ENTERPRISE CYBERSECURITY · GOVERNMENT · BANKING · HEALTHCARE · IT
Enterprise-Grade Security for Canada's Most Regulated Industries
Lunima delivers fixed-price, compliance-ready security assessments built for government contractors, banks, healthcare providers, and IT teams — with clear findings and results in 5 days, not 5 months.
We’re on a mission to protect your business and end users so you can relax
Lunima is a Toronto-based cybersecurity firm built specifically for the defence suppliers, banks, healthcare providers, and government contractors that enterprise security firms ignore — organisations that hold sensitive data but can't access $50,000 security assessments. We deliver the same protection as the large firms at a price that works for a 20-person defence supplier or a regional credit union. Every engagement is delivered personally. Fixed prices. Results in 5 days.
Toronto, ON
5 Days
Canada
$0 Setup
WHO WE ARE · CANADIAN-OWNED · TORONTO, ONTARIO
What Lunima is.
A Canadian cybersecurity firm that runs day-to-day security operations and produces the compliance evidence regulated buyers ask for. One firm, one contract, one accountable line — from the first scan through to the signed attestation.
Assess, Guard and Respond under one contract.
Most firms sell you a report or a tool. Lunima scopes the gap, runs the 24/7 monitoring that closes it, and stands up incident response when something gets through — under one contract, with one evidence trail that carries across all three.
24/7/365
Huntress-powered SOC coverage, every day of the year.
Under 1 hour
Typical time to deploy Guard across your endpoints.
Fixed price
Published in Canadian dollars. No lock-in, no surprise invoice.
HOW WE OPERATE · WHAT YOU CAN HOLD US TO
Four commitments, in writing.
Security firms are easy to hire and hard to hold to account. These four terms go into every Lunima engagement letter — the same wording for a 20-person machine shop as for a credit union.
The number in the proposal is the number on the invoice.
Scope and price are agreed in writing before any work begins. No hourly billing, no change orders for work we should have scoped, no surprise invoice at the end of a bad month. If the scope genuinely changes, we re-quote and you decide.
In writing
Scope and price agreed before any work starts.
30 days
Notice to cancel Guard. No annual lock-in.
Yours to keep
SSP, POA&M and evidence handed over in usable form.
WHAT LUNIMA ACTUALLY DOES
Assess. Guard. Respond.
Most security firms sell you a report or a tool. Lunima does the three things that actually move a Canadian organisation from exposed to defensible — and stays accountable for all three.
01 / LUNIMA ASSESS
Find the gaps before a buyer does.
An independent assessment against CPCSC, CMMC and ITSP.10.171 — with the gap report, SSP framework, POA&M and crosswalk your prime will accept.
FIXED FEE · 5-DAY SPRINT
24/7/365 MONITORING
Huntress-powered EDR and identity monitoring with a human SOC behind it — watching for ransomware, credential theft and intruders, and acting the moment something moves.
A real team on your endpoints, 24/7.
02 / LUNIMA GUARD
PER-INCIDENT ENGAGEMENT
When it happens, you're not alone.
03 / LUNIMA RESPOND
Containment, forensics and recovery run by people who already know your environment, plus the written record your insurer, your regulator and your prime will ask for.
WHO WE BUILD FOR
Four sectors. Four different mandates.
The rule that decides whether you keep a contract is not the same in defence as it is in healthcare. Here is what applies to you — and what Lunima delivers against it.
CPCSC · MANDATORY 2026
Defence
CGP-registered manufacturers and their suppliers. We run the gap assessment, build the SSP, and get you attest-ready before the RFP lands.
Banking & Finance
Federally regulated institutions push B-10 obligations down to their vendors. We produce the control evidence their due-diligence team asks for.
OSFI B-10 · VENDOR RISK
Healthcare
Clinics, labs and health-tech holding personal health information. We cover safeguards, breach response and the record the IPC expects.
PHIPA · ONTARIO HEALTH
Government
Federal and provincial suppliers. We map your controls to ITSG-33 and PIPEDA so procurement gets an answer, not another questionnaire.
ITSG-33 · PIPEDA
SERVICES
Built different, on purpose

Defence Focus
We work exclusively with CGP-registered Canadian manufacturers on CPCSC. Not a generalist IT shop dabbling in compliance.

A real 24/7 team
Powered by Huntress. Enterprise-grade monitoring watches your systems around the clock, not just software running quietly.

You talk to the person who assessed you
No ticketing system, no junior analyst. Direct access to the same expert, every time.

Plain- reporting
Every finding mapped to the specific rule that makes it your legal risk. No 200-page report you'll never read.

Fixed prices, no surprises
Scope and price agreed before we start. You'll never get a surprise invoice from Lunima.

Attestation you can hand over
Proof ready the day a prime or DND asks. No scrambling when the RFP lands.

Protecting the Businesses
"I built Lunima because Canadian businesses were falling through the gap between $299 antivirus software and $50,000 enterprise assessments. Defence suppliers losing contracts because they couldn't prove CPCSC readiness. Healthcare clinics shutting down after ransomware. Firms exposed by credentials on the dark web. The enterprise firms weren't interested — the contracts were too small. So I built the firm that actually shows up for these organisations. Every Lunima client works directly with me. Not a ticketing system. Not a junior analyst. Me — the same person who assessed your environment picks up when something goes wrong."
Security,
Built by Someone
Accountable to you.
Every engagement runs the same way, whatever the sector: one named lead who stays on your file from the first scan to the signed report, evidence mapped to the framework your regulator or prime actually checks, and a price agreed before we start. Government suppliers get CPCSC-ready packages, banks get OSFI B-10 documentation, healthcare providers get PHIPA-aligned reporting — produced by the person who did the work, never a call centre.


Compliance Expertise
CPCSC
Defence Supply Chain
PHIPA
Ontario Healthcare
OSFI B-10
Financial Sector
ITSG-33
GC IT Security
Bill C-27
AI & Data Act
FINTRAC
Anti-Money Laundering
Why This
Matters Now
Facts & Figures
2026
CPCSC Level 1 mandatory
Required this summer to stay contract-eligible
13
Level 1 controls
We check every one, and tell you where you stand
5 days
To attest-ready
Full gap assessment and package, fixed price
24/7
Monitoring via Huntress
A real team watching, not just software