Boutique consultancy — security · regulation · digital trust

Defensible. Bank-ready. Trusted.

Regulators, banks, payment platforms, insurers and AI systems all form a judgement about whether your company can be trusted. We engineer that judgement deliberately — with fixed-scope, fixed-price products and named professionals who sign their work.

Fixed prices, published openly Evidence, not opinions Professional indemnity cover on every engagement Remote-first, serving clients worldwide
Frameworks we work in

One team across the whole regulatory stack

Most firms cover one or two of these. The overlap between them is where the wasted effort — and the missed obligation — usually lives.

EU regulation International standard Attestation & market demand
Why companies come to us

Regulation with teeth

DORA, NIS2, the AI Act and the CRA carry turnover-based fines — and, in several countries, personal liability for directors and managers.

Reputation as infrastructure

Mail in spam, a flagged domain, a bank's due-diligence red mark — onboarding stops, invoices vanish, deals stall. Trust is a technical asset.

Invisible AI risk

Staff already use AI tools the business never approved — leaking data and creating obligations nobody is tracking.

The human factor

Most breaches still start with a person: a click, a misjudgement, a moment of stress. Technology alone doesn't close that gap.

Start small, fixed and priced

Three ways to begin — price, timeline and deliverable known before you sign

Every engagement starts with a bounded product. The findings tell us both whether there is more to do.

Most common start

Corporate Digital Trust Audit

€2,500–3,200
Fixed price · 5–10 days

How your company looks to email systems, blacklists, fraud filters, search and AI engines — and to impersonators.

  • Board-level snapshot
  • Technical findings report
  • Prioritised fix list + review call

DORA / NIS2 Evidence Sprint

€9,500–18,500
Fixed price · 3–5 weeks

A defensible evidence pack for your regulatory obligations — proof, not just a plan. Includes an executive fraud/BEC briefing.

  • Gap assessment + prioritised roadmap
  • Supplier-contract review
  • Board & auditor-ready presentation

AI Governance & Shadow-AI Sprint

€6,500–12,000
Fixed price · 3–4 weeks

The AI tools already in use across your business — found, inventoried and governed before they become an incident.

  • Shadow-AI discovery + inventory
  • Acceptable-use governance + risk register
  • Transparency posture, ISO 42001 basics

Working toward DORA, SOC 2 or ISO 27001 instead? Those run as scoped readiness programmes — see specialist services.

How we work

Audit → Sprint → Retainer. Never the other way around.

Nobody should buy a long engagement from a stranger. A low-risk audit surfaces concrete problems; a fixed-scope sprint fixes them; lasting success turns into monitoring or advisory — if and only if it earns it.

Assess

A fixed-price audit with a defined deliverable. You know the cost before we start.

Roadmap

Findings ranked by real risk and regulatory weight — a document your board and your auditor can both read.

Implement

Fixed-scope sprints. Anything touching a live system is snapshotted, staged, signed off and reversible.

Attest

A defensible, documented trail wherever a regulator, bank, auditor or insurer will look.

Free · 20 questions · about 4 minutes

The Readiness Scorecard

Answer twenty questions about how your organisation actually operates today. You get a scored PDF showing your top gaps against the framework that applies to you — DORA, NIS2, SOC 2 or ISO 27001 — and one recommended next step.

No sales call attached. If the answer is "you're fine", the scorecard will say so.

Your scorecard PDF and nothing else — we don't run drip campaigns.
The calendar that drives our clients

Deadlines we work against — real ones only

We run campaigns only against confirmed dates. Urgency you can verify is the only urgency we sell.

Next deadline11 Sep 2026

Cyber Resilience Act — 24-hour vulnerability reporting to ENISA begins for software makers.

Every yearQ1 season

DORA Register of Information — the annual submission season for financial entities and their ICT providers.

Already enforcedNIS2

Audits, fines and personal liability for management across the EU. In Bulgaria, municipalities and administrations are in scope regardless of size.

Free · automated · no meeting required

The Reputation Snapshot

One page showing how the world's trust systems see your domain — email authentication, blacklists, exposure, visibility — with the three most costly red flags.

Launching shortly. No spam — one report, one follow-up, nothing else.
Who we serve

Regulated. Reputation-sensitive. No CISO.

Our clients share three traits: a real regulatory obligation, genuine reputational sensitivity, and no in-house security or compliance leadership to handle it.

  • Non-bank financial firms — payment institutions, e-money issuers, asset managers, brokers, insurers, crypto-asset service providers.
  • SaaS & software vendors that must clear the due diligence of financial clients — where SOC 2 and ISO 27001 are the currency.
  • Public bodies under NIS2 — including Bulgarian municipalities and administrations, served in Bulgarian.
Honest scope

What we are not

  • Not a web or marketing agency, and not general IT support.
  • Not a cheap-pentest shop competing on price.
  • Not "Big-4 lite" — we compete on speed, depth and a price that fits a smaller firm.
  • Not a licensed auditor or law firm — accredited partners complete those journeys, and we say so up front.
Advisers, MSPs, brokers, law firms

Refer a client. Earn 20% of their first engagement.

A simple, disclosed partner programme — commission-based or reciprocal, whichever fits your profession.

See the partner programme