Six ways to work together. Every engagement is advisory: the deliverable is an assessment, a plan, or a decision — never a transaction.
What to build and for whom — the decision that quietly determines whether the next two years work. Most deep-tech roadmaps are a list of everything the technology can do. A product is the much smaller list someone will pay for.
A written product and business strategy: the segment, the wedge, the pricing model, the twelve-month roadmap, and the three things that have to be true for it to work. Reviewed with the team, not delivered over the wall.
Monthly retainer, fixed-scope project, or advisory equity vesting on time. Typically three to six months, then a lighter ongoing cadence.
Getting into a market that has never bought this before. Deep-tech GTM is not a smaller version of software GTM — the buyer is often inventing the budget line, and the sales cycle runs through people who are personally at risk if it fails.
A go-to-market plan with named target accounts, the procurement path for each, a hiring sequence, and a weekly operating rhythm. Plus direct work with whoever is carrying the number.
Retainer or milestone-based project fee. Milestones are defined by work delivered, never by a financing or a closed deal.
An independent read on opportunities already on your desk. Is the technology real, is this team the one to commercialize it, and what would have to be true for it to reach scale. Written for an investment committee, not for a lab.
A written assessment — usually eight to fifteen pages — stating what is real, what is unproven, what would change the answer, and the questions to put to the company. Plus a call to walk through it.
Per-assessment or an advisory retainer. Never contingent on whether you invest, and never paid by the company being assessed.
We have led more than $300M in acquisitions and been on the other side of a $1.6B one. Both views turn out to matter: what looks like a clean tuck-in from the buyer's side often looks very different from inside the target.
A landscape map with a ranked target list and the rationale for each, or a technical diligence memo on a specific target. Ongoing engagements include a standing scouting cadence.
Scouting retainer or a defined project. Advisory only — we do not act as an intermediary in any transaction.
Joint technical assessment on rounds where the science is the risk, and reciprocal perspective-sharing with funds working the same sectors. Most of this is informal and unpaid; it is how the sector actually works.
A short written read or a working call, depending on the timeline. Where a fund needs a formal memo, it is structured as advisory work on the same terms as section 03.
Advisory basis where formal, or none where reciprocal. Any capital we invest is our own, on the same terms as everyone else in the round.
SOC 2, CMMC, HIPAA, and FedRAMP are not security exercises. They are the gate on the first enterprise, health-system, or federal contract — and companies routinely discover a twelve-month timeline in month one of a sales cycle they expected to close in three. This is a market-access problem wearing an IT costume, which is why it sits inside this practice rather than outside it.
A gap assessment against the target framework, a sequenced remediation plan, the policy and evidence architecture, hands-on configuration of the technical controls, and management of the audit itself through to attestation. NextScale does not issue certifications — an accredited auditor or registrar does. What NextScale does is get you there and run the process.
Fixed-scope readiness program or a monthly retainer through the observation window. Priced against the framework and the state you start from, never against whether an audit opinion comes back clean.
The same discipline pointed at a different target. Family offices and their principals are attacked as individuals rather than as enterprises — targeted wire fraud, credential theft against personal accounts, exposure through travel and home networks. The institutional security stack does not cover any of it, and the people responsible for the money are usually the least protected people in the structure.
An assessment of exposure across people and locations, a hardening program executed rather than recommended, documented wire-verification procedures for the office, and a standing response arrangement.
Annual retainer scoped to the number of principals and locations. Confidential by construction — this engagement is never referenced anywhere.
A small number of formal board or advisory-board seats each year, for companies where sustained involvement beats episodic advice. This is the highest-commitment engagement and the one with the shortest list.
Whatever the company actually needs between meetings — which is rarely what the board deck says it needs.
Advisory equity on standard terms, or standard board compensation. By introduction.
Compliance platforms are evidence-collection engines. They watch your systems and assemble the artefacts an auditor asks for. What they do not do — and do not claim to do — is design the control, configure the tooling, write the policy, or answer the auditor.
So the platform subscription is the beginning of the spend rather than the end of it. The usual sequence is a platform, then a consultancy to write the policies, then an integrator to configure endpoint management and identity, then a separate firm to run the audit relationship. Four vendors, four scopes, and nobody who owns the outcome. NextScale runs this as one engagement, ending in the attestation rather than in a set of recommendations.
Every engagement begins with a conversation and a short written scope — what the question is, what the deliverable will be, and when. If the scope cannot be written in a paragraph, it is not ready to start.
The fastest way to be useful is to be clear about where we are not. We will usually say so in the first exchange rather than the third.
If you are not sure, say what is in front of you and we will tell you which one it is — or that it is neither.