Held to the standards
we hold you to
You're about to trust an outside team with the thing that could end your business. That trust has to be earned in specifics — the frameworks we work to, the tools we run, and how we handle what you show us.
Frameworks we align to
We build and operate against recognised security frameworks, and we help our clients get and stay audit-ready against them. Alignment means our practices are designed around these controls — and that we can speak the language your auditors and clients expect.
SOC 2 & ISO/IEC 27001 shape how we think about access, change, monitoring, and evidence — and they're the standards our Audit & Compliance engagements help you achieve. MITRE ATT&CK is the map our detections are written against, so coverage is measured in real adversary techniques, not vendor buzzwords.
The tooling we run on
Our SOC is built on a Wazuh-powered SIEM — open, inspectable, and tuned per client rather than a black box you can't audit. Our managed edge is built on Cloudflare, giving your apps enterprise-grade WAF, DDoS mitigation, and TLS. Good tools matter, but configuration and the people running them matter more; that's the part we own.
How we handle your data
Confidentiality is the whole job. These are the practices we hold ourselves to.
Least privilege
Access to your environment is scoped to what the work requires, and no more — granted deliberately, reviewed, and revoked when done.
Data minimisation
We collect the telemetry we need to defend you and avoid hoarding what we don't. Less data held is less data at risk.
Evidence handling
Forensic and audit evidence is preserved with sound chain-of-custody and shared only with the people who need it.
Confidentiality first
What we learn about your environment stays yours. We never trade on it, and we won't name you as a client without your say-so.
Our own posture
We hold ourselves to the practices we sell: hardened endpoints and accounts, monitored access to client environments, and the same containment-first discipline internally that we bring to your incidents. A security provider that doesn't practise what it preaches isn't one.
A note on honesty: we say "aligned to" SOC 2 and ISO/IEC 27001 deliberately. Where a specific certification or attestation matters for your procurement, ask us directly and we'll tell you exactly where we stand — no badge theatre.
See your risk clearly.
Book a free 30-minute assessment. We'll review your exposure and show you where a pattern is already forming. No obligation.