The blog
Source-checked writing on compliance, AI security and cryptography, each article citing its primary sources so you can check the figures rather than trust them.
Resources
Working material rather than marketing collateral. Nothing here is behind an email form, because a checklist you have to trade your inbox for is an advert wearing a checklist’s clothes.
Available now
We publish something when it is genuinely useful to the people we work with, which is not often. Everything here is maintained rather than posted and forgotten — each page carries the date its facts were last checked.
Also useful
Most of what people ask us for is not a download. It is an answer, and those live on the site.
Source-checked writing on compliance, AI security and cryptography, each article citing its primary sources so you can check the figures rather than trust them.
The questions people actually ask before hiring us, including the awkward ones about price, capacity and what we cannot do.
The numbers behind the testing engine, published as scale rather than methodology — rule counts, CVE coverage and what that does and does not mean.
Every service page carries its own FAQ covering the questions that only apply to that piece of work.
Next step
The checklists are written to be used without us. If one of them tells you something you would rather not have found out, that is a good reason for a 30-minute call — no obligation, no charge.