Cybersecurity and compliance programs that stand up to scrutiny

Data Fiduciaries is a cybersecurity governance, risk, and compliance consultancy based in Dallas-Fort Worth, Texas. We build and assess security programs for growth-stage companies, law firms and legal departments, and established enterprises nationwide, and we lead the response when incidents occur. From SOC 2 readiness and vCISO leadership to regulatory assessments, AI governance, and incident response, we help organizations prove the care they owe to the data entrusted to them.

A confidential conversation with no obligation. Monday to Friday, 9:00am to 3:00pm Central.

Frameworks we work in

  • SOC 2 and ISO 27001
  • PCI DSS and HITRUST
  • NIST CSF 2.0 and CIS Controls
  • HIPAA, GLBA, and NYDFS
  • GDPR and state privacy laws
  • ISO 42001 and NIST AI RMF
  • CMMC and NIST SP 800-171
  • FAIR risk quantification

What we do

Nine practices, one accountable partner

Every engagement is scoped to your objectives, your technology, and the evidence your customers, auditors, and regulators will ask for.

AI Governance

Govern the AI you build, buy, or use: AI inventory, risk classification, ISO 42001 and NIST AI RMF programs, and EU, Colorado, and Texas AI law readiness.

AI Governance

Our standard

An organization's duty of care over data is measured by what it can prove.

Evidence over assertion. Every program we build is designed to produce the evidence auditors, customers, regulators, and courts will ask for, so your security claims can be demonstrated rather than asserted.

Who we serve

Built for three kinds of organization

Growth-Stage Companies

Close enterprise deals with a security program that fits how you build: SOC 2 and ISO 27001 readiness, vCISO leadership, product security, and trust programs.

Read more

Law Firms and Legal Departments

Technical control assessments, consulting and testifying experts, reasonable security opinions, and regulatory inquiry support for law firms and legal teams.

Read more

Established Enterprises

Baseline security maturity, quantify cyber risk with FAIR, report to the board with confidence, and stay current through periodic reassessment.

Read more

Responding to an active incident? Use our emergency incident response page. Confidentiality and engagement terms are established immediately so work can begin.

Start with a confidential conversation

Every engagement is scoped individually and begins with a conversation about where your program stands and where it needs to be. Work is conducted under a nondisclosure agreement and a master services agreement.

Consultations are available Monday to Friday, 9:00am to 3:00pm Central.