Security your customer can verify.
From vCISO advisory and security reviews to pen testing and monitoring — plus security built into the software we write. And an honest inventory of what we have and what we do not.
Security is a requirement, not a badge.
We do not sell a certificate. We do what a customer actually asks for when they put you through their security review — and we build the same thing into the software we write for you.
vCISO as a service
Security leadership without a permanent hire: policies, risk assessment, the choice of controls and accountability to your board and to your customers.
Reviews and compliance
Preparation for the vendor security review your customer sends you, GDPR obligations written into contracts, and putting in order the evidence they ask for. We have been through such a review at a tier-one bank, with a signed information-security annex.
Pen testing
Testing of applications and infrastructure, with findings ordered by real risk and with clear remediation steps — not with a raw tool report.
Monitoring and response (SOC)
Monitoring, alerting and incident response, with agreed response times.
Security in the software itself
Identity Server and OIDC, Key Vault for secrets, policy-driven pipelines, row-level security and audit chains — in the code, not in a document.
Azure security architecture
Migrations and architecture on Azure: segmentation, access management and data residency where regulation requires it — including delivery with no data egress from the client’s network at all.
What we have, what we do not have, and what is on the roadmap.
We would rather you hear this from us than find it in a security review.
What we have
A signed information-security annex with a tier-one bank, whose vendor security review we passed. Delivery inside a government ministry’s network, with an audit chain that exposes changes. Delivery experience in US healthcare under HIPAA requirements. GDPR obligations written into contracts. ISO 9001:2015-auditable data sets in production.
What we do not have
An ISO 27001 certificate. Microsoft Solutions Partner status. A HIPAA attestation or a signed BAA. A published DPA template. A formal written retention policy.
What is on the roadmap
A formal information-security management system, a standard DPA and a written retention policy — driven by client requirements, not by a wish for a badge.
Three ways, depending on what you actually need.
The same model as for the rest of our delivery: a small, bounded assessment first, then work phase by phase, then ongoing if you want it.
1–2 weeks · fixed fee
A bounded assessment of where you stand: where the risks are, what is cheap to close, what needs a project. You get a map and a proposal, with no obligation to continue.
Phase by phase · fixed scope
Architecture, remediation, pen testing and compliance — phase by phase, with ownership handed over at the end of each one. You can stop after any phase and keep what has been built.
vCISO or monitoring · monthly
The vCISO role, monitoring and response, or both. We run it, or we hand it to your team with the documentation to run it themselves.
Put us through your security review.
A one- to two-week assessment at a fixed fee — at the end you know where you stand and what gets closed first.
Request an assessment