What we do
- ISO 27001 as your implementation partner: gap analysis, ISMS scoping, control implementation, internal audit, and the evidence tooling that keeps it current between surveillance audits. We have taken clients through to certification and run the penetration testing the auditor asked for.
- GDPR engineering: data maps, retention enforcement, DPA-ready processing records, and EU data residency enforced in the architecture.
- NIS2 and DORA readiness: risk registers, incident-reporting workflows with the statutory clocks built in, supplier oversight, and the DORA Register of Information.
- EU AI Act evidence: logging, technical documentation, and model monitoring that the systems generate as they run.
Why an engineering firm
Compliance consultancies write policies. We change the systems the policies describe. When the control is enforced in code, the evidence writes itself and the auditor finds what the document promised.
We are not certified ourselves, and we say so on the trust page. What we bring is the implementation side: the engineers who build the controls, run the internal audit, and test the result before your certification body does.
We run our own operations the same way: Dutch B.V., standard DPA with every engagement, NDA within 24 hours, EU data residency for anything we host.