Resources

Things you can use without talking to us first.

Working material rather than marketing collateral. Nothing here is behind an email form, because a checklist you have to trade your inbox for is an advert wearing a checklist’s clothes.

Available now

Short list, and it stays short.

We publish something when it is genuinely useful to the people we work with, which is not often. Everything here is maintained rather than posted and forgotten — each page carries the date its facts were last checked.

Also useful

The rest of it is already published.

Most of what people ask us for is not a download. It is an answer, and those live on the site.

The blog

Source-checked writing on compliance, AI security and cryptography, each article citing its primary sources so you can check the figures rather than trust them.

The FAQ

The questions people actually ask before hiring us, including the awkward ones about price, capacity and what we cannot do.

Detection coverage

The numbers behind the testing engine, published as scale rather than methodology — rule counts, CVE coverage and what that does and does not mean.

Service FAQs

Every service page carries its own FAQ covering the questions that only apply to that piece of work.

Read the blog

Next step

Read it, then tell us where you are stuck.

The checklists are written to be used without us. If one of them tells you something you would rather not have found out, that is a good reason for a 30-minute call — no obligation, no charge.