Design, build, and operate your infrastructure aligned with GDPR and NIS2 without slowing your roadmap.
From architecture assessments to managed compliance ops, we deliver secure infrastructure platforms with data residency and audit-ready evidence.
Deliverables
Concrete deliverables, not a capability list. Most engagements start with the first item and continue into one of the others.
- Architecture assessments
- A written review of what you run now against what your obligations require, with the gaps ranked by how much they would cost to close.
- Platform design for regulated environments
- Platforms designed so that data residency, access boundaries, logging — and, since the Data Act, the ability to leave — are properties of the architecture rather than things bolted on before an audit.
- Managed Kubernetes, provider-neutral
- Cluster design, networking, identity, secrets, multi-tenancy and upgrade strategy — the parts that are difficult to change later. The same definitions target AWS EKS or an EU provider such as Scaleway Kapsule, so where a cluster runs stays a residency decision rather than an architectural one.
- Zero-trust service networking
- Traffic between cluster workloads authenticated and encrypted by default with mutual TLS, and authorisation expressed as identity-based policy rather than network location. We implement this with Linkerd. Scoped honestly: this is zero trust for service-to-service traffic, not for users and devices, which are different problems with different answers.
- GitOps
- Every change to a running system arrives as a reviewed commit. This is what makes change control demonstrable instead of asserted.
- Policy as code
- Admission policies that reject a non-compliant workload before it runs, rather than reporting it afterwards — implemented with Kyverno. The control and the proof it was enforced are the same artefact.
- AI/ML infrastructure on Kubernetes
- GPU scheduling, model serving and data pipelines on the same governed platform as everything else, rather than a shadow estate beside it.
- Managed compliance operations
- Ongoing operation of the platform with the evidence an auditor asks for produced as a by-product: who changed what, when, approved by whom, and where the data sat.
How we build
Developers get the same cluster experience on their laptop as in production. A single bootstrap CLI, written in-house, creates a local k3d cluster and a managed cluster from the same definitions — so what passes locally is not a different system from what runs in the cloud. Which managed provider is a separate decision: AWS EKS, or an EU provider such as Scaleway Kapsule where residency has to be answered in Europe.
Everything is infrastructure as code and everything is reviewable in Git. That is partly an engineering preference and partly a compliance one: a reviewed commit history is the cheapest audit evidence there is, and it exists whether or not anyone asks for it.
The mesh's authorisation policies live there too. Which services may talk to which is a file, not a firewall someone configured by hand two years ago — so the answer to "how is internal traffic restricted?" is a diff with a history rather than a screenshot.
Common starting points
Most work begins as one of these, and often continues into the others.
- Compliance readiness assessment — the controls your obligations require, from GDPR to NIS2 and its national transposition to the Data Act and the AI Act, mapped to what you already run, with the governance gaps separated from the technical ones.
- Kubernetes platform build with GitOps — multi-environment cluster design, Argo CD delivery, and local parity for the engineering team.
- Data residency review — where data actually sits, versus where the DPA says it does.
How an engagement starts
- An intro call. Half an hour. You describe the obligation or the system; we say whether we are the right people and what we would look at first.
- A scoped assessment. A review with a written finding at the end — what is in place, what is missing, what it would take to close.
- Then, if it makes sense, the work itself. Advisory, implementation, or ongoing compliance operations.
We reply to everything ourselves. No intake form, no chatbot, no sales sequence.
