Services

Tech, talent, and growth — under one roof.

Eighteen production services across engineering, remote talent, marketing, design, and security and compliance. One contract. One invoice.

Creative & Design · 1 service

Subscription design. Unlimited revisions, scoped to your active brand and product surface.

Security & Compliance · 7 services

Readiness, remediation and programme work. We implement the controls and close the findings; we never audit, attest or certify, and we take no fee from any auditor we introduce you to.

Compliance Readiness Assessment

The honest gap list, costed in engineer-days

A fixed-fee assessment of where you actually stand against SOC 2 or ISO 27001:2022, ending in a costed, sequenced remediation plan and a warm introduction to an auditor. We are not your auditor and legally cannot be — which is exactly why we can do this work.

From $12,500

Compliance Remediation Pod

Keep your Vanta. Keep your auditor. We ship the fixes.

Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.

From $15,000/mo

Agent Security & AI Governance Review

Answer the AI questionnaire, fix what it exposes

A fixed-scope review of a production agent or RAG system: what it can reach, how it gets abused, and how to rebuild it so the finding stops recurring. It ends with the AI-governance evidence pack your enterprise buyer is asking for, and the remediation shipped as pull requests.

From $18,000

Cyber Essentials Readiness (UK)

Pass Danzell first time, or find out why now

The April 2026 Danzell question set added auto-fail conditions the Willow set did not have, and brought AI and LLM tools into scope as cloud services. We get your estate to a state that passes, then hand you to an IASME-licensed certification body — we are not one and cannot certify you.

From £7,500

EU Cyber Resilience Act Readiness

The 11 September reporting clock, engineered for

From 11 September 2026, every manufacturer of a product with digital elements sold into the EU owes 24-hour early warning, 72-hour notification and a 14-day final report on actively exploited vulnerabilities and severe incidents — including on legacy products. This is the engineering work that makes that possible.

From $16,000

UAE PDPL & ISR Engineering Readiness

NESA, DESC ISR v3 and PDPL, on the build side

The UAE moved from voluntary guidance to mandatory resilience under the National Cyber Security Strategy. We map NESA, DESC ISR v3 and PDPL obligations onto your actual architecture and close the engineering half — with in-country processing and data-residency boundaries designed in, not retrofitted.

From $16,000

Compliance Programme Retainer

The internal audit your certification body can't do

ISO 27001 requires an internal audit and a management review every year, and your certification body is barred from performing either. We run them, resolve control drift before it reaches the auditor, and hold your evidence current through surveillance.

From $3,500/mo
Services FAQ

Common questions, straight answers.

Can I combine services on one contract?

Yes — one contract, one invoice, one account manager across any combination of services. Most clients start with one service and expand within 3 months.

Do I need a minimum commitment?

No. Direct Hire is a flat per-hire fee. Managed EOR is month-to-month with no lock-in. Build engagements are scoped per project — you choose fixed-scope or retainer.

How quickly can we start?

Discovery call within 24 hours. Talent shortlists in 72 hours. Build engagements kick off within 1 week of the signed brief.

Can you handle multi-country teams?

Yes — we operate in India, UAE, and the US directly; partner network covers 150+ countries for payroll and compliance.

What if we already have an internal team?

We supplement, not replace. Most engagements augment an existing in-house team with senior talent or a build pod for a specific project.

How do you bill?

Monthly invoice, USD, payable on Net-15 terms. No upfront deposit. We bill only after value is delivered (candidate starts, engineer joins, milestone shipped).

Are you a security company now?

No. We are an engineering and talent firm that implements security controls and staffs security engineers. Under ISO/IEC 17021 and the AICPA independence code, the firm that certifies you is barred from having consulted you — so the implementation half of compliance is permanently available to firms like us and permanently closed to your auditor. That is the half of the work we do.

Can you audit or certify us?

No, and no firm that helps you implement can. Only a licensed CPA firm can attest SOC 2, only a UKAS- or ANAB-accredited body can certify ISO 27001 or ISO 42001, and Cyber Essentials certificates come only from an IASME-licensed body. We do the readiness, the remediation and the audit liaison, then introduce you to an auditor — and we take no fee from them.

What security work will you not take?

Penetration testing under our own name, CHECK or ITHC work for UK public sector, Cyber Essentials certification, any audit or attestation, 24/7 monitoring, managed detection, incident response retainers, and US federal, ITAR or CMMC work. Some of those are legally gated and some we simply cannot staff to a standard we would defend. We refer the first group and decline the second.

WhatsApp us