Tenchi Start a conversation
About

A security practice, not a security vendor.

Tenchi is a specialist cyber security firm working internationally with regulated SaaS, financial technology, blockchain and enterprise clients. We take on a small number of engagements at a time so the person who scoped the work is the person who does it.

What twenty years buys you

The practice grew out of two decades in information security: internal IT audit in banking, penetration testing and forensics, secure software engineering, DevOps and DevSecOps leadership, and finally company-wide security ownership at a cloud platform serving regulated EU financial institutions.

That range is the point. Audit experience means we know what evidence has to look like. Engineering experience means the controls we design can be implemented without stopping delivery.

Strategy and governance
Security strategy, risk management, policy, board reporting, vendor risk, certification programmes.
Engineering and cloud
AWS, GCP, Kubernetes, Terraform, Ansible, CI/CD, secrets management, detection and logging.
Assurance and resilience
Threat modelling, SAST/SCA/DAST, penetration testing, incident response, BC/DR, forensics.

Selected work

Client names stay confidential. These are the engagements that shaped how we work.

Regulated fintech platform

Company-wide security strategy, SOC 2 Type 2 and ISO 27001 through external audit, enterprise risk register, incident response and BC/DR governance, and EU AI Act-aligned AI governance.

Global blockchain network

CI/CD security, build integrity, artefact handling and dependency control for one of the largest blockchain implementations in the world, plus event and mobile risk assessments.

Enterprise supply chain

Secure build pipelines using SLSA concepts and in-toto attestation, demonstrated to enterprise clients as a reference implementation.

Banking IT audit

CobiT, ITIL and ISO 27001 audits with risk findings and remediation recommendations presented to a management board.

Securing IoT platforms

Security ownership for a connected-device platform: authenticated device access and credential lifecycle, segmented device-to-backend communication, hardened infrastructure with baselines enforced in code, and central logging for detection across the fleet.

Own product

An online marketplace platform designed and built end to end with AI-assisted development: architecture, implementation, testing and iterative delivery.

How we work

Remote-first and international. Written scope before the work starts, written findings when it ends, and a handover that leaves your team able to run what we built.

  • We say what we would not do. Security budgets are finite and most risk registers are too long.
  • Controls are designed with the engineers who will operate them, not handed to them.
  • Every engagement ends with documentation your next auditor can read.
  • If a fixed scope is the honest answer, we quote a fixed scope rather than a retainer.

Work with us

One email is enough to start. Tell us the platform, the deadline and who is asking.

Get in touch