Approach

Evidence first. Opinion second.

An assessment is only worth what it can withstand. Ours are built to survive the second question — from an auditor, an insurer, a customer's security team, or a board member who reads carefully.

The method

Three movements, every engagement.

The scope changes. The sequence does not.

01 / Establish

What is actually true

We do not begin with a questionnaire returned by whoever is most optimistic about the answer. We begin with evidence.

  • Stakeholder interviews across security, IT, engineering, legal, and the business units that quietly adopt tools first
  • Telemetry review — identity logs, third-party authorisations, administrative configuration, expense records
  • Artefact collection — existing policy, vendor agreements, architecture, prior findings
The gap between what an organisation believes is deployed and what is genuinely in use is, in our experience, the single most common source of audit findings.
02 / Model

How it realistically fails

Generic risk registers persuade nobody. We construct specific, plausible failure paths through your systems, named against frameworks your auditors already accept.

  • NIST AI RMF — the governance spine: Govern, Map, Measure, Manage
  • OWASP LLM Top 10 — the language for prompt injection, data disclosure, excessive agency, supply chain
  • MITRE ATLAS — adversary tactics against machine-learning systems, cited by technique
  • ISO/IEC 42001 and the EU AI Act — referenced where certification or European exposure is in play
One concrete attack chain described in your own architecture is worth more than forty pages of taxonomy. We aim for the former.
03 / Prioritise

What to do, in what order

Findings without sequence are a burden. Every engagement ends with a roadmap sized by effort and ordered by risk — and an executive readout your sponsor can carry upward without translating it first.

  • Immediate — what to close in the next thirty days
  • Ninety days — the structural work: process, review gates, logging
  • Twelve months — maturity: evaluation, monitoring, certification tracks where warranted
Each item carries an effort size and an owning role, so the plan survives contact with a budget conversation.
Principles

How we hold ourselves.

Independence is structural

We resell no third-party tooling and take no vendor commissions. No recommendation leads to a licence we profit from — which is the only durable guarantee that the advice is about you, not about our margin.

Seniority is not delegated

The person on your first call is the person doing the work and presenting the findings. No partner-sells, associate-delivers arrangement — it is simply not how a boutique should operate.

Scope is fixed, and honoured

A one-page proposal states deliverables, timeline, and price. If the work turns out to be larger than we scoped, that is our estimate to absorb, not your invoice to discover.

Access is minimal

Read-only, least-privilege, time-boxed, and granted in writing. We ask for the least we can do the work with — and we say so before you ask.

We decline work

If an engagement is not right — wrong problem, wrong timing, or a firm better suited to it — we will say so on the first call. A boutique's reputation is its only asset.

Plain language, always

Findings are written to be read by an executive without a translator, and by an engineer without condescension. If a sentence needs a glossary, it needs rewriting.

The measure of an assessment is not what it found. It is what changed in the ninety days afterwards. Axiomeer — Operating principle

See what the deliverables actually look like →

Getting started

Thirty minutes, and a candid read.

No pitch deck, no discovery invoice. Describe the pressure you are under and we will tell you what we would do about it.