What we sell

Services

Every engagement is scoped in a free call and quoted in writing within 48 hours. Entry products carry a published fixed price; specialist work is quoted after scoping.

Corporate Digital Trust Audit

from €2,400
Fixed price · 5–10 days

How your company looks to email systems, blacklists, fraud filters, search and AI engines — and to impersonators.

DORA / NIS2 Evidence Sprint

from €7,900
Fixed price · 3–5 weeks

A defensible evidence pack for your regulatory obligations — proof, not just a plan. Includes an executive fraud briefing.

AI Governance & Shadow-AI Sprint

from €5,900
Fixed price · 3–4 weeks

The AI tools already in use across your business — found, inventoried and governed before they become an incident.

DORA

from €4,400
Fixed price · 3–6 weeks

For financial entities supervised by БНБ, КФН, CySEC or an equivalent authority, and for the ICT providers they depend on. A published fixed price for the readiness assessment.

Who we serve

Obliged, exposed, and under-resourced.

Our clients have a regulatory obligation they did not ask for, a reputation that a single incident would damage, and no in-house security leadership to deal with either.

  • Financial firms — payment institutions, e-money issuers, asset managers, brokers, insurers and crypto-asset service providers.
  • Software and SaaS vendors that must clear the due diligence of regulated buyers, where SOC 2 and ISO 27001 are the currency.
  • Public bodies and critical suppliers in scope of NIS2.

Specialist capabilities

Regulatory and compliance advisory

DORA, NIS2, the EU AI Act, the Cyber Resilience Act, GDPR and MiCA: gap assessments, roadmaps, supplier-contract review, Register of Information preparation, third-party risk programmes.

Certification and attestation readiness

ISO/IEC 27001, ISO/IEC 42001 and SOC 2 — control design, policy sets and evidence discipline before an auditor is engaged. The certification body stays independent, as it must.

Email and domain trust engineering

Why your mail and your domain are distrusted, and how to fix it: authentication (SPF, DKIM, DMARC), deliverability recovery, blacklist removal, impersonation defence.

Security questionnaires and vendor due diligence

The recurring tax on every vendor selling to regulated buyers. We answer the questionnaires and build the reusable evidence set.

Cloud and product security

Secure architecture and cloud configuration review, secure development practices, and product-security readiness for software makers.

AI security and governance

Shadow-AI discovery, AI inventories and governance, ISO/IEC 42001 gap analysis, and risk review of AI agents and their connectors.

Fractional security leadership

Named, accountable security leadership in clear monthly tiers — including the independent oversight supervisory authorities expect.

Strategic incident management

Coordination, decision support and regulatory reporting when it matters. Technical forensics runs through vetted partners — we never promise 24/7 capability we do not have.

Book a scoping call