AI consulting for European rules
AI consulting and cybersecurity advisory for European organisations — EU AI Act readiness, GDPR-compliant architectures, and readiness consulting for NIS2, DORA and ISO 27001 — delivered by the team that builds the systems.
AI Consulting
Strategy, EU AI Act readiness, and AI governance for organisations putting models into production under European law
Cybersecurity
Readiness consulting for NIS2, DORA, and ISO 27001 — plus the architecture reviews and AI-specific security work that has to hold up beneath them
Engineering Delivery
The same team builds what it recommends — production AI systems, cloud-native platforms, and the pipelines that keep them auditable
INFRASTRUCTURE · 001
Compliant by construction.
The delivery baseline we apply across every engagement. European obligations are cheapest to meet when they are designed in — retrofitting residency, audit trails, and least privilege costs several times more than building with them from the first commit.
EU Data Residency
EU-region deployment and self-hosted inference for workloads that cannot leave the jurisdiction
Auditable Pipelines
Versioned datasets, reproducible builds, and staged rollout — evidence produced as a by-product
Evidence & Documentation
Model cards, decision logs, and control records kept current instead of assembled before an audit
Hardened by Default
Least-privilege access, managed secrets, and signed artefacts as the baseline, not an upgrade
STACK · 002
The stack we ship with.
Industry-leading tooling chosen for reliability, ergonomics, and a clean blast radius — nothing more.
Infrastructure & DevOps
01Security & Compliance
02AI & Development
03Linux & System
04A few things we're working on
PARTNERS · 003
Trusted technology partners.
The platforms and protocols we lean on — chosen for reliability, performance, and the depth of their engineering teams.
Amazon Web Services
Cloud Infrastructure
Akamai Connected Cloud
Cloud Computing
Solana & Stellar
Blockchain Networks
PostgreSQL
Database Solutions
Convex
Reactive Database
Anthropic
Frontier AI Models
Cloudflare
Security & CDN
GitLab
Development Platform
Strategic Partnerships
Collaborating with industry leaders to deliver comprehensive blockchain and AI solutions
COMMON QUESTIONS
Before you write to us.
- Do you work with organisations across the EU?
- Yes. We work remotely with clients across the European Union, the EEA, the UK, and Türkiye, and travel for workshops and on-site assessments where the engagement calls for it. Engagements are delivered in English.
- What does EU AI Act readiness actually involve?
- It starts with classifying each of your AI systems against the Act's risk tiers, because the obligations that follow depend entirely on that classification. From there we map the required controls — technical documentation, data governance, logging, human oversight, and transparency to affected people — against what your systems do today, and give you a prioritised list of the gaps that matter most.
- Are you a consultancy or an engineering team?
- Both, deliberately. The people who write the assessment are the people who can implement it. That constraint keeps our recommendations to things that can actually be built, and it means you are not paying a second firm to interpret the first firm's deck.
- Does NIS2 apply to my organisation?
- NIS2 covers a much wider set of sectors than the directive it replaced, and scope depends on your sector, size, and the criticality of the service you provide. Determining whether you fall in scope as an essential or important entity is the first step of our gap assessment, before any remediation work is proposed.
- Are you certified under ISO 27001 or NIS2?
- No, and we say so plainly. We are a consultancy, not a certification or accreditation body: we hold no certification under these frameworks and cannot issue one to you either. What we do is the preparation work — assessing your controls against what those frameworks require, closing the gaps, and assembling the evidence so that the accredited auditor or the regulator finds what they need when they arrive.
- Can you keep our data inside the EU?
- Yes. For regulated workloads we design around EU-region infrastructure and, where a third-country model provider is not acceptable, self-hosted open-weights models running on infrastructure you control. Which of those applies is a decision we make with you during the architecture phase, not a default we impose.
- We already have AI in production — is it too late?
- No, and this is the more common case. Systems that are already live are exactly what a readiness review is for: we classify what you are running, find where it falls short of what the Act and your own risk appetite require, and sequence the fixes so the system keeps serving while the gaps close. Starting from a running system is usually faster than starting from a blank page, because the hard decisions have already been made.
- How does an engagement usually start?
- With a short call to establish what you run, what you are accountable for, and what is actually urgent. Most clients then take a scoped assessment — AI readiness or security gap analysis — that produces a prioritised roadmap. Delivery work follows only if you want us to do it.
Something not covered here? Ask us directly.
