Security & Compliance
Built to be examined.
Role based access, audit trails and GDPR by design. We build systems that hold personal data of health professionals, tax records and case files of an ombudsperson institution, where the question is never only whether the software works but whether it can be defended in an audit.
Built to be examined.
Compliance is not a document produced at the end. It is access control, logging, retention and encryption designed into the system, so that when someone asks who saw this record and when, there is an answer.
Who can see what, decided as a structure.
Role based permissions modelled against the real organization, including delegation, temporary access and the separation of duties that regulated environments require.
Every meaningful action recorded.
Who did what, when, and what the value was before and after. Written to be readable by an auditor, not only by a developer.
Personal data handled as a liability, not a resource.
Lawful basis, minimisation, retention periods, subject access and deletion, designed into the data model rather than bolted on.
Security as part of building, not a review at the end.
Code review, dependency scanning, secrets management and environment hardening as standing practice on every project.
From data classification to systems that survive audits.
Classify
What data, and which rules apply.
Model roles
Permissions from real responsibility.
Log
Audit trails as a feature.
Encrypt
In transit and at rest.
Attack
We try to reach what we should not.
Review
Updated as regulation moves.
The systems we run for public institutions carry role based access and audit trails as core features, because the institutions using them have to account for every action.
One team, seventeen capabilities
We design, build and run custom software: web platforms, mobile products, AI systems and cloud infrastructure.
Highlighted is where you are. The rest is on the same team.