How to Start
All work begins with a short assessment. We agree on its duration, deliverable and price before starting. The client leaves with a document they can act on with us or with any team they choose, and there is no obligation to proceed further. If they continue, the assessment is not charged again.
Threat model assessment
For most clients, this is where the work begins. Interviews with operators and decision-makers, an inventory of systems, data, devices and accounts, and a review of contracts and configurations. The result is the written model, with the relevant actors, what each can access today and what it costs to change that, and the protection plan with estimated effort and a clear implementation sequence. Nothing is altered in this phase without written authorization.
Request a ConversationLGPD and GDPR readiness
Inventory, legal bases, impact assessment where applicable, gaps and a quote for the remediation work.
DetailsCertification readiness
ISO/IEC 27001 and 27701, SOC 2 Type II, TISAX, PCI DSS: gaps, a plan prioritized by risk, controls implemented and an evidence pack. Certification is issued by a third party.
DetailsArchitecture review
What exists, what is fragile, what to modernize and in what order, with security treated as part of the architecture.
DetailsAI inventory and governance
Which AI is already in use, who authorized it, what it can access, the regulatory exposure, the policy and the control model.
DetailsInfrastructure review
Where the data lives, who can access it, the state of servers, networks and backups, and the migration or construction plan.
DetailsWhat comes after the assessment
We carry out the assessment plan in stages, each with its own scope and price: designing the protection, building or integrating what is needed, rehearsing threat scenarios, testing against the model and moving into operation. In operation, protection is maintained under a monthly agreement, with the threat model updated as relevant actors and their capabilities change, monitoring, patching, incident response and a report on the month’s activity.
For clients who want one team to cover the full scope, we combine the relevant assessments into an integrated review. One lead coordinates systems, infrastructure, AI and security. The result is a single plan with priorities, dependencies and responsibilities for implementation.