What twenty years buys you
The practice grew out of two decades in information security: internal IT audit in banking, penetration testing and forensics, secure software engineering, DevOps and DevSecOps leadership, and finally company-wide security ownership at a cloud platform serving regulated EU financial institutions.
That range is the point. Audit experience means we know what evidence has to look like. Engineering experience means the controls we design can be implemented without stopping delivery.
Selected work
Client names stay confidential. These are the engagements that shaped how we work.
Company-wide security strategy, SOC 2 Type 2 and ISO 27001 through external audit, enterprise risk register, incident response and BC/DR governance, and EU AI Act-aligned AI governance.
CI/CD security, build integrity, artefact handling and dependency control for one of the largest blockchain implementations in the world, plus event and mobile risk assessments.
Secure build pipelines using SLSA concepts and in-toto attestation, demonstrated to enterprise clients as a reference implementation.
CobiT, ITIL and ISO 27001 audits with risk findings and remediation recommendations presented to a management board.
Security ownership for a connected-device platform: authenticated device access and credential lifecycle, segmented device-to-backend communication, hardened infrastructure with baselines enforced in code, and central logging for detection across the fleet.
An online marketplace platform designed and built end to end with AI-assisted development: architecture, implementation, testing and iterative delivery.
How we work
Remote-first and international. Written scope before the work starts, written findings when it ends, and a handover that leaves your team able to run what we built.
- We say what we would not do. Security budgets are finite and most risk registers are too long.
- Controls are designed with the engineers who will operate them, not handed to them.
- Every engagement ends with documentation your next auditor can read.
- If a fixed scope is the honest answer, we quote a fixed scope rather than a retainer.
Work with us
One email is enough to start. Tell us the platform, the deadline and who is asking.