Compliance and data protection, together.
We put in place the structure the regulation requires, build the IT systems that run it, and keep the data protected.When those three are split across suppliers, nobody owns the whole; here it is one team and one contract.
Three products that run your compliance
A consulting report sits on a shelf; a product runs every day. We develop, deploy and support all three ourselves.
Three pillars, one team
Compliance, software and data protection complete each other. When one is missing, the other two hang in the air.
All twelve servicesCompliance
Inventory, policy, risk analysis and audit records.
Software
The application and integrations that keep the rule off paper.
Data protection
Access, logging, backup and breach response.
We write the limits before we put AI into a system
Calling a model is easy. The hard part is deciding upfront which data goes, who approves, and what you will show in an audit.
Where the data stays
Which data reaches the model, which does not, how long it is kept — written into the contract.
Human approval stays
Model output is a suggestion, not a decision. Approval remains at the consequential step.
Every call is traceable
Input summary, model, output and timestamp are recorded.
The limits are written
What the model will not do is defined in the system prompt and the contract.
The two tools on this site follow the same rules
The compliance test and the site assistant on this site run on exactly the approach we deploy for clients: calls are server-side, the test score comes from your answers rather than the model, and what the output is not is written underneath. We apply to ourselves what we describe to others.
Not the consultant who writes a report and leaves
Most compliance projects get stuck in the same place: documents are delivered, the system to operate them never gets built.
One team, end to end
No chasing separate suppliers for compliance, software and security.
Evidence-based
We do not frighten you with penalty figures; we say what will be done and what will stand as proof.
One contract, one contact
One person owns the whole engagement from start to finish.
We tie the rule to software
Keeping the inventory current and answering requests on time is a system's job.
We build and hand over
The aim is capability, not dependency. Documentation and training are part of the delivery.
We apply it to ourselves
We operate the controls we recommend in our own processes — this site included.
The standards and legislation we work with
We provide implementation, audit readiness and operational support in these frameworks.
These are our areas of expertise; they are not certificates held by the company. Our certifications will be listed separately once ready to publish.
Our technology solution partners
We work with Microsoft, Palo Alto Networks and Forcepoint technologies, building the technical side of compliance on top of these products.
The legislation is the same; where it gets hard differs
We wrote out the three problems we meet most often in each sector.
Content that is not a sales pitch
Where to look when you need to read the legislation, find a term, or work through something step by step. All of it open, no sign-up.
The questions that come up most in first conversations
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
