Skip to content

Services

Everything we do, in full.

Ten practices and 85 services, grouped by the order work actually happens: assess what is there, engineer what is missing, build what does not exist, govern it, then decide where it goes next.

Practices
10
Services
85
Lead practice
AI & LLM Security
Delivery
Senior, direct

Capability

One security practice.

  • One method
  • One standard of evidence
  • One person accountable
AppSecAI & LLMArch.DevSecOpsSoftwareDashboardsISOPrivacyGRCConsultingASSESSENGINEERBUILDGOVERNADVISECybaethrexSECURITY PRACTICE
  • Senior practitioners, no junior bench
  • AI security as the lead practice
  • Every engagement ends in evidence
01Technology

We design and develop software, applications, digital platforms, SaaS products, AI solutions and technology-enabled services.

05

Software & Application Development

8 SERVICES

Built secure, because we test for a living.

We build the applications and tooling we would otherwise be asked to assess. The same people who break software for clients write this, which is the whole argument for having us do it.

  • Web Application Development
  • Mobile Application Development
  • Custom Software Development
  • SaaS Application Development
  • API Development & Integration
  • Secure Application Development
  • Security Tool Development
  • Enterprise Application Engineering
06

Dashboards & Platforms

8 SERVICES

Make posture visible to the people who fund it.

A team that cannot see its own posture will not manage it, and leadership that only sees snapshots funds the wrong thing. We build the reporting layer that fixes both.

  • Security Dashboard Development
  • Executive Security Dashboards
  • SOC / Security Operations Dashboards
  • Risk & Compliance Dashboards
  • Vulnerability Management Dashboards
  • Custom Business Intelligence Dashboards
  • Security Analytics & Visualization
  • Enterprise Portal Development
02Security

We assess, engineer and secure applications, AI systems, cloud environments, infrastructure and digital technologies.

01

Application Security

8 SERVICES

Find the flaws a scanner will never reach.

Manual, adversary-led testing of web, mobile and API surfaces. Business logic and authorisation first, because those are the findings that turn into breaches rather than tickets.

  • Web Application Security Testing
  • Mobile Application Security Testing
  • API Security Testing
  • Penetration Testing
  • Vulnerability Assessment
  • Secure Code Review
  • Threat Modeling
  • Application Security Architecture
02

AI & LLM Security

9 SERVICES

Secure AI before it becomes business risk.

The lead practice. We assess AI as an architecture rather than a model: prompts, retrieval, agents, tools and the enterprise data sitting at the end of the chain.

  • AI / LLM Security Assessment
  • Generative AI Security
  • AI Application Security
  • RAG Security Assessment
  • AI Agent Security
  • Prompt Injection Testing
  • AI Red Teaming
  • AI Security Architecture
  • AI Governance & Risk Assessment
03

Security Architecture

8 SERVICES

Design the controls before you need them.

Architecture-level work where the expensive findings are cheapest to close: reference designs, trust boundaries and the roadmap that sequences them.

  • Security Architecture Review
  • Cloud Security Architecture
  • Application Security Architecture
  • Zero Trust Architecture
  • DevSecOps Engineering
  • Security Engineering
  • Security Controls Implementation
  • Security Strategy & Roadmap
04

DevSecOps & Security Engineering

9 SERVICES

Put the control where the work already happens.

Security inside the pipeline rather than beside it. If the secure path is slower than the insecure one, engineers route around it, so we make the secure path the default.

  • DevSecOps Implementation
  • CI/CD Security
  • SAST / DAST / SCA Integration
  • Secrets Management
  • Infrastructure Security
  • Cloud Security Engineering
  • Security Automation
  • Secure SDLC
  • Security Tool Integration
03Advisory

We help organizations navigate security architecture, privacy, GRC, ISO, compliance, risk and technology transformation.

07

ISO & Compliance Advisory

9 SERVICES

Certification without the theatre.

ISMS work that produces a system the business can actually operate, not a binder written for an auditor and never opened again.

  • ISO 27001 Implementation
  • ISO 27001 Gap Assessment
  • ISO 27001 Internal Audit
  • ISO 27001 Audit Readiness
  • ISO 42001 Advisory
  • ISO 27701 Advisory
  • ISO Certification Readiness
  • ISMS Development & Documentation
  • Compliance Program Development
08

Privacy & Data Protection

8 SERVICES

Know what data you hold, and why.

DPDP Act and wider privacy work that starts with data mapping, because every privacy obligation downstream depends on knowing what you actually process.

  • DPDP Act Compliance
  • Privacy Gap Assessment
  • Data Protection Program
  • Privacy Governance
  • Data Mapping & Classification
  • Privacy Risk Assessment
  • Data Retention & Protection
  • Third-Party Privacy Risk
09

GRC, Risk & Audit

10 SERVICES

Evidence that survives scrutiny.

Audit, risk and governance work written to the standard your regulators, customers and certification bodies actually apply.

  • Information Security Audit
  • ISO Internal Audit
  • Security Compliance Audit
  • IT & Technology Audit
  • Risk Assessment
  • Third-Party Risk Management
  • Security Governance
  • Policy & Procedure Development
  • Audit Remediation Support
  • Compliance Readiness
10

Technology Consulting

8 SERVICES

Make security part of the technology strategy.

Working with technology and security leaders on the decisions that set direction: strategy, transformation, and where the risk actually sits in a changing estate.

  • Technology Strategy
  • Cybersecurity Strategy
  • Security Transformation
  • Architecture Consulting
  • Technology Risk Advisory
  • Cloud Security Advisory
  • Digital Transformation Security
  • Security Program Development
06Deliverables

What actually arrives.

An engagement that ends at a slide deck leaves you with an opinion. These are the artefacts every engagement produces.

01

Executive summary

Two pages a board can read: what is exposed, what it would cost you, and the three decisions that matter.

02

Attack-path narratives

Each significant finding written as a chain: entry point, pivot, impact, so the consequence is legible without a security background.

03

Technical findings

Reproduction steps, evidence, affected components and root cause. Written for the engineer who has to fix it.

04

Prioritised remediation plan

Ordered by consequence and effort, with owners, dependencies and the design-level fixes that close whole classes of issue.

05

Framework mapping

Findings mapped to ISO 27001, NIST CSF, NIST 800-53, the EU AI Act or ISO/IEC 42001, whichever your auditors and customers ask about.

06

Retest and evidence pack

Verification that the fix holds, packaged for customer security reviews, regulators and audit committees.

07Engagement models

Four ways to work with us.

Scope and commitment differ; the standard of delivery does not.

01

Assessment

A defined question answered properly: an application, a cloud estate, an AI system, a control set. Scoped up front, priced up front, delivered with evidence. Right when you need to know where you stand before deciding anything else.

Fixed scope · 2–6 weeks
02

Programme

Assessment through to design and validation, run as phases with decision points between them. You can stop at any phase boundary without stranding the work. Right when you have a known gap and need it closed, not just documented.

Multi-phase · 3–9 months
03

Assurance retainer

Recurring validation as the estate changes: release testing, drift review, new-service assessment and the evidence refresh your customers keep asking for. Right when you ship continuously and cannot re-prove security annually.

Ongoing · quarterly cadence
04

Fractional security leadership

Senior security ownership without a full-time hire: strategy, risk decisions, vendor and audit support, and the authority to say no on your behalf. Right when you need the judgement of a security leader before you need the headcount.

Embedded · monthly commitment

Next step

Not sure which one you need?

That is the first conversation.

Describe the situation and we will tell you which practice fits, what it would take, and whether you need us at all.