UnKAnscious Join the Private Alpha

UnKAnscious · Services

A few engagements a year, led personally.

UnKAnscious builds software. We also take on a small number of engagements where the problem is worth a senior person's whole attention — AI that has to be trusted with real authority, and security programs that have to hold up under examination.

Two different things, kept apart on purpose

GoalRunner is a product. You connect your mail, it tells you what you owe and what you are owed, and you pay for software. It is in Private Alpha. If that is what you came for, the GoalRunner pages are the right place and this one is not.

Services is a practice. It is a person doing work for you, scoped and priced per engagement. Buying one has never been a condition of the other, and it never will be. We do not run engagements as a route into the product, and we do not sell the product by promising the practice.

The two share one thing: the same view of what AI is for. An AI system may be allowed to understand a great deal; its power to act is a separate grant, made explicitly, one capability at a time. That principle is in GoalRunner's architecture, and it is the lens every engagement is run through.

Four kinds of engagement

These are not a menu with hours attached. Each one is a problem we have actually worked on, described honestly enough that you can tell whether it is yours.

AI Strategy & Implementation

Deciding what to build with AI, what to buy, and what to refuse — then getting the first real thing into production instead of into a deck.

Typically engaged when

  • The organization has agreed it should "do something with AI" and nobody can name the first system.
  • A pilot works and nobody can say what would make it safe to run unattended.
  • There is a plan to give a model authority over a real workflow — sending, filing, approving, paying — and no one has drawn the authority boundary yet.
  • You need a technical read on a build-versus-buy decision from someone with no stake in the answer.

What you get

  • A written position on what to build, what to buy, and what to leave alone — with the reasoning, not just the recommendation.
  • An authority model for any agentic system in scope: what it may understand, what it may do, and what a human must press.
  • A first implementation, or a specification precise enough that your team can build it without a second engagement.
  • The evidence design — what the system must be able to show for every conclusion it reaches.

Cybersecurity & Risk Advisory

Security work at the level where it meets the board, the auditor, the regulator and the acquirer — architecture, governance, compliance programs, and the reporting that has to survive being questioned.

Typically engaged when

  • A regulated or government environment has to be built, approved, and then actually operated.
  • A compliance program exists on paper and does not hold up when someone tests it.
  • The board is asking questions about security posture that the current reporting cannot answer.
  • A transaction requires security due diligence, or an acquired company has to be integrated without inheriting its problems.

What you get

  • An assessment that names the real gaps in priority order, with what it costs not to fix each one.
  • Security architecture and governance design for the environment in question, including the operating model that keeps it true after the project ends.
  • Board- and customer-facing reporting that is defensible line by line.
  • Due-diligence work products for pre-close review and post-close integration.

AI + Security Readiness

The intersection: what happens to your security posture when AI systems are given access to your data and, eventually, permission to act.

Typically engaged when

  • Employees are already using AI tools and the organization has no position on what that means for its data.
  • A vendor's AI feature is about to be enabled across the company and someone has to say yes or no.
  • You are being asked, by a customer or a regulator, how AI is governed here — and the honest answer is that it is not.
  • An agent is going to be given credentials, and the question of what it is permitted to do with them has not been answered.

What you get

  • A governance position for AI use that people can actually follow, written in the language of your business rather than a framework's.
  • A review of the AI systems already in use, what data reaches them, and under what terms.
  • An authority-boundary design for any agent given credentials: least privilege applied to a thing that acts on its own.
  • The material you need to answer a customer, an auditor or a board on this subject without improvising.

Executive / Fractional Advisory

A senior technology and security executive available on a standing basis — for organizations that need the judgment without the headcount, and for founders who need someone who has already made the decision in front of them.

Typically engaged when

  • You need CISO-level judgment on a recurring basis and cannot justify a full-time hire.
  • A security or engineering leader is new to the seat and needs someone to think out loud with.
  • A founder or an executive team wants a technical advisor who will disagree with them.
  • A specific decision — an architecture, a hire, a vendor, a disclosure — needs a second senior opinion before it is made.

What you get

  • A standing engagement with defined availability, not an open-ended retainer.
  • Direct participation where it is useful: board and customer conversations, architecture review, incident response readiness.
  • Written positions on the decisions taken during the engagement, so the reasoning outlives the engagement.
  • A clear end. Advisory work that cannot name its own finish line has become a dependency, which is the opposite of the point.

How we work

Selective, and we will say no

A small number of engagements at a time, because the work is done by the person you spoke to. If an engagement is not a fit — wrong problem, wrong stage, or someone else would do it better — we will say so in the first conversation rather than the third invoice.

Scoped, not metered

Engagements are scoped to an outcome and priced per engagement. We do not sell hours, and we do not sell a body to sit in your standups.

Written down

Every engagement produces something durable — a position, an architecture, a program someone else can run. If the only artifact is a conversation, you paid for the wrong thing.

Honest about the boundary

We give technical and security judgment. We are not attorneys, auditors, or a certification body, and we will tell you when the question in front of you needs one of those instead.

Who does the work

Engagements are led by Bron Torres, a co-founder and co-CEO of UnKAnscious. Twenty years of enterprise security leadership — most recently as Vice President of Cybersecurity at Dayforce, with CISO-scope accountability for its government cloud environments, and before that as Director of Security Assurance at Autodesk, where he built the M&A security practice and led the government cloud program.

The AI half is not theoretical. He designed and built GoalRunner end to end — the orchestration, the agentic automation, and the governance controls around them — which is the same problem most organizations are about to have: a system that understands a great deal and must be prevented from acting on all of it.

He has run an independent advisory practice before, from 2017 to 2019, as an advisory CISO. This is not a new line of business so much as a resumed one.

The full record — roles, dates, programs and speaking — is on the Bron Torres page. Nothing on this page goes beyond what is documented there.

What we will tell you before you ask

  • We are a small company. UnKAnscious is early-stage and says so. If your procurement process requires a vendor of a certain size or tenure, that is a real constraint and worth establishing before either of us spends time.
  • We hold no security certifications. UnKAnscious is not SOC 2 audited, ISO certified, or FedRAMP authorized as a company. Experience taking other organizations through those regimes is not the same thing as holding them ourselves, and we will not let the two blur.
  • We are not a law firm or an audit firm. Nothing in an engagement is legal advice or an audit opinion, and we will tell you when you need one.
  • We do not publish client names or results. Not as modesty — we do not have permission to, and we would rather have a short page than a fabricated one. If you want references, ask, and we will tell you honestly what we can and cannot offer.
  • An engagement is not a route to the product, and the product is not a route to an engagement. Neither is a condition of the other.

Questions about engagements

Is this consulting, or is it software?

Two separate things from the same company. GoalRunner is software you would license. An engagement is work performed for you. You can buy either without the other, and most people will only ever want one.

What does an engagement cost?

It depends on the scope, and we would rather tell you a real number for your actual problem than publish a range that is wrong for everyone. Scope and price are agreed in writing before any work starts.

How small is "selective"?

Small enough that saying yes to yours means saying no to another. The work is led by the person you would be talking to, not passed to a team you have not met, so the ceiling is a real one rather than a positioning device.

Do you have professional liability or cyber insurance?

Ask us during scoping and we will tell you exactly what is and is not in place at that moment. We are not going to publish a coverage claim on a web page that you would then be relying on.

Will you sign our NDA, MSA, and security questionnaire?

Yes to the first two as a matter of course. On security questionnaires: we will answer them accurately, including the answers that are "no" — see the disclosures above.

Can you help us evaluate an AI vendor?

Yes, and it is one of the more useful things an outside party can do. The questions worth asking a vendor are rarely about model quality; they are about what the system reaches, what it retains, what it is permitted to do without a human, and what it can show you afterwards.

Do you take equity instead of fees?

It has to be a specific conversation rather than a policy. Ask.

We are looking for the product, not a consultant.

Then you want GoalRunner, and the fastest route is requesting Private Alpha access. Nothing on this page needs to be part of that.

Discuss an engagement

Tell us the problem in a paragraph. If it is a fit, the next step is a conversation with the person who would do the work. If it is not, we will say so and, where we can, point you at someone better placed.