Security & compliance
Know where your system is exposed before someone else does.
Audits and penetration tests, with every finding ranked and written down. Encryption and data protection built into the system instead of added after. Compliance work for PDPA, GDPR, CCPA and ISO 27001 that ends with documented evidence rather than a filled-in template.
Bring the system that worries you.
- A working session on your live system, or the one you are about to build.
- Written findings, ranked by severity, that you can hand to any team.
- You are not obliged to fix them with us.
- 12years building
- 43systems delivered
- 37organisations
- 18sectors
What you get
Six things you leave with, each of them written down.
Security work that ends in a document you can act on: with us, with your own team, or with an auditor.
A ranked list of what is exploitable
Penetration testing and vulnerability assessment of your application and the infrastructure under it. Every finding comes with its severity, how it was reproduced, and what fixes it.
Data handling that meets PDPA, GDPR and CCPA
A map of the personal data you hold, where it flows and who can reach it. That map drives the consent, retention and access controls the regulations require, which we put in the system and on paper.
Data protected at rest and in transit
End-to-end encryption where it belongs, secure storage, and transmission protocols. Each is configured, tested and documented so the next engineer can see why the choice was made.
An ISMS an auditor can assess
The policies, risk register, controls and evidence that make up an information security management system aligned to ISO 27001. Certification is issued by an accredited body; we build what it assesses, with your team, so it is maintained after we leave.
A plan for the day something goes wrong
Monitoring that alerts on the signals that matter, and a written response plan: who is called, what is isolated, what is told to whom. Response times are set out in your support agreement.
A team that recognises the attack
Security practice and threat-awareness sessions for your staff and your developers. They cover phishing, credential handling and secure coding, and are pitched at the way your organisation works day to day.
Work in this area
Systems we have delivered that hold sensitive data.
5 of the 43: a biometric visa system, a district land office's consent records, a ministry's statistics, a refinery's safety records and a broker's client data.
All 43 systems




In writing
Three things you get before the first invoice.
01
The findings are yours.
We hand over every report, test result and policy document as it is produced, rather than holding it back until the final invoice. You can act on it with us or with anyone else.
02
Remediation is fixed price.
After the assessment, we quote the fixes for phase one as a defined scope at a defined cost. You are never signing an open-ended security engagement.
03
A warranty, in writing.
Defects in controls and fixes we shipped, we fix at no charge for the warranty period. A support agreement with named response times is available after that.
How it runs
Five stages. You receive something you own at each.
- 01Insight
A written scope and the risks found in the first session.
- 02Strategy
The remediation and compliance plan, with a fixed price for phase one.
- 03Build
Fixes and controls landing in your repository every sprint.
- 04Launch
The production release, retested, with the evidence attached.
- 05Support
Documentation, a warranty, and named response times if you want them.
Other services
Security is usually one part of a larger piece of work.
Start with a free consultation on your system.
Bring the system that holds your most sensitive data, or the one you are about to put in front of an auditor. We spend a working session on it and you leave with written findings that are yours to act on, with us or with anyone else.