Consulting
Technical privacy and AI assurance.
Privacy, compliance, AI governance, and technical assurance for UK organisations. We work where policy meets architecture: agents, data flows, model-connected products, identity, telemetry, and privacy-enhancing technologies.
Technical work
More than governance paperwork.
Good governance should be backed by tests, controls, and design choices that survive contact with a real system. We keep the sensitive mechanics private, but the work itself is technical.
AI agent evaluation
Capability boundaries, tool-use tests, prompt-injection exposure, memory and retrieval failure modes, human approval gates, and deployment evidence.
Privacy engineering
Data-flow reviews, AI context boundaries, telemetry discipline, PET suitability, vendor-risk surfaces, and architecture recommendations that engineers can act on.
Research-grade validation
Claims are treated as hypotheses: define the threat model, construct tests, record limitations, and publish only what survives without leaking sensitive details.
Governance with teeth
Policies, DPIAs, model cards, and board reporting are tied to technical controls, logs, monitoring, escalation paths, and real product behaviour.
Engagements
Choose a starting point.
GDPR Audit
A structured review of your organisation's data processing activities, policies, and controls against UK GDPR requirements.
View detailsOnline Safety Act
Assessment of whether and how the UK Online Safety Act 2023 applies to your digital service, with a compliance roadmap.
View detailsDPIA
A structured risk assessment for data processing activities that are likely to result in high risk to individuals, as required by UK GDPR Article 35.
View detailsAI Governance
Design and implementation of a governance framework for organisations deploying AI systems, aligned with the EU AI Act, UK AI regulatory principles, and ISO 42001.
View detailsAgent Assurance
Technical review of AI assistants, agentic workflows, and model-connected products: what they can do, where they fail, and what evidence is needed before wider rollout.
View detailsPrivacy Engineering
Architecture-level review for products handling sensitive data, AI context, telemetry, identity, or analytics, with practical privacy-enhancing technology recommendations.
View detailsPrivacy by Design
Technical and process review of a product or system to ensure privacy is embedded from the design stage, not bolted on later.
View detailsAdvisory Retainer
Ongoing access to privacy and compliance expertise on a retained basis. Includes a set number of hours per month for ad-hoc questions, reviews, and guidance.
View detailsTraining
Interactive sessions for teams on privacy, data protection, AI governance, or online safety topics.
View detailsHow we work
A three-step evidence loop.
01
Frame the claim
We define what the system, product, or compliance claim must prove, and what must stay confidential.
02
Test the system
We review evidence, architecture, controls, and failure modes with a practical technical lens.
03
Ship the evidence
You receive a prioritised remediation plan, a leadership summary, and public-safe wording where useful.
Important notice
All consulting is advisory, not legal advice. For legal opinions we refer to qualified data protection solicitors. Professional indemnity insurance is maintained on all engagements.
Not sure where to start?
Tell us about your organisation. We will scope the right engagement.
