Tenchi Start a conversation
Services

Security you can put in front of an auditor, a customer and an attacker.

Every engagement is scoped in writing before it starts: what we will deliver, what you will own afterwards, and how we will know it worked.

01

Certification readiness

SOC 2 Type 2 and ISO 27001, run as a programme rather than a paperwork exercise. Controls that engineering will actually keep using after the report is signed.

  • Gap analysis against the target framework and your customers' questionnaires
  • Policy set, control design and implementation with named owners
  • Evidence collection that runs on its own, not the week before the audit
  • Auditor selection, coordination and remediation through to opinion
02

Fractional CISO

Senior security leadership at the fraction of a full-time hire you need. Accountable for posture, present in the rooms where it is decided.

  • Security strategy and roadmap tied to product and revenue, not to a tool list
  • Enterprise risk register, risk assessments and treatment plans you can defend
  • Executive and board reporting: posture, incidents, compliance status
  • Vendor risk, due-diligence responses and regulated-customer assurance
03

Cloud & platform security

Architecture and configuration review across AWS, GCP and Kubernetes, done by someone who has run the infrastructure as well as reviewed it.

  • Cloud security posture, secure baselines and infrastructure-as-code review
  • Identity and access design, secrets management, least privilege that survives contact with engineers
  • Kubernetes hardening, network policy and workload isolation
  • Central logging, detection and alerting with owners for every alert
04

DevSecOps & secure SDLC

Security inside the pipeline, where it costs the least. Gates that block real risk and stay quiet the rest of the time.

  • Threat modelling, architecture review and code review on the paths that matter
  • SAST, SCA and DAST selected, tuned and triaged so findings get fixed
  • Build integrity, artefact provenance and dependency control
  • Software-supply-chain controls to SLSA levels 1 and 2, with in-toto attestation
05

Incident response & BC/DR

The plan that gets used at three in the morning, and the rehearsal that proves it works before you need it.

  • Incident response plan, severity model and SIRT roles with real escalation paths
  • Business continuity and disaster recovery planning, RTO and RPO you can meet
  • Ransomware resilience: immutable backups, isolation and tested restore
  • Tabletop exercises, root-cause analysis and corrective-action tracking
06

AI security & governance

Your teams are already using AI. Governance turns that from an unmanaged exposure into something you can describe to a customer or a regulator. We work to the EU AI Act and the NIST AI Risk Management Framework.

  • AI-system inventory and risk classification aligned to the EU AI Act
  • Governance mapped to the NIST AI Risk Management Framework — govern, map, measure, manage
  • Acceptable-use, accountability and human-oversight model
  • Security and privacy controls for model access, prompts and data flows
  • Vendor assessment for AI providers and AI features inside existing tools
07

Secure SaaS, AI-assisted

We build products, not only the controls around them. AI-assisted development compresses the delivery timeline; twenty years of security work keeps the shortcuts out of the architecture.

  • Product and platform architecture with the threat model written first
  • AI-assisted implementation with human review on every security-relevant path
  • Authentication, tenancy isolation, secrets and audit logging designed in from the start
  • Delivered on a cloud footprint that is already compliance-ready

Not sure which one you need?

Describe the deadline you are working towards. We will name the shortest path to it.

Get in touch