Security advice from the people who do the work
verrou is a boutique security consultancy built on a straightforward premise: the person who scopes your engagement should be the person who executes it and writes the report. No junior bench, no handoffs, no filler.
Why verrou
verrou (pronounced veh-ROO) — French for "lock" — was founded on a simple idea: security advice should be direct, practical, and delivered by the person who actually does the work.
verrou is led by cybersecurity practitioners with experience across offensive security, security leadership, and compliance. Every engagement is scoped, executed, and reported by senior hands — no handoffs to a junior team, no bloated staffing, no boilerplate copied from the last client’s report.
That model is deliberate. When a senior practitioner owns the work end to end, findings are sharper, context is never lost in a handoff, and the recommendations you get are ones we would act on ourselves. You talk to the people testing your systems, not an account manager relaying messages.
We work best with growing companies that need serious security outcomes — Post-Quantum Cryptography Readiness, AI Security, or Product Penetration Testing — without enterprise-consultancy overhead. If you want plain-language answers and a partner who stays close to the technical detail, that’s exactly what we built verrou to be.
Senior practitioners, no junior bench
Every verrou engagement is delivered by experienced hands. Here is the team behind the work.
Nathan LaFollette
Business Development Advisor
Nathan advises executives on Post-Quantum Cryptography Readiness and AI Security. Over three decades he has built global security programs and managed multi-million dollar contracts, with a proven track record of significantly improving margins. He has led teams running over 1,200 Offensive Security Assessments a month to the Fortune 10.
Chesley Moodley
Technology Advisor
Chesley spent more than 15 years moving from core infrastructure and security operations to leading teams that build B2B software. Companies bring him in to make AI and security ideas commercially defensible. He is most useful where deep technical work has to be explained to the people deciding whether to fund it.
How we operate
A few commitments that shape every engagement.
Senior hands only
The people who scope your work are the people who execute it. No junior bench, no handoffs, no learning on your systems.
Plain-language reporting
Findings you can act on, written for the people who have to fix them — clear severity, real-world impact, and concrete next steps, not a wall of scanner output.
Fix-and-verify
We don’t stop at the finding. We help you prioritize remediation and re-test the fixes, so you close the gap rather than just documenting it.
No lock-in
No proprietary black boxes and no dependency you can’t walk away from. You keep the artifacts, the context, and the knowledge to run with them.