About Us

We're called Compliance Simple because that's where most clients start. What we actually build is a security program that makes compliance a byproduct rather than an objective.


Founders

Both founders on every engagement.

No junior handoffs, no account managers. You work directly with the people who built the company.

Eugene De Fikh

Eugene De Fikh

Founder & Fractional CISO

Eugene leads security strategy, compliance program design, and the relationship with auditors and enterprise buyers. For the past 15 years he has worked with growth-stage companies feeling security pressure for the first time, turning that pressure into structure. He builds security programs that hold up under scrutiny and support revenue instead of blocking it.

LinkedIn
Oren Golan

Oren Golan

Co-Founder | Engineering Leader | Ex-Amazon

Oren handles engineering, product security, and the automation that eliminates the manual work most firms still do by hand. He spent years building secure, scalable applications at Amazon and multiple startups. He still writes code, which means he speaks the same language as the engineering teams he partners with.

LinkedIn
Ben the Boston Terrier

Ben

Employee #1

Ben is a Boston Terrier who has been with Compliance Simple since day one. He attends every meeting, reviews every document (by sitting on the keyboard), and provides morale support during late-night audit prep. His security clearance is pending, but his commitment to the team is unquestionable.

What We Do

Security programs that hold up under scrutiny.

We build the architecture. Compliance is a byproduct.

01

Security Architecture & Compliance

SOC 2 readiness, security program design, policy frameworks, and vendor risk management. We architect the foundation so compliance is a natural output.

02

Security Operations & Leadership

Fractional CISO services, incident response planning, security team mentorship, and board-level reporting. Continuous security leadership without the full-time hire.

03

Technical Security & Engineering

Cloud infrastructure hardening, CI/CD pipeline security, access control architecture, and technical risk assessments. Hands-on engineering that closes the gap between policy and practice.


Ready to get started?

Book a 30-minute intro call. Both founders will be on the line.

Book an intro call