Sagentix Cyber & AI
We author the evidence
a governed decision runs on.
For organizations facing a Canadian federal authorization, certification or governance decision, Sagentix authors the evidence the decision runs on.
Sagentix prepares organizations for independent assessment. The party who reviews the work is always someone else — an independent assessor, or the department that grants the authority to operate.
That separation is what makes the work survive the review.
How to check that, rather than take our word for it
Independence is a structural question, not a policy question — so it can be verified.
Ask three questions
Ask any adviser you are evaluating: does the firm, or any affiliate of it, hold an accreditation as a certification body or a third-party assessment organization? Is it pursuing one? And does it, or an affiliate, audit, attest or certify anything for clients it also advises?
Then check the answers
Accreditations are recorded in a public register maintained by the national accreditation body. It takes a few minutes and it does not require anyone’s permission.
Our answers
No certification arm, no accredited laboratory, no assessor accreditation in progress. We author — and the party who judges the work is independent of us, which is what gives it weight.
What we author
Readiness and authoring — the assessment stays with an independent assessor.
Authorization readiness
Security assessment and authorization artifacts, control tailoring against ITSP.10.033 — the catalogue that superseded ITSG-33 Annex 3A on 31 March 2026 — CCCS Cloud Medium readiness at Protected B, and the FedRAMP-recognition path where it applies.
Governance advisory
Artificial-intelligence governance built against the instruments that actually bind rather than the standards that do not; post-quantum migration programmes tied to the Security Policy Implementation Notice in force since 9 October 2025; cyber strategy, architecture and fractional security leadership.
Embedded senior advisory
Cleared, bilingual enterprise-architecture and cyber-governance capacity placed inside federal programmes through a prime.
Where you will want someone else — and we will tell you who
- Perform independent assessments
- Issue certifications
- Operate a security operations centre
- Run penetration tests
For any of these, we will point you to a firm that does them well.
How this practice is priced
Two steps, and the first one is deliberately small.
Step one
A paid pre-qualification, before anyone quotes a programme
Every engagement starts with a scope-fixing first unit at its own fixed price. It produces a scoping memo: a security categorization, the control profile that actually applies, a complexity classification, and the scope the work genuinely needs rather than the one that fits a template.
The fee is credited against the engagement if you proceed within ninety days — the same structure as the Phase 1 entry engagement in the go-to-market practice.
Step two
Then a firm fixed price, or a monthly engagement
Catalogue work sold through a prime is firm-fixed-price in defined blocks. Continuing readiness work is sold as a monthly engagement at one of two levels, scoped by capability rather than by hours:
- ReadinessOne authorization path — control tailoring and requirement traceability, evidence production, and the package itself.
- ProgrammeA continuing programme — several systems or frameworks at once, with continuous monitoring, annual refresh and regulatory liaison.
Why there is no number on this page
We publish a price where we can guarantee the scope. Our go-to-market methodology produces a fixed set of deliverables to a fixed standard, so we can tell you the price before we know anything about you. Compliance readiness does not work that way — the effort depends on your control environment, your cloud footprint and how much evidence already exists. Anyone who publishes a fixed number for that is either quoting a gap analysis or planning to re-scope you later. We start with a paid pre-qualification, and then you get a firm fixed price for the actual work.
Start with the gate, not the proposal.
Thirty minutes. We establish which Canadian gate actually applies to you, what the evidence you already hold is worth against it, and what the elapsed time realistically looks like — including the parts nobody controls.