Do you provide formal attestation?
No. MKDC engagements deliver advisory documentation, not formal attestation. You receive a reproducible witness bundle — any third party can re-derive every conclusion — but we do not sign attestations or substitute for independent auditor judgment.
What's included in an engagement?
Discovery & documentation, Recovery runbooks & DR analysis, and Compliance are delivered together in 4–6 weeks:
Discovery & documentation
- Validated inventory and L2/L3 topology
- Cross-tier dependency map validated end-to-end
Recovery runbooks & DR analysis
- RTO/RPO matrix and prioritized DR gap analysis
- Recovery runbooks ordered by the dependency map
Compliance
- Automated compliance reports with per-framework gap analysis for every supported framework
- Board-ready executive summary
- Reproducible witness bundle — any third party can re-derive every conclusion
Which compliance frameworks do you support?
We deliver automated compliance reports with per-framework gap analysis with subset mapping per framework for:
- FFIEC BCM Booklet
- SOC 2 — Common Criteria 9 (Risk Mitigation / BCM)
- SOX ITGC (recovery + change-management subset)
- HIPAA Security Rule §164.308(a)(7) Contingency Plan
- HHS 405(d) HICP — Resilience subset
- ISO 22301:2019 — BCMS operational subset (crosswalk)
Each engagement includes a cross-framework index and evidence bound to the captured estate in the witness bundle. Full control catalogs are scoped in the SOW.
Who is this for?
Security and compliance leaders who sponsor an engagement when a calendared DR audit or regulatory cycle creates budget and urgency:
- CISO
- Head of Risk
- IT Compliance leader
- Director of Internal Audit
Operations teams provide access and validate output during the engagement. MKDC scopes and delivers the audit artifact set your committee needs.
Our operational documentation does not match what is running — can you help?
Yes — that gap is why security and compliance leaders engage us before an audit cycle. We map what is actually running via read-only API capture — networks, compute, storage, and dependencies — and deliver validated inventory, topology, and a dependency map tied to recovery runbooks and automated compliance reports with per-framework gap analysis. Your operations teams fill in business context through guided follow-ups we structure for them.
How do you document an estate when runbooks and topology are stale?
Read-only API capture from management planes — vCenter, switches, storage, OOB — not interviews alone. MKDC normalizes that into inventory, L2/L3 topology, and a cross-tier dependency map validated before publish. Your operations teams document intent — what is critical, who owns it — through guided follow-ups we structure for them.
We have stale runbooks and topology diagrams — can you replace them with something current?
Yes — not by redrawing old diagrams or copying outdated docs. We capture what is running today and replace stale topology diagrams and runbooks with capture-derived deliverables:
- Validated inventory and L2/L3 topology derived from read-only capture — not hand-updated diagram files
- Cross-tier dependency map validated end-to-end
- Recovery runbooks ordered by the dependency map
- RTO/RPO matrix and prioritized DR gap analysis
- Reproducible witness bundle — any third party can re-derive every conclusion
Where vendor coverage is partial, every deliverable labels what was captured and what was not.
Can you resolve production vs. non-production for audit scope?
We document what is running and how it connects from read-only API capture. Labeling production workloads, application ownership, and business criticality requires context your operations teams hold. We structure follow-ups so they can enrich the map with the labels your audit committee needs — instead of guessing under exam pressure.
What if our vendor mix isn't fully covered?
We run a short qualification conversation before any SOW. Estates with partial coverage receive a reduced-fee engagement with every deliverable clearly labeling what was captured and what was not. Estates outside current coverage go on a wait-list — and inform our vendor coverage roadmap directly.
Do you change anything in production?
No. Capture is read-only via authenticated access to management APIs only — vCenter, network device APIs, storage controllers, OOB — with no agents installed on production workloads. Zero production interruption is a core requirement of how we built the product, not a best-effort claim.
We already have discovery or CMDB tooling — do we still need MKDC?
Often yes, for different reasons. Discovery tools and CMDBs give you ongoing maps you operate day to day. MKDC delivers audit-grade capture in one engagement: cross-tier validation, recovery runbooks, automated compliance reports with per-framework gap analysis, and a reproducible witness bundle. We complement daily ITSM when the gap is audit documentation — not when you only need a live dependency dashboard.
When is MKDC not the right fit?
MKDC is for audit-ready DR and compliance documentation on operational data-centers. We're usually not the right fit when:
- You only need a live dependency map or inventory update — not audit-grade documentation before a DR audit or compliance cycle.
- Your scope is cloud-native (for example, SOC 2) with no on-premises data-center for us to capture.
We're a partial fit — not a full substitute — when:
- You need formal attestation signatures or a facilitated DR tabletop exercise today. We deliver the advisory documentation and reproducible witness bundle those reviews depend on; we do not sign attestations or run tabletop exercises ourselves.
Why are discovery & documentation, recovery runbooks & DR analysis, and compliance bundled?
Recovery runbooks and automated compliance reports with per-framework gap analysis are derived from the same validated capture. Splitting the pillars would produce inconsistent or non-reproducible artifacts — recovery runbooks disconnected from the dependency map, compliance gaps without estate evidence. One fixed-fee engagement, 4–6 weeks, one witness bundle.
Where is our data stored during the engagement?
Captures and credentials live in a dedicated engagement environment for the duration of the engagement. Retention, credential rotation, and data-handling terms are documented per customer in the SOW.
Are you insured, and what are your liability limits?
Each engagement runs under a Master Services Agreement with a fixed-scope SOW. MKDC's liability under that contract is capped at the engagement fee. We carry $5–10M aggregate Errors & Omissions coverage, bound before any signed engagement.