Security & Compliance

Map, rank, then fix — in that order — and document what an auditor will ask you for.

  • GDPR
  • ISO 27001 framework
  • Pentesting
  • Encryption

Our approach

  1. Establish the baseline

    Mapping personal data, access paths and dependencies before making any recommendation.

  2. Fix in order of risk

    A ranked, costed action plan rather than an unprioritised list of findings. Not everything has to be fixed: some risks are documented and accepted, and we write that down too.

  3. Wire controls into the pipeline

    Automated dependency and secret scanning in CI, so compliance does not decay over time.

Typical use cases

Pass your client’s audit

A major client sends over a security questionnaire calibrated for organisations several times your size, and the signature waits on the answer. We establish the baseline, rank the gaps by risk, and assemble the technical and documentary file the auditor will ask for.

Host sensitive data

The data model was designed before these records became sensitive, when segregation was not yet the question. We separate access scopes, make their history auditable, and set retention periods with your DPO.

A project in this area?

Talk it through with one of our engineers. Thirty minutes is usually enough to tell whether we are the right people for it.