// Services
Services: data, cybersecurity, compliance and AI
One team, four areas and a product. Every engagement starts with a first step of 4 to 6 weeks and a fixed scope.
Data
Data catalogs with owners and lineage, and platforms that produce their own audit evidence.
Data governance and metadata
A data catalog with owners, documented definitions and lineage, and change impact analysis. The groundwork for reporting, audits and AI.Data platforms and pipelines
Design, build and migration of data platforms on Databricks and Snowflake, with pipelines in dbt, Airflow and Prefect. Tests, lineage and logs in every pipeline.
Cybersecurity
Penetration tests with a retest of your fixes, application testing against OWASP ASVS, OT security under IEC 62443, and senior security specialists who join your team.
Penetration testing
Manual testing of web applications, APIs, cloud, networks and AI features. A report with evidence, priorities by business impact and a retest of fixes.OWASP ASVS assessment
Application verification against OWASP ASVS 5.0 at the level you choose, with a result for every requirement, plus chatbot and agent testing against the OWASP Top 10 for LLM Applications 2026.IEC 62443 and OT security
OT and ICS security for manufacturing and energy, based on IEC 62443: zones and conduits, target security levels and requirements for integrators. Live control networks are assessed passively only.Security specialists on your project
Senior security specialists and data engineers join your team for a defined scope. Profiles before you sign, the team named in the contract.
Compliance and audit
NIS2 in Poland (KSC) with audit readiness and management training, ISO/IEC 27001, DORA, NIST CSF 2.0 and the CRA, one framework at a time.
Compliance and audit
NIS2 in Poland (KSC), ISO/IEC 27001, DORA, the CRA and customer security questionnaires, one framework at a time, from gap analysis to evidence.NIS2 compliance in Poland (KSC)
Implementing NIS2 in Poland (the KSC Act), from gap analysis to controls with evidence, plus a pre-audit review against Article 15. Deadlines, duties and independence rules.NIS2 audit readiness in Poland (KSC)
A pre-audit review for NIS2 in Poland (KSC): your controls and evidence checked the way an Article 15 auditor will check them. Evidence index, fix list and a re-check.NIS2 management training
Yearly management training under Article 8e of the KSC Act, NIS2 in Poland: a board workshop, an incident exercise and a complete training record for the audit.ISO/IEC 27001
ISMS implementation to ISO/IEC 27001:2022, ready for certification: scope, risk assessment, Statement of Applicability and controls with evidence.DORA compliance
ICT risk management framework, classification and reporting of major incidents, a resilience testing program and a register of information on ICT providers built from data.NIST CSF 2.0
Current and Target Profiles under NIST CSF 2.0, with a Govern review, a gap analysis and a mapping to ISO/IEC 27001 and NIS2.Cyber Resilience Act (CRA)
CRA for hardware and software makers: a reporting path for vulnerabilities and incidents, an SBOM from every build, vulnerability handling and conformity assessment prepared before 11 December 2027.
AI governance and strategy
AI strategy first (where AI adds value, which risks you accept), then an approved path instead of bans, rules your systems enforce, LLM security testing and readiness for the AI Act and ISO/IEC 42001.
AI governance and AI security
An AI policy enforced in your systems, AI Act obligations, security testing of chatbots and agents, and review of AI-written code.AI Act and ISO/IEC 42001
An AI system register with your role and risk class for each system, AI Act obligations, and an AI management system under ISO/IEC 42001 taken to certification readiness.
Advisory
Architecture reviews, IT audit, business continuity with DR tests, a fractional CISO for NIS2 in Poland, plus software we know how to secure.

IT Consulting
Architecture review, IT audit, business continuity and disaster recovery, technical due diligence, and a fractional CISO or architect.Business continuity and DR testing
Business impact analysis, a business continuity plan, tabletop exercises and restore tests with measured times. Built for NIS2, DORA and ISO 22301.Fractional CISO for KSC
A fractional CISO for entities under NIS2 in Poland (KSC): risk register, evidence and customer questionnaires every month, a board report every quarter. Clear scope, no 24/7 monitoring.
Custom software development
Data-heavy internal systems, integrations and legacy modernization. A secure development lifecycle and code review from day one.
Product
An on-premises appliance that collects compliance evidence straight from your systems.
Let's talk about your situation
We reply within one business day
Tell us which system, data or regulation you are dealing with. We'll come back with questions about scope and a proposed first step of 4 to 6 weeks. No sales pitch.