I'm looking for security consultant recommendations! I support a non-profit that’s building PII-storing open source software that integrates with government data storage systems, and they would like a third-party security assessment. This is *not* about compliance, this is straight-up wanting somebody to review their code and practices, try to break in, etc. If you've worked a small or single-person (read as: not really expensive) consultant you'd recommend for this, I'd love to hear about them.