SOC 2ISO 27001ISO 42001FEDRAMPGOVRAMPTXRAMPHIPAAHITRUSTPCI-DSSGDPRCCPA
SOC 2ISO 27001ISO 42001FEDRAMPGOVRAMPTXRAMPHIPAAHITRUSTPCI-DSSGDPRCCPA
NEWAI-ready and adaptive by default — every engagement we start rolls in best-in-class AI security practice from day one, including ISO/IEC 42001 (AI Management System) readiness.See how
Savannah Research Labs mark
SAVANNAH RESEARCH LABS
SECURITY · RISK · COMPLIANCE · CRITICAL INFRASTRUCTURE
African savannah at dusk — lone acacia treeElephants crossing the savannah beneath KilimanjaroLion resting in golden lightMisty hills at dawn
SAVANNAH RESEARCH LABS INC. — VANCOUVER · TORONTO

Your one-stop shop for AI security, infra and compliance needs.

We take companies from zero to audit-ready. vCISO leadership, compliance programs across eleven frameworks, and applied security R&D — advised by a founder with a peer-reviewed publication record, not a slide deck.

PhD, UBC
Electrical & Computer Engineering
16 papers
Peer-reviewed, ACM & IEEE venues
2 patents
US patents
11 frameworks
From SOC 2 to FedRAMP
3 sites
West Coast Canada to East Coast North America
PARTNERS
Prescient Security
Vanta
KnowBe4
CrowdStrike
Palo Alto Networks
Prescient Security
Vanta
KnowBe4
CrowdStrike
Palo Alto Networks
Prescient Security
Vanta
KnowBe4
CrowdStrike
Palo Alto Networks
Prescient Security
Vanta
KnowBe4
CrowdStrike
Palo Alto Networks
WHAT WE DO

Eight practices. One accountable lab.

Every engagement is led by the principal — the person who writes your roadmap sits with your auditors.

01
vCISO Services
Fractional executive security leadership — strategy, board reporting, and full ownership of your security program.
02
Compliance as a Service
SOC 2, ISO 27001, ISO 42001, HIPAA, HITRUST, PCI-DSS, GDPR, CCPA — scoped, implemented, audit-ready.
03
Public-Sector Readiness
FedRAMP, GovRAMP and TXRAMP authorization strategy, gap assessment and continuous monitoring.
04
GRC Platform Enablement
Vanta, Drata and Secureframe — selection, rollout, evidence automation and continuous compliance operations.
05
Risk & Vendor Management
Living risk registers, third-party due diligence and vendor security reviews your customers can inspect.
06
M&A Security Due Diligence
Pre-acquisition posture assessment, remediation costing and post-close security integration.
07
R&D & Software Engineering
Contract research and secure software development — anomaly detection, ML systems, autonomous platforms.
08
Training & Workshops
Security awareness programs, engineering deep-dives and incident-response tabletop exercises.
VCISO ENGAGEMENTS

Three ways to hire a CISO.

Billed monthly on a quarterly commitment. Taxes extra.

ESSENTIALS
$3,500/ month
For startups that need a security program — and a named security leader — for the first time.
+Security program assessment & 12-month roadmap
+One framework track (SOC 2 or ISO 27001)
+Policy suite authored and maintained
+Monthly leadership briefing
+Vendor security reviews — up to 5 per quarter
+Direct line to your vCISO
MOST ENGAGED
GROWTH
$7,500/ month
For companies whose customers are asking hard questions — and whose deals depend on the answers.
+Everything in Essentials
+Two concurrent framework tracks
+GRC platform operated for you (Vanta / Drata / Secureframe)
+Customer security questionnaires & trust page
+Risk register with quarterly reviews
+Incident response plan + annual tabletop
+Audit representation, end to end
ENTERPRISE
from$15,000/ month
For regulated, public-sector and M&A-bound organizations that need embedded leadership.
+Everything in Growth
+Multi-framework: FedRAMP, GovRAMP, TXRAMP, HITRUST
+Weekly embedded leadership cadence
+M&A due diligence & board advisory
+24/7 incident escalation
+Security hiring support & team mentoring
PEER-REVIEWED FOUNDATIONS

Advice you can cite.

Our methods for intrusion detection, access control and attack recovery were built and defended in the open — at ACM and IEEE security venues — before they were ever billed to a client.

GOOGLE SCHOLAR PROFILE
Vast library shelving with a small art exhibition in the foreground
2024
DeLorean: diagnosis-guided attack recovery for securing robotic vehicles from sensor deception attacks
ACM AsiaCCS
2021
PID-Piper: recovering robotic vehicles from physical attacks
IEEE/IFIP DSN Best Paper Award
2021
Are you for real? Authentication in dynamic IoT systems
IEEE PRDC
2019
Out of control: stealthy attacks against robotic vehicles protected by control-based techniques
ACM ACSAC
2018
DynPolAC: dynamic policy-based access control for IoT systems
IEEE PRDC
2018
CORGIDS: a correlation-based generic intrusion detection system
ACM CCS · CPS-SPC
IN THE NEWS
FEDRAMP 20x · JULY 2026

FedRAMP just opened a SOC 2 on-ramp to the federal market.

NEW · FEDRAMP CLASS A

Under its FedRAMP 20x overhaul — the Consolidated Rules for 2026 — FedRAMP has introduced Class A, an entry-level certification that lets a cloud service provider get listed in the federal Marketplace on the strength of an existing SOC 2 Type II, with no agency sponsor required. Class A is the lowest of four new lettered classes (A through D) that replace the old Low, Moderate and High baselines.

It's an on-ramp, not a destination. A Class A listing places you in the Marketplace's Preparation phase — enough for a federal agency to adopt your service for a low-risk pilot — and starts a two-year clock to earn a full Class B, C or D authorization.

The catch: a SOC 2 Type II makes you eligible, but it doesn't get you across the line. On top of your report you must implement and test roughly 25 mandatory FedRAMP rules and the 20x Key Security Indicators — continuous evidence, identity and access management, change management and incident response — then submit a complete evidence package through the FedRAMP PMO's Program Certification.

Don't navigate Class A alone — let Savannah Research Labs do it for you. Call for an initial consultation on your FedRAMP path: or .

KEY DATES
JUN 25 2026
CR26 published
JUL 1 2026
CR26 takes effect
AUG 3 2026
Class A pipeline opens
AUG 31 2026
Class B & C pipelines open
JAN 1 2027
CR26 mandatory program-wide
Eligible frameworks at launch: SOC 2 Type II, GovRAMP, or an existing FedRAMP Rev. 5 / Ready assessment.

Savannah Research Labs gets you Class A–ready.

This is exactly the preparation we run for you. We map your posture against the Class A requirements, stand up and test the mandatory FedRAMP rules and 20x KSIs, build the continuous-evidence pipeline they demand, assemble your SOC 2 and audit-engagement package, and manage your submission through the FedRAMP PMO — while we operate the SOC 2, ISO 27001 and other frameworks that get you there.

Mehdi Karimi, PhD — Founder & Principal, Savannah Research Labs
FOUNDER & PRINCIPAL

Mehdi Karimi, PhD

Mehdi brings 25 years of experience in security engineering and compliance to every engagement, anchored by a PhD specializing in cybersecurity from the University of British Columbia (UBC). His research on securing enterprise cloud and autonomous systems is reflected in a substantial body of peer-reviewed publications and patents in the field, including a Best Paper Award at IEEE/IFIP DSN.

At Savannah Research Labs, Mehdi leads every engagement personally as a hands-on vCISO — architecting and operationalizing enterprise-grade security programs, and directing multi-framework compliance leadership across SOC 2, ISO 27001, ISO 42001 and FedRAMP, from initial gap assessment and control implementation through formal audit and certification. The focus stays practical: security leadership and compliance outcomes that hold up under real scrutiny.

VCISOGRCARTIFICIAL INTELLIGENCEENTERPRISE CLOUD SYSTEMSLLMCOMPLIANCENIST 800-53
CONTACT

Two coasts. One lab.

WEST COAST HQ — MAILING
Unit 1004 – 555 13th St.
West Vancouver, BC V7T 2N8
Canada
DIRECTIONS
EASTERN OFFICE
34 Willett Cres.
Richmond Hill, ON L4C 7W1
Canada
DIRECTIONS
CENTRAL LAB
62 McCallum Dr.
Richmond Hill, ON L4C 7T5
Canada
DIRECTIONS
Savannah Research Labs Inc. — incorporated under the Business Corporations Act (British Columbia) · BC1402762 · est. February 2023
© 2026 · All rights reserved