About

A paladin is bound to a code, not a client.

The name comes from the medieval champion — a defender sworn to a duty, not to whoever’s paying that week. That’s the standard we hold assessments to: a plan fiduciary’s duty is to participants, not to the service provider filling out the paperwork, so the assessment answering to that duty can’t be graded by the party with an interest in a good score.

Why this exists

The DOL wrote the standard. Almost nobody is actually being held to it.

In 2021 the DOL’s EBSA published twelve cybersecurity best practices for plan service providers. In 2024 it clarified those practices apply to every ERISA plan, not just retirement plans. In 2026, cybersecurity became EBSA’s top-listed national enforcement priority. The obligation has existed for years — what’s new is that it’s finally being checked.

Most of what plans get in response is a service provider filling out a generic security questionnaire about itself. That tells a trustee the questionnaire was completed. It doesn’t tell them the controls actually exist, and it isn’t mapped to the specific practices the DOL wrote.

What we actually built

Not a licensed platform. Not a self-graded checklist.

DOL-native, not generic

Twelve domains, mapped directly to EBSA’s own guidance — not a generic NIST or ISO checklist repurposed for retirement plans.

Rubric-graded, not self-graded

A published, deterministic rubric scores every answer the same way twice, and the evidence-quality layer grades whether a written justification is specific or vague — a claim alone isn’t enough.

We own it, not license it

The question bank and scoring engine are ours — built for this problem, not a third-party platform repackaged with a markup.

Get a defensible answer before your next audit does.

Start an assessment