Trust center

Digital Consulting, Inc., vendor information

Most engagements pass through vendor onboarding before the first invoice. The company details, the documents, and the security answers that step asks for are on this page, so your procurement, legal, and finance teams can work while the scope is still being written.

Please send requests to info@dcicyber.com. If we are asked for confidential information, we will need a mutual NDA in place first.

A shorter path for small teams

None of this is a prerequisite. If your company has no vendor onboarding process, a mutual NDA and a signed statement of work are enough to start, and everything below is here for the day you need it.

Ask for the NDA

Entity

The contracting entity

Legal nameDigital Consulting, Inc.
Entity type California corporation, S corporation election in effect
Incorporated28 January 2005, California
Secretary of State entity number2732543
D-U-N-S06-707-8722
Los Angeles business tax Account 0002243519-0001-1, active
Governing lawCalifornia
Tax identificationOn the W-9, issued on request
Mailing address P.O. Box 227
Woodland Hills, CA 91365-0227
United States
Telephone +1 (818) 359‑2645
General enquiries info@dcicyber.com
Security reports security@dcicyber.com, OpenPGP key

The entity number above can be checked in the California Secretary of State business search.

Documents

Onboarding documents

Document How to get it Typical turnaround
W-9 Email info@dcicyber.com. Same business day
Certificate of insurance Issued by the carrier, naming your organization as certificate holder. 2 business days
Proof of registration California Secretary of State business search, entity number 2732543. Public record
Mutual NDA Signed before any sensitive detail is discussed. We issue our own, and can work with yours. Same business day
Consulting services agreement A master agreement with a statement of work for each engagement. We issue our own, and can work with yours where your process calls for it. Same business day
Data processing addendum Executed where an engagement involves personal information. We can work with yours. On request
Security policy Provided under NDA. 2 business days
Security questionnaires Completed and returned in your format. 5 business days

Turnaround covers issuing a document. Where one is redlined, timing follows the negotiation.

Insurance

Insurance

Coverage Professional liability, errors and omissions, including cyber liability. The policy's schedule of insured services names cyber security consulting.
Carrier National Liability & Fire Insurance Company, a Berkshire Hathaway company, written through biBerk. NAIC 20052.
BasisClaims-made
Limits Stated on the certificate of insurance, issued on request.
Certificate ACORD 25, issued by the carrier and naming your organization as certificate holder.

Process

Engagement process

The same four steps run every engagement, and each one ends with something in writing.

  1. Discovery and scoping

    We start by understanding your environment, data, business objectives, and protection needs. Together, we define the engagement's goals and scope. If sensitive information needs to be shared, we will put a mutual NDA in place first.

    What you get: a proposed scope, approach, timeline, and fee estimate, plus a mutual NDA when needed.
  2. Agreement and preparation

    We document the scope, deliverables, responsibilities, timeline, and fees in a consulting services agreement and statement of work. We also complete any required onboarding and prepare for the engagement.

    What you get: an executed consulting agreement and statement of work, along with a W-9, certificate of insurance, and other agreed onboarding documents.
  3. Execution and communication

    We begin with a kickoff to confirm priorities, responsibilities, access requirements, and communication channels. If the work involves access to your systems or code, we also establish clear boundaries and escalation contacts. Throughout the engagement, we share progress and raise important issues early.

    What you get: a structured kickoff, clear points of contact, progress updates, and early notice of significant issues.
  4. Results and next steps

    We deliver the agreed-upon work and walk your team through the findings, recommendations, and priorities. Our materials are designed for both technical teams and executives, with practical next steps your organization can act on.

    What you get: the deliverables defined in the statement of work, a walkthrough of the results, and prioritized recommendations and next steps.

Security

Security practices

We take reasonable steps to protect your information before, during, and after an engagement. More detail is available in our security questionnaire under NDA. For any security-related issues, see our security contact information.

Governance

We maintain written security policies and review them periodically. We can provide relevant policies under NDA or complete your security questionnaire in your preferred format.

Incident response

We maintain a written incident response policy. If we confirm an incident affecting your confidential information in our possession, we will notify you without undue delay and cooperate with your investigation, as provided in our agreement.

Client material

We exchange client material through a dedicated, access-restricted SharePoint site managed by Digital Consulting, Inc., or another secure method we agree on with you. Access is limited to people working on the engagement. When the work is complete, we will return or securely delete the material upon written request. Work is performed in the United States unless we agree otherwise in writing.

AI tooling

We may use business-grade AI tools to support certain client engagements. Their use is governed by our information security policy, the applicable client agreement, and any instructions from the client. We use company accounts and services subject to commercial terms. Under those terms, providers do not use submitted content to train their models, and our agreement with each provider includes a data processing addendum with standard contractual clauses.

We do not submit restricted information or protected health information to AI services. Personal accounts are not approved for company or client data. Before submitting client material, we check the engagement terms and any NDA for restrictions on third-party disclosure or requirements to approve subprocessors.

We identify the providers we use, along with relevant plan and retention details, in our security questionnaire responses under NDA.

Commercial

Contracting and payment

Contract forms A consulting services agreement with a statement of work for each engagement.
Engagement models Fixed-scope assessments, retainer and ongoing support, and project-based programs. The commercial structure follows the engagement, and time and materials, fixed fee, and monthly retainers are all workable.
Fees Quoted per engagement in the statement of work, exclusive of taxes, in US dollars.
Payment terms Net 30 from the invoice date unless the statement of work says otherwise.
Purchase orders Customer purchase orders are accepted. If your organization requires one for procurement or invoice processing, please provide it before services begin.
Purchasing portals If your procurement process requires a purchasing portal, we will work with you to accommodate that where feasible.
Payment instructions Payment instructions are never changed by email. Confirm any such request by telephone, on a number you obtain independently of the message.

Contact

Document requests and questions go to info@dcicyber.com. Vulnerability reports about our own systems go to security@dcicyber.com, and you can encrypt them with our OpenPGP key.

RSA 4096, uid Digital Consulting, Inc. - Security <security@dcicyber.com>
Fingerprint 1EA7 39A9 7D92 3401 41BC D383 63D2 784C A98C 0C6F

Mailing address

Digital Consulting, Inc.
P.O. Box 227
Woodland Hills, CA 91365-0227
United States

Request the onboarding pack Book a consultation