We serve as your external audit partner to certify you against the best practices your customers expect.
Our experts tailor the controls to match your business needs in preparation for your audit period.
We serve as your external audit partner to certify you against the best practices your customers expect.
Founder & CEO
READ MORE →
Technology Trust Services
READ MORE →
Technology Trust Services
READ MORE →
Technology Trust Services
READ MORE →
Decrypt Compliance is a Silicon Valley cybersecurity audit firm specializing in helping high-growth B2B SaaS companies achieve compliance certifications faster.
We support a wide range of security frameworks to meet the needs of our clients. This includes:
We understand that speed is critical for fast-growing businesses. That's why we've streamlined our audit process to deliver results significantly faster than traditional audit firms. We leverage modern technology for tasks like data collection, analysis, and reporting, allowing our team to focus on understanding your business and your compliance frameworks. This combination of automation and human oversight ensures that your audit is completed efficiently and effectively, without sacrificing the quality or rigor of the process.
We keep you informed throughout the process and ensure a smooth experience. Our responsive team is always available to answer your questions.
At Decrypt Compliance, our lean, agile team allows us to provide highly personalized service to each client. Our founder is directly involved in every engagement, ensuring you receive top-tier guidance and a responsive audit experience throughout your compliance journey
Our team understands today's security challenges for B2B SaaS companies. Our approach translates traditional compliance requirements to your modern, cloud-native tech stack. This helps you achieve your compliance goals and improve your baseline security practices by taking credit for the tools you're already using to secure your environment.
At Decrypt, we're committed to being your long-term compliance partner. We don't just focus on getting you through the initial audit – we provide ongoing support and guidance to help you maintain and continuously improve your security posture. When there are industry trends, regulatory changes, we proactively update you on emerging opportunities.
Get Started
Tell us about your company and we’ll get back to you with a clear path to certification – including timeline and pricing.
Raymond Cheng has dedicated his career to advancing the technology compliance profession. With nearly 10 years of experience in security and privacy compliance, including roles at EY and Global 500 companies like Google, Salesforce, and Tencent, Raymond founded Decrypt Compliance to foster trust and accelerate the global economy. He is an active contributor to his field, and serves on the Board of the Rotary Club of San Francisco Bay Area.
Raymond holds CPA.CITP, CISSP, CISA, CCSK, CIPP/E, and ISO 27001 Lead Auditor certifications. He is proficient in English, Cantonese, Mandarin, and Spanish.
"Growth is never by mere chance; it is the result of forces working together"
James Cash Penney
"There are no limits to what you can accomplish, except the limits you place on your own thinking."
Brian Tracy
Lee Govender is a dedicated IT Professional with experience in information security and compliance. Lee has worked in IT Audit and Advisory for major financial institutions in South Africa’s JSE Top 40 and in customer success where he assisted clients with ISO 27001 certifications and SOC 2 reports. Lee’s expertise spans both technical auditing and client relationship management.
Committed to continuous improvement, Lee holds a Microsoft Azure Fundamentals Certificate. Beyond his professional pursuits, Lee is passionate about animal welfare and actively volunteers with the Society for the Prevention of Cruelty to Animals.
"Nothing is impossible, the word itself says ‘I’m possible’!"
Audrey Hepburn
“We are what we repeatedly do. Excellence, then, is not an act, but a habit.”
Aristotle
Jana Storm is a seasoned IT Audit and Risk Assurance professional with extensive experience at PwC, where she specialized in banking and capital markets. Jana’s unique people-oriented approach ensures organizations meet both regulatory and operational standards while fostering positive team environments.
Jana holds a BCom Honours in Management Accounting and is currently pursuing her CIMA qualification. Beyond her professional pursuits, she is passionate about mentoring colleagues and is an avid runner who believes in the power of physical movement to build mental resilience. Jana actively promotes workplace environments where people feel valued and engaged.
"If you want to go fast, go alone. If you want to go far, go together."
African Proverb
"Be yourself; everyone else is already taken"
Oscar Wilde
Lauren Van Niekerk is a dedicated information security professional from the Asset Management Industry. She has experience across various frameworks including ISO, SOC 2, GDPR and CCPA. Lauren is obtaining her Masters in Information Security & Digital Forensics. As part of paying it forward, she regularly donates to the Red Cross Children’s Hospital.
"Great works are performed not by strength, but by perseverance"
Samuel Johnson
Julian Antoniou is an IT audit and security professional with a BSc Hons in Cybersecurity from The Open University UK. Julian has completed various certifications in network security, risk management, and security awareness and is actively expanding his knowledge in IT auditing and compliance standards to support clients in achieving their compliance goals.
Beyond his professional work, Julian believes in the philosophy of “a healthy body, a healthy mind.” He sees discipline in physical health as complementary to discipline in professional development. Julian is fluent in English, has conversational proficiency in Afrikaans, and possesses a basic understanding of Greek.
"Excellence is never an accident. It is always the result of high intention, sincere effort, and intelligent execution."
Aristotle
Marcel Pillay is a seasoned audit professional with extensive experience in various industries including many of South Africa’s JSE Top 40 listed companies. Marcel is a Chartered Accountant (CA(SA)), Certified Information Systems Auditor (CISA) and Certified Internal Auditor (CIA), this broad range of experience across a multitude of industries gives him unique a perspective on risk and how technology can enable business operations while at the same time optimizing controls. Marcel spent 17 years at PwC and as an Associate Director in PwC’s Risk Assurance division, he specialized in SOC and ISAE audit reporting. Outside of the office, he has spends his time cooking for friends and family and believes balance is needed in all aspects of ones life.
"The journey of a thousand miles begins with a single step."
Lao Tzu
Mulisa Ramalisa is a Governance, Risk, and Compliance (GRC) and IT Audit professional with over four years of experience across financial services, technology, and risk control environments. She has worked with leading firms including EY and Deloitte, delivering risk-based audits, evaluating IT and application controls, and advising on governance and security frameworks.
Mulisa holds a BCom in Financial Sciences and a BCom Honours in Internal Auditing from the University of Pretoria and is CISA certified. Her credentials include Microsoft Azure Fundamentals, Identity & Access Administration, SAP Access Control, and data analytics certifications. Passionate about IT, cybersecurity and AI, Mulisa is committed to strengthening governance, enhancing control environments, and contributing meaningfully to the professional and business community.
“Do what you can, with what you have, where you are.”
Theodore Roosevelt
Esther Mkize is an IT Audit professional with approximately five years of experience in technology risk and assurance, primarily within the banking and financial services sector, with exposure to other industries as well. Her experience includes application control reviews, IT infrastructure audits, and IT general controls, developed through her work at SNG Grant Thornton and PwC.
Esther is particularly interested in the intersection of technology risk and governance, and enjoys understanding how systems operate beneath the surface to identify, assess, and manage risks effectively.
Outside of her professional work, Esther values continuous learning and personal growth. She appreciates structured thinking, clear communication, and collaborative problem-solving in everything she does.
“Grounded, intentional, and always evolving”