What we do

Five services. Here is what each covers and what you leave with.

Scoped project or standing mandate, the rule is the same: whoever defines the work does the work, and at the end you get a document you can use.

PenTest

Offensive Security

We test applications, networks, cloud and people the way an outsider would, then hand you every finding with steps to reproduce it and an order for fixing.

  • Web & API penetration testing
  • Internal & external network testing
  • Cloud configuration review (Azure, AWS, M365)
  • Phishing & social-engineering simulation

You leave with A report with findings ranked by risk, reproduction steps and fix guidance.

Governance

Compliance & Audit

We map your obligations - ISO 27001, SOC 2, NIS2, GDPR and, where they apply, Moldova's Law 195/2024 and HG 562/2025 - to controls you can actually operate, then get you ready for the audit. An ISO 27001 certificate carries most of the way; we help you get there.

  • Gap assessment against ISO 27001, SOC 2, NIS2 and local regimes
  • Data protection under GDPR or Law 195/2024: records of processing, DPIA, breach procedures
  • Policies, risk register and control design
  • Audit preparation and evidence collection

You leave with A prioritised roadmap and an evidence file mapped to each requirement.

Infra

Infrastructure Review

We go through what holds everything up: network, cloud, identity, backups. We look at the real configuration, not the diagram.

  • Network architecture & segmentation review
  • Cloud & identity configuration (Azure, AWS, M365, AD)
  • Resilience: backup, recovery & continuity
  • Hardening baseline for critical systems

You leave with A report of the weak points, ranked by impact, with hardening steps in the order that reduces risk fastest.

Agentic AI

AI-Agent Governance & Security

Copilots and AI agents reach real data and real systems. We define what they may touch, test what happens when someone tries to hijack them, and write a policy you can enforce.

  • Inventory of AI use across the organisation and a risk map
  • Access boundaries for agents and integrations
  • Usage policy aligned with GDPR and local data-protection law
  • Adversarial testing: prompt injection and data leakage

You leave with An enforceable AI usage policy, a risk register and the test results.

Not sure which one you need?

Start with a 30-minute call. We'll tell you where you stand and what is worth doing first.

Book a call