Event 23 Sep · New York Africa Digital Futures Forum Building Africa’s digital infrastructure for secured identity, governance and compliance. Register (opens in a new tab)

Services

Every practice,
one accountable team.

You get one team and one point of accountability across every practice — not a different vendor for each, blaming the others. Every engagement ends with something your own people can run.

01

Consulting

Deciding what to build, buy, or retire.

Most of the money is lost before anyone writes code — in the wrong system, bought for the wrong reason. We sit on your side of the table while that decision is made.

  • Current-state review of what you already run
  • Build / buy / retire recommendation, written down
  • Costed roadmap with sequencing
  • Vendor selection support
Talk to us about a review

How we assess

Build, buy or retire — scored against cost, risk and time A scored matrix. Buying is cheapest, building carries the lowest risk, retiring is fastest. Each axis names its own winner, so the trade-off is made explicit rather than assumed. BUILDBUYRETIRE COSTRISKTIME Higher spend Your build cost Cheapest Licence only Licence cost Sunk, then gone Lowest risk You control it Vendor lock-in Their roadmap Migration risk Data has to move Longest Months, not weeks Medium Config and rollout Fastest Switch it off Best on this axis — scored, not asserted
Scroll to see the whole diagram

02

Software Solutions

Products built to run in production.

Not a prototype that impresses in a meeting. Software that carries real load, real users and real data — with a handover your own team can pick up.

  • Web and mobile applications
  • Integrations with systems you cannot replace
  • Deployment, monitoring and runbooks
  • Documented handover to your team
Talk to us about a build

How we build

Design, build, test, deploy, operate — with what is running fed back in A five stage pipeline on a single spine, ending at Operate, with a dashed line carrying measurements from the running system back to Design. Everything is version controlled, tested in CI, and handed over with documentation. Design Build Test Deploy Operate MEASURED, THEN FED BACK IN Version controlled Nothing untracked Tested in CI Every change Handover docs Your team can run it
Scroll to see the whole diagram

03

Cyber Security

Security you can show an auditor.

A security programme is not a certificate. It is a threat model, closed gaps, tested controls, and evidence you can put in front of a regulator or a board.

  • Threat modelling and risk assessment
  • Penetration testing with reproduction steps
  • Security programme design and policy
  • Assurance evidence and reporting
Talk to us about security

How we assure

Defence in depth — policy, network and access around the data Concentric rings labelled policy, network and access surrounding the data at the centre. Beside them, four commitments: a written threat model, control gaps closed by real exposure, controls tested rather than assumed, and evidence an auditor can follow. DATA POLICY NETWORK ACCESS Threat model Written down, agreed, revisited Control gaps closed Prioritised by real exposure Tested, not assumed Findings with reproduction steps Evidence you can show An auditor can follow the trail
Scroll to see the whole diagram

Within this practice

ISO Certification & Training

Build systems that meet global standards — and keep performing beyond certification.

  • ISO 27001
  • ISO 9001
  • ISO 22301
Talk to us about ISO certification

What it covers

  • Global standardisation of your processes
  • Risk, controls and business continuity
  • Lead auditor training for your team
  • Gap assessment through to certification

04

NDPR Compliance Audit

Know what personal data you hold, and where it goes.

Most organisations can produce a privacy policy. Far fewer can produce the inventory behind it — what personal data they hold, which system it sits in, who can reach it and why it was collected. Everything the regulator asks for is downstream of that record, so that is where the audit starts.

  • Data mapping across every system, source and flow
  • Privacy impact assessments, run before you build
  • Annual audit return prepared for NDPC filing
Talk to us about a data audit

How we audit

Every source in, every disclosure out, against one inventory Personal data arrives from web forms, HR records and card payments into a single inventory holding the field, its source, its lawful basis and its retention period. From there it is disclosed onward to a payroll bureau, cloud hosting and analytics. The flow to analytics is drawn dashed because no lawful basis has been recorded against it — an unmapped disclosure is the finding an audit exists to surface. COLLECTED FROM HELD IN DISCLOSED TO Web forms HR records Card payments Payroll bureau Cloud hosting Analytics INVENTORY Field, source, basis No lawful basis recorded — the finding an audit exists to surface
Scroll to see the whole diagram

The rest

05 — 10

05

Tech Support

Advisory and hands-on support for systems already carrying load — the people to call when it matters.

Talk to us about Tech Support

06

Training

Hands-on skills for enthusiasts and professionals entering the sector, taught by people who ship.

Talk to us about Training

Not sure which practice you need?

Tell us the problem rather than the service. A short call is usually enough to work out whether this is a consulting question, a build, or a security one.