About Veratlas

Built by a practitioner.
For SaaS companies.

Veratlas is not a generic MSP. It's a security baseline architecture firm — built from nearly two decades inside financial institutions and defense environments, designed specifically for 50–100 person SaaS companies facing their first serious security pressure.

Trusted by growing companies

UGC Masters Swapkaart Brain Donors Creative Corner Codelevate Craft Policy

The founder

Kaloyan Markov

"After nearly two decades building, designing, and operating global infrastructure for Fortune 500 organisations — from major financial institutions and defence contractors to datacentre operators and international MSPs — I founded Veratlas because fast-growing SaaS companies keep hitting the same wall: enterprise customers demand security maturity they couldn't build fast enough. We took what works at Fortune 500 scale and made it accessible in 90 days."

I spent nearly two decades building and securing enterprise networks — inside banks, financial institutions, defence contractors, and global MSPs where failure wasn't an option. These are organisations with dedicated security teams, seven-figure budgets, and regulators breathing down their necks.

Then I started talking to SaaS founders. Same compliance pressure. Same exposure. A fraction of the resources. No security function. No documentation. No idea where to start. And auditors, enterprise customers, and investors asking harder questions every quarter.

Veratlas exists because that gap is real — and completely solvable. The same structures that protect financial institutions can be adapted, implemented, and run for a 60-person SaaS company. That's what we do.

Kaloyan Markov

Background

Nearly 20 years enterprise security

Network security and infrastructure across financial institutions and defense environments

ISO 27001 aligned delivery

Every engagement is built around ISO 27001 control mapping and evidence pack generation

Microsoft Partner

Full Microsoft 365 security stack: Entra ID, Intune, Defender — and JumpCloud for Google Workspace environments

Based in the Netherlands

Operating entity: MPM ICT Services B.V. — serving Europe and USA

Remote-first delivery

Fully remote delivery model — built for SaaS companies wherever they are in Europe and the USA

Connect on LinkedIn

Our presence

Two offices. One mission.

Office — Netherlands

Barneveld, Netherlands (HQ)
hello@veratlas.com

Office — Bulgaria

Sofia, Bulgaria
hello@veratlas.com

Serving clients across Europe & the USA

What we are

Not a generic MSP.
Not a tool reseller.

Most IT providers manage your helpdesk. Veratlas builds and runs your security program. The difference matters — especially when an auditor or enterprise customer asks for proof.

What Veratlas is

  • A security baseline architect for SaaS companies
  • A compliance enabler — ISO 27001, SOC 2, PCI DSS
  • A maturity builder from ad-hoc to auditable operations
  • A long-term governance partner with embedded vCISO
  • A delivery model built around repeatability and evidence

What Veratlas is not

  • A generic MSP / break-fix IT company
  • A low-cost IT provider competing on price
  • A tool reseller bundling software licenses
  • A helpdesk or ticket-volume business
  • A one-size-fits-all provider for all industries

How we operate

Principles that
never get traded away.

01

Outcomes, not hours

We price by outcome and scope — not by time spent. Fixed prices, defined deliverables. You know exactly what you're getting before you sign.

02

Documentation is the product

Every control we implement is documented, auditable, and packaged as evidence. Not because auditors ask — because that's what operational maturity actually looks like.

03

Security theater is the enemy

We don't build security programs to look good in a deck. We build them to actually reduce risk, survive audits, and hold up under scrutiny. Form follows function.

04

Repeatable beats custom

We standardize 80% of our delivery across clients. This keeps costs low, quality high, and lets us focus custom thinking on the 20% that genuinely differs.

05

Honest before comfortable

If the Assessment shows your environment is worse than you thought, we tell you. If we're not the right fit, we'll say so. No sugarcoating, no false urgency, no overpromising.

Work with us

Start with a
Security Assessment.

A 2–3 week deep-dive into your full security posture. Prioritized findings, a remediation roadmap, and a clear path to audit readiness. €2,500 — fully credited toward the Sprint.

Book a Fit Call

30-minute discovery call · No commitment · Serving Europe & USA