Consulting

Technical privacy and AI assurance.

Privacy, compliance, AI governance, and technical assurance for UK organisations. We work where policy meets architecture: agents, data flows, model-connected products, identity, telemetry, and privacy-enhancing technologies.

Technical work

More than governance paperwork.

Good governance should be backed by tests, controls, and design choices that survive contact with a real system. We keep the sensitive mechanics private, but the work itself is technical.

AI agent evaluation

Capability boundaries, tool-use tests, prompt-injection exposure, memory and retrieval failure modes, human approval gates, and deployment evidence.

Privacy engineering

Data-flow reviews, AI context boundaries, telemetry discipline, PET suitability, vendor-risk surfaces, and architecture recommendations that engineers can act on.

Research-grade validation

Claims are treated as hypotheses: define the threat model, construct tests, record limitations, and publish only what survives without leaking sensitive details.

Governance with teeth

Policies, DPIAs, model cards, and board reporting are tied to technical controls, logs, monitoring, escalation paths, and real product behaviour.

Engagements

Choose a starting point.

GDPR Audit

A structured review of your organisation's data processing activities, policies, and controls against UK GDPR requirements.

View details

Online Safety Act

Assessment of whether and how the UK Online Safety Act 2023 applies to your digital service, with a compliance roadmap.

View details

DPIA

A structured risk assessment for data processing activities that are likely to result in high risk to individuals, as required by UK GDPR Article 35.

View details

AI Governance

Design and implementation of a governance framework for organisations deploying AI systems, aligned with the EU AI Act, UK AI regulatory principles, and ISO 42001.

View details

Agent Assurance

Technical review of AI assistants, agentic workflows, and model-connected products: what they can do, where they fail, and what evidence is needed before wider rollout.

View details

Privacy Engineering

Architecture-level review for products handling sensitive data, AI context, telemetry, identity, or analytics, with practical privacy-enhancing technology recommendations.

View details

Privacy by Design

Technical and process review of a product or system to ensure privacy is embedded from the design stage, not bolted on later.

View details

Advisory Retainer

Ongoing access to privacy and compliance expertise on a retained basis. Includes a set number of hours per month for ad-hoc questions, reviews, and guidance.

View details

Training

Interactive sessions for teams on privacy, data protection, AI governance, or online safety topics.

View details

How we work

A three-step evidence loop.

01

Frame the claim

We define what the system, product, or compliance claim must prove, and what must stay confidential.

02

Test the system

We review evidence, architecture, controls, and failure modes with a practical technical lens.

03

Ship the evidence

You receive a prioritised remediation plan, a leadership summary, and public-safe wording where useful.

Important notice

All consulting is advisory, not legal advice. For legal opinions we refer to qualified data protection solicitors. Professional indemnity insurance is maintained on all engagements.

Not sure where to start?

Tell us about your organisation. We will scope the right engagement.