Cleared consultant group · Secret Level II
All provinces and territories · accepting engagements

SEC-OPS // AI security · Zero Trust · federal cyber assurance
Frank Dolphins Group is a team of senior security consultants who are ready to deploy across every province and territory, and each consultant holds an active Secret Level II clearance. Government work is our focus: ITSG-33 assessment and authorization, Zero Trust architecture, threat detection and AI security. The same rigour is also available to select non-government clients in central banking, critical infrastructure, national not-for-profits and healthcare when the mission demands it.
Clearance
Every consultant at Frank Dolphins Group holds an active Secret Level II clearance, which removes the slowest step in federal delivery. Work can begin inside protected environments without waiting on sponsorship, and sensitive findings are handled at the level they belong to.
Level II Secret
Every consultant in the group carries an active Secret clearance, verifiable on request through the contracting authority.
Protected B environments
We are comfortable working inside Protected A and B systems and in classified discussions.
Reliability screening
Reliability status and background screening are already in place across the whole team.
Capabilities
Every engagement is scoped to produce the artifacts a departmental security authority actually needs: assessments, evidence, and defensible risk decisions.
SA&A packages aligned to ITSG-33 control profiles: threat and risk assessments, control traceability, residual risk statements and authority-to-operate support.
Independent evaluation of departmental security posture against federal policy, plus remediation roadmaps that survive audit scrutiny.
Secure configuration reviews and hardening for Azure and Microsoft 365 estates, Entra ID identity governance and Zero Trust segmentation.
Detection engineering, log pipeline design and incident response playbooks that give SOC teams usable signal instead of noise.
Recurring vulnerability management programs, configuration baselines and evidence collection tied to real remediation ownership.
Security and governance for generative AI and machine learning systems, with every AI specific risk mapped back to Zero Trust principles, the NIST AI Risk Management Framework and ITSG-33 control families.
AI security
Departments are adopting AI faster than their existing controls were written for, so we make it measurable. We map every AI specific risk to a Zero Trust principle, a NIST reference and an ITSG-33 control family, so an AI system can be assessed and authorized with the same rigour as any other federal system.
Prompt injection & jailbreaks
Untrusted content steering a model into unintended actions or disclosure.
Assume breach · verify every request
AI RMF Measure · SI-10, SI-4 · SI (system & information integrity)
Data leakage through AI endpoints
Protected information leaving the boundary in prompts, outputs or vendor logs.
Data-centric protection
SC-8, SC-28, AC-4 · SC / MP control families, Protected A/B handling
Oversharing in retrieval and Copilot
Existing permission sprawl amplified the moment a model can search everything a user can.
Least privilege access
AC-3, AC-6, AC-24 · AC (access control) tailoring
Unaccountable model identity
Agents and service principals acting without a verifiable, revocable identity.
Explicit identity verification
IA-2, IA-9, AC-2 · IA (identification & authentication)
Track record
Most of our delivery is for federal government, central banking and the government consulting practices at Microsoft and Deloitte. We also bring the same standard to critical infrastructure, national not-for-profits and healthcare when the mission requires it.
Government of Canada
Administrative Tribunals Support Service of Canada (ATSSC)
Security assessment and authorization support for a federal administrative tribunal agency.
Central banking
Bank of Canada
Security analysis and control assurance in a high-sensitivity financial environment.
Global technology
Microsoft
Consulting delivered to Microsoft public sector and government clients, covering cloud and identity security engineering.
Professional services
Deloitte
Consulting delivered to Deloitte government and public sector clients across risk, audit readiness and security advisory.
Critical infrastructure
Suncor Energy
Operational technology and enterprise IT security across energy operations.
National not-for-profit
Kids Help Phone
Security and privacy support for a national youth crisis service handling highly sensitive personal information.
Healthcare & seniors care
The Brenda Strafford Foundation
Security posture and compliance support across clinical and long-term care environments.
Credentials
Compliance work is judged on credentials and evidence, so these are the ones we bring into every engagement. The full dossier, including framework coverage, sits on the credentials page.
Certifications held
20+
Frameworks in practice
12
Years in security
15+
Availability
Government contracts, task authorizations and subcontract arrangements are our main focus across every province and territory. We also take select non-government engagements where the same senior team, clearance discipline and federal rigour can add value, and we can send résumés and a capability statement on request.