Services · Security

Security your customer can verify.

From vCISO advisory and security reviews to pen testing and monitoring — plus security built into the software we write. And an honest inventory of what we have and what we do not.

vCISO
as a service, with no hiring
Tier-one
bank — we passed their vendor security review
Ministry
delivery inside a government network, with no data egress
Honest
we publish what we do NOT have as well
How we work

Security is a requirement, not a badge.

We do not sell a certificate. We do what a customer actually asks for when they put you through their security review — and we build the same thing into the software we write for you.

01
Assessment
where you are now
02
Priorities
risk against cost
03
Architecture
identity, secrets, network
04
Testing
pen test and review
05
Compliance
contracts and obligations
06
Monitoring
SOC and response
We do the same in our own delivery — which is why we can show it, not merely claim it

vCISO as a service

Security leadership without a permanent hire: policies, risk assessment, the choice of controls and accountability to your board and to your customers.

Reviews and compliance

Preparation for the vendor security review your customer sends you, GDPR obligations written into contracts, and putting in order the evidence they ask for. We have been through such a review at a tier-one bank, with a signed information-security annex.

Pen testing

Testing of applications and infrastructure, with findings ordered by real risk and with clear remediation steps — not with a raw tool report.

Monitoring and response (SOC)

Monitoring, alerting and incident response, with agreed response times.

Security in the software itself

Identity Server and OIDC, Key Vault for secrets, policy-driven pipelines, row-level security and audit chains — in the code, not in a document.

Azure security architecture

Migrations and architecture on Azure: segmentation, access management and data residency where regulation requires it — including delivery with no data egress from the client’s network at all.

An honest inventory

What we have, what we do not have, and what is on the roadmap.

We would rather you hear this from us than find it in a security review.

What we have

A signed information-security annex with a tier-one bank, whose vendor security review we passed. Delivery inside a government ministry’s network, with an audit chain that exposes changes. HIPAA-compliant delivery experience in US healthcare. GDPR obligations written into contracts. ISO 9001:2015-auditable data sets in production.

What we do not have

An ISO 27001 certificate. Microsoft Solutions Partner status. A HIPAA attestation or a signed BAA. A published DPA template. A formal written retention policy.

What is on the roadmap

A formal information-security management system, a standard DPA and a written retention policy — driven by client requirements, not by a wish for a badge.

How we engage

Three ways, depending on what you actually need.

The same model as for the rest of our delivery: a small, bounded assessment first, then work phase by phase, then ongoing if you want it.

Assessment

1–2 weeks · fixed fee

findings and priorities

A bounded assessment of where you stand: where the risks are, what is cheap to close, what needs a project. You get a map and a proposal, with no obligation to continue.

Project

Phase by phase · fixed scope

no surprises in scope

Architecture, remediation, pen testing and compliance — phase by phase, with ownership handed over at the end of each one. You can stop after any phase and keep what has been built.

Ongoing

vCISO or monitoring · monthly

SLA · optional

The vCISO role, monitoring and response, or both. We run it, or we hand it to your team with the documentation to run it themselves.

Put us through your security review.

A one- to two-week assessment at a fixed fee — at the end you know where you stand and what gets closed first.

Request an assessment