About

Security and private workspaces for organizations that cannot afford to get trust wrong.

Secure Origin helps journalists, mission-driven organizations, underserved businesses, NGOs, and small teams protect sensitive work through managed security services and private workspaces. Press and public-interest work are central to our mission, and the model also fits related organizations with limited internal security or IT capacity.


Our philosophy

Operator-led security with clear scope

Validation-first security

We prove controls through penetration testing, adversary emulation, detection review, restore checks, and operational evidence. If we cannot demonstrate it, we do not claim it.

Security services plus Workspaces

Security services protect devices, people, workflows, and programs. Workspaces give teams a private place to share files, edit documents, organize project materials, and collaborate without turning every request into custom infrastructure.

Small-team focused

We serve clinics, law firms, professional services firms, SaaS teams, nonprofits, newsrooms, NGOs, legal aid teams, and privacy-first teams where a breach or outage creates real stakeholder risk.

Direct and transparent

No account managers and no unnecessary layers. You work directly with senior practitioners, and deliverables, responsibilities, timeline, assumptions, and price are explicit before work begins.


Who runs Secure Origin

Rafael Gutierrez

Rafael Gutierrez
Founder & principal

Rafael founded Secure Origin to give small organizations access to serious cybersecurity through clear packages, practical delivery, and direct senior engineering judgment.

He is a member of The Southlander, a worker-owned newsroom, and works directly with organizations doing community work. That experience shapes how Secure Origin thinks about trust, confidentiality, and security for teams with limited resources.

His background spans security architecture, detection engineering, adversary emulation, and infrastructure operations. That combination shapes the service model: protect critical systems, test what matters, run bounded collaboration environments, and keep reporting close to the systems it describes.

Whether it is security testing for a public media organization, managed security for a small team, or a dedicated workspace for a mission-driven organization, the principle is the same: prove what works, fix what matters, and support clients with direct senior engineering judgment.

Secure contact
For sensitive inquiries, email hello@secureorigin.io. PGP fingerprint for hello@secureorigin.io:
0BA7 6A2D 2761 340E 394F 7F13 129B A65D 2CA7 34C5

Frequently asked questions

Common questions

What types of organizations do you work with?
Small organizations that handle sensitive data and do not have large internal security teams: clinics, law firms, professional services firms, SaaS companies, nonprofits, NGOs, newsrooms, legal aid teams, and privacy-first organizations. If customer trust, funder confidence, or operational continuity depends on protecting your systems, we are built for you.
How do I get started?
Use the intake form on the Security services page. Share the basics about your organization, service interest, endpoint count, timeline, and what you need help securing. Use email only when the inquiry itself is sensitive.
How is this different from a standard penetration test?
Security Testing & Validation covers penetration testing, tabletop exercises, exposure review, control validation, identity, exposed services, and relevant detection paths.
What do Workspaces include?
Workspaces include managed file sharing, browser document editing, collaboration tools, backups, access changes, support boundaries, and export paths. Dedicated team workspaces can include Mattermost chat and calls. See the Workspaces page for details.
How long does an engagement take?
Each proposal includes a written timeline before work begins. Security Testing & Validation typically runs over a few weeks. Protect Devices onboarding and Dedicated Workspace timelines depend on endpoint count, team size, storage, placement, and scope.
What are your fees?
Protect Devices starts at $35 per endpoint per month with a $500 monthly minimum and onboarding starting at $750-$1,500. Protect People starts at $15 per user per month with the same monthly minimum and onboarding range. Protect The Organization starts at $7,500 for a security program foundation, with optional co-managed cadence starting at $1,500 per month. Security Testing & Validation starts at $6,500. Shared journalist workspaces start at $25 per month, with an optional Solo Workspace plus Device Protection bundle at $50 per month. Dedicated Workspaces start at $3,000 launch and $750 per month. Every proposal includes deliverables, responsibilities, timeline, assumptions, and price before work begins.
Request review Book call