Skip to content
The medieval curtain wall and towers of Aigues-Mortes standing against a low evening sky.

Secure. Comply. Transform.

The Citadel of Trust

In Rome, the arx was the fortified summit of the Capitol: the place that held when everything else fell.

Trust works the same way. It is not declared. It is built, and then defended.

We build it for mid-size companies — security, compliance, cloud and AI — with one senior partner, a fixed price and deliverables agreed before we start.

Why now

Four regulations, one window

They were written separately. They land on the same teams, in the same months, in companies that rarely have anyone assigned to them.

  • NIS2

    Applies since

    Extends EU cybersecurity duties to thousands of mid-size companies, and makes directors personally accountable for supervising them.

  • DORA

    Applies since

    Requires financial entities and their ICT providers to prove operational resilience, down to a register of every contract.

  • CRA

    Applies since

    Makes security a condition for placing a product with digital elements on the EU market. Reporting of actively exploited vulnerabilities comes first, then the full regime in December 2027.

  • AI Act

    Applies since

    Sets obligations by risk level for anyone providing or deploying an AI system, including companies that only use one.

The evidence these four texts ask for overlaps by roughly seventy per cent. Produced once, it answers all of them.

What we do

Four practices that talk to each other

Most firms will sell you one of these. The gaps between them are where incidents and audit findings live, so we keep all four in the same hands.

Cybersecurity

Hold the walls, and know where they are thin.

  • Governance, risk and strategy
  • Audit and offensive security
  • Architecture and protection
  • Detection, response and continuity
  • Cloud and AI security

Learn more — Cybersecurity

Compliance & Regulatory

Prove it once. Use the proof everywhere.

  • European cybersecurity regulation
  • Standards and certifications
  • Personal data
  • Artificial intelligence
  • Compliance governance

Learn more — Compliance & Regulatory

Cloud & DevSecOps

Security that ships with the code, not after it.

  • Cloud strategy and architecture
  • Foundation and migration
  • Governance, operations and cost
  • DevSecOps

Learn more — Cloud & DevSecOps

AI Transformation

Deploy it because it works, and because you can defend it.

  • Strategy and governance
  • Use cases and delivery
  • Trustworthy and secure AI

Learn more — AI Transformation

All services →

How we work

Six steps, no surprises

From first call to signed proposal in five working days, and from kick-off to board readout without a single unplanned invoice.

  1. Step 1 of 6

    Qualification call

    45 minutes, free

    A senior consultant, not a salesperson. We ask what is driving the deadline, what exists already, how many entities and systems are in scope, and who will have to approve the result. You get an honest read on feasibility and a range before we hang up — including, when it applies, the fact that you do not need us for this.

  2. Step 2 of 6

    Proposal

    Within 5 working days

    A written proposal with the scope, the deliverables listed item by item, the schedule with dates, the people involved, and a fixed price. No day-rate estimates with a range attached, and no discovery phase billed before the scope is known.

  3. Step 3 of 6

    Kick-off

    Week 1

    Framework contract and mutual non-disclosure agreement signed, insurance certificates provided, access requested and granted, stakeholders identified, and the reporting rhythm agreed. We confirm the schedule against your constraints — audits, releases, holidays — before anything starts.

  4. Step 4 of 6

    Delivery

    Per the schedule

    The work runs with a thirty-minute checkpoint every week: what was done, what was found, what is next, and anything that threatens the date. Significant findings are raised when we find them, not saved for the report. Work is done in your tools and your repository wherever possible.

  5. Step 5 of 6

    Readout and handover

    Final week

    A presentation to the people who have to act on it — usually the executive committee or the board — with the executive summary, the findings, and the costed action plan. Then a working handover with your team: the detail, the evidence, the configuration, and how to maintain it.

  6. Step 6 of 6

    Follow-on proposal

    Within 15 days

    A written proposal for what comes next, if anything does: targeted missions from the action plan, a recurring service to hold the ongoing work, or nothing at all. Sent within fifteen days of the readout so the decision is made while the findings are fresh, with no obligation attached.

See the engagement model →

Fixed price

Start with a pack

Eighty per cent of our catalogue is sold at a fixed price with deliverables defined upfront. You know the scope, the timeline and the cost before you commit.

Cyber 360 Flash

Three weeks to a clear picture: maturity, exposure and the ten things to fix first.

Duration
3 weeks
Price
€6,000 to €9,000
excl. VAT, indicative

Discuss this pack — Cyber 360 Flash

NIS2 Ready

From applicability to a defensible compliance position, with the governance duties covered.

Duration
8–12 weeks
Price
€18,000 to €35,000
excl. VAT, indicative

Discuss this pack — NIS2 Ready

AI Act Check

Every AI system inventoried, classified and dated, with the obligations that follow.

Duration
3–4 weeks
Price
€6,000 to €12,000
excl. VAT, indicative

Discuss this pack — AI Act Check

See all packs →

Who you work with

One senior contact, a network behind them

You work directly with a senior specialist in cybersecurity and compliance, with experience across data security, AI, software platforms and cloud. Not a sales lead who hands you to a junior after signature.

Where a mission needs a qualification we do not hold, or a jurisdiction we do not practise in, we bring in a vetted partner and stay accountable for the result. Penetration testing runs with PASSI-qualified teams, incident response with PRIS, managed detection with PDIS.

Read our story →

Where we operate

Directly from France, and through partners who practise locally.

Europe
France, Belgium, Luxembourg, Switzerland, Spain, Germany, Portugal, Italy
French-speaking Africa
Tunisia, Morocco, Senegal, Ivory Coast, Cameroon
South America
Brazil, Argentina, Colombia, Chile

Client references

Named client references are provided under NDA during the qualification call. Published testimonials will appear here once our first clients have authorised them in writing.

Client logos

Client logos

We publish a client logo only with written permission. This strip will fill as those permissions arrive.

Next step

Forty-five minutes, no obligation

Tell us what is coming — an audit, a deadline, a customer questionnaire, an AI project nobody has reviewed. We will tell you what we would do, in what order, and what it would cost. If we are not the right firm for it, we will say so.