Tenchi Start a conversation
Cyber security architecture & governance

Build secure. Prove it. Keep it that way.

Tenchi designs, delivers and defends security programmes for platforms that carry regulated data. Twenty years of security leadership, working internationally, available as a contract.

Get in touch See the services
20+ Years in information security, from audit floor to executive table
Audit-ready SOC 2 Type 2 and ISO 27001 programmes run end to end, evidence to external audit
Hands-on AWS, GCP, Kubernetes, CI/CD and secure SDLC — not slideware

What we do

Seven practices, each one deliverable on its own or as part of a programme. Most engagements start with one and grow.

01 Certification readiness SOC 2 Type 2 and ISO 27001 from gap analysis through control design, evidence and external audit. 02 Fractional CISO Security leadership on retainer: strategy, risk register, board reporting, customer and regulator assurance. 03 Cloud & platform security Architecture review and hardening across AWS, GCP and Kubernetes, with identity and monitoring that hold up. 04 DevSecOps & secure SDLC Threat modelling, SAST/SCA/DAST, build integrity and software-supply-chain controls to SLSA levels 1 and 2. 05 Incident response & BC/DR Response plans, SIRT structure, tabletop exercises, immutable backup strategy and ransomware resilience. 06 AI security & governance AI-system inventory, risk classification, accountability and controls aligned to the EU AI Act and the NIST AI Risk Management Framework. 07 · New Secure SaaS, AI-assisted We build the product as well as the controls — architecture to delivery, using AI-assisted development with security in the loop from the first commit.

How we work with you

Five engagement models. The right one depends on whether you need a leader, a deadline met, or an answer.

Fractional CISO Monthly retainer, named accountability, ongoing ownership.
Fixed-scope assessment Defined audit or review, fixed price, written findings and a plan.
Programme delivery We build the programme and hand it over running.
Advisory hours A block of time for architecture calls, reviews and second opinions.
Product build AI-assisted delivery of a secure SaaS product, end to end.

Track record

Client names stay confidential. The work does not.

More about Tenchi

Owned company-wide security strategy for a cloud platform serving regulated EU financial institutions, and carried SOC 2 Type 2 and ISO 27001 through external audit.

Hardened CI/CD and build integrity for one of the largest blockchain networks in the world.

Stood up AI governance aligned to the EU AI Act before it was a procurement question.

Audited banking IT against CobiT, ITIL and ISO 27001, and reported findings to a management board.

Tell us what has to be true in six months.

A certification date, a customer questionnaire, a product launch, a board that wants numbers. We will tell you what it takes.

Get in touch