Security & governance
The speed of AI. The discipline of a CISO.
AI makes building fast. It does not make building safe. Every system here gets a security wrap as standard, not as an upsell.
The security wrap is the set of controls we apply to every build before it goes live: row-level access control, secrets management, authentication hardening, security headers, a pre-launch scan and a written security statement you can show your own customers.
Standard on every build
What the security wrap includes
These are not optional extras. They are part of the fixed price.
- 01
Row-level security
Enabled and policy-reviewed on every table, so data access is enforced by the database rather than assumed by the app.
- 02
Secrets management
Keys and credentials held server-side in managed secret storage, never shipped to the browser or committed to a repository.
- 03
Authentication hardening
Sensible session handling, role separation and least-privilege access reviewed before anyone logs in for real.
- 04
Security headers
Transport and browser protections configured at the edge, so the basics are not left to defaults.
- 05
Pre-launch scan
An automated and manual pass over the build before go-live, with findings fixed rather than filed.
- 06
Written security statement
A plain-English document describing what was done and how the system is protected — something you can show your own customers.
When security happens
Not bolted on at the end
Security is a scheduled stop in the build, not a final tick-box.
Partway through the development build we pause. Our CISO consultants assess the data-security needs of your business: what data the platform holds, your UK GDPR obligations, whether you hold or are working towards ISO 27001 or Cyber Essentials, and any sector-specific requirements such as the DSPT for health and social care.
We then work with you to put the relevant documentation and processes in place — data-handling, access control, retention and incident response — and confirm the platform's data handling is secure. Only then do we go live, with a written security statement you can show your own customers.
Governance
Support beyond the build
Delivered with contract CISOs, DevOps engineers and governance specialists from a vetted network.
Cyber Essentials alignment
ISO 27001 alignment
DSPT support for care providers
A note on wording: work here is aligned to recognised standards. No one can honestly promise an unbreachable or guaranteed-secure system, and we won't.
Rescue
Nervous about an app you've already built?
If you have an AI-built app in front of customers and nobody has checked the database rules, a fixed-price audit is the cheapest hour you'll spend this quarter.
FAQ
Common questions
Are AI-built apps secure?
- Not by default. In 2025 a single misconfiguration class exposed customer data across more than 170 AI-generated apps because database security was never switched on. Speed is now the easy part; the discipline to secure what was built is what most fast builds skip.
What is included in the security wrap?
- Row-level access control, secrets management, authentication hardening, security headers, a pre-launch scan and a written security statement — applied as a distinct stage before go-live, not bolted on at the end.
Are you certified?
- We align builds to Cyber Essentials and ISO 27001 and support DSPT for care providers, working with contract CISOs and governance specialists. We describe our work as aligned to those standards; we do not claim certification on your behalf.
Can we get a security audit without a build?
- Yes — that is the Rescue package: a fixed-price audit of an existing app, £750–£2,500, with a prioritised fix plan.