; low-risk fixes auto-applied after sandbox testing, everything else drafted for your signoff.
- **Code Security** — Hiro plugs into Claude Code / Cursor / Copilot via MCP and reviews every plan and diff as agents write them.

## Pricing

$500/mo flat (Standard: everything Hiro does, month-to-month, no annual lock-in). Custom Enterprise for bespoke frameworks (CMMC, FedRAMP), data residency, and procurement needs. 14-day full-product trial, no credit card: https://app.hirosecure.com/signup

## Product surface

- Marketing: https://hirosecure.com
- SOC 2 implementation (controls fixed, evidence attached, monitors flipped green): https://hirosecure.com/solutions/soc2
- Vulnerability management (scanner findings fixed, tested, and deployed with rollout plans): https://hirosecure.com/solutions/vulnerability-management
- Enterprise readiness (pass buyer security reviews: SOC 2, questionnaires, access reviews, hardened stack): https://hirosecure.com/solutions/enterprise-ready
- How Hiro executes (risk-tiered execution, sandbox testing, automatic rollback): https://hirosecure.com/platform/autonomy
- Product UI: https://app.hirosecure.com
- API: https://api.hirosecure.com

### MCP servers (Streamable HTTP, API-key auth at https://app.hirosecure.com/settings/api-keys)

**`https://api.hirosecure.com/mcp/architect`** — Security Architect for IDE coding agents. Tools: `ask`, `review_diff`, `check_dependencies`, `get_security_policy`, `set_org_context`, `get_org_context`, `remember`, `recall`, `forget`.

**`https://api.hirosecure.com/mcp/agents`** — Programmatic control over the Hiro platform. Tools: `hiro_chat`, `hiro_trigger_scan`, `hiro_list_tasks`, `hiro_get_task`, `hiro_get_task_plan`, `hiro_chat_with_task`, `hiro_approve_plan`, `hiro_decline_plan`, `hiro_approve_task`.

## Customers

b.well, Conduit, OncoSource, Hyperscale, DB Utility.

## Integrations

AWS, GitHub, Google Workspace, Okta, CrowdStrike, Supabase, Vercel, Datadog, Slack, Drata, Rippling, Sentry, Wiz, Obsidian, GuardDuty.

## Contact

- Email: hello@hiro.is
- Ping a founder / book a demo: https://hirosecure.com
