F.5 · Cybersecurity & Compliance
Compliance, Audit & Risk Management
Controls mapped to the code path that implements them

What we build
Getting to a certification and staying there. Gap assessment against ISO 27001, SOC 2, IEC 62443, PCI DSS, HIPAA, GDPR, and the DPDP Act, controls mapped to the architecture and to the code path that implements them, policy written to be followed rather than filed, evidence collection automated wherever the system can produce it, internal audit and readiness review, and support through the external audit itself.
Capabilities
- Gap assessment against ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, DPDP, and IEC 62443
- Controls mapped to the architecture and to the code path that implements them
- Policies written to be followed, and a register that shows who has actually read them
- Evidence collection automated wherever the system can produce it itself
- Internal audit, readiness review, and remediation tracked to closure
- Support through the external audit, including answering the awkward questions
Related services
How it connects
Where it sits in the stack.
This service, and the two it hands off to. None of them can be optimised alone.
Compliance & Risk
Getting to a certification and staying there.
Security Architecture
Security designed into the architecture rather than added at its edge.
Cybersecurity & Compliance · see serviceManaged Detection & Response
Continuous monitoring and response across endpoints, identity, cloud, and network.
Cybersecurity & Compliance · see serviceBring us the whole problem.
Tell us where the work is stuck, whether that is a model that never reached production, an application nobody can change, a data platform nobody trusts, or a plant the business cannot see. An engineer replies with a first read, not a sales deck.