A 60-person SaaS company had never been through a SOC 2. Their security posture was ad hoc, their policies were templates from the internet, and they had an enterprise customer deal contingent on a Type II report. We built the entire program from scratch — scoped controls, wrote policies, stood up evidence collection, and liaised directly with their auditor.