03 · Consultancy

Independent judgement for AI and security projects.

Your partner to decide, oversee and correct: in new or ongoing projects, in-house or outsourced, in any country. No licences to sell, no vendors to defend.

Barcelona · 41.39° N, 2.17° E · Spain · Europe · Global

IndependenceWe do not resell licences or take vendor commissions.
The people who assess also buildThe same specialists who audit and build.
Reports built for decisionsConclusions in management language, with evidence.

Services

Three ways to support your project

Before deciding, during delivery or when something does not add up. Every engagement is agreed with scope, deliverables and schedule in writing.

01

Assessment and due diligence

Technical and risk assessment of an application, an AI integration or a vendor before contracting, investing or launching. A report with quantified risk and prioritised recommendations.

For management, investors and procurement leads who must decide on technology they did not build.

What is included

  • Architecture, code and dependency review
  • Vendor assessment and review of their security questionnaires
  • AI system risk analysis: data, permissions, compliance
  • Technology due diligence in investment or acquisition deals
  • Executive report with risk, remediation cost and priority

What is not included

  • Financial valuation of the company
  • Financial audit

The assessment is carried out by people who audit and build systems every day, not by a checklist.

02

Project and vendor oversight

Independent oversight of AI developments and integrations delivered by third parties: scope, quality, security and compliance reviewed at every milestone, with reports to management.

For organisations that outsource development and need their own judgement on the client side.

What is included

  • Scope definition, acceptance criteria and milestones
  • Delivery review: code, security, performance and documentation
  • Compliance control: GDPR, AI Act, DORA, CRA
  • Risk and scope-change management
  • Regular reporting to management and a recommendation at every decision

What is not included

  • Administrative contract management

We review with the same offensive tests we apply to our own developments.

03

AI strategy and technical leadership

What to automate, with which model, where to host the data and what regulation requires: a roadmap with owners and dates, and ongoing technical support when needed.

For companies that want to adopt AI with a plan and no in-house technical structure, or one that needs reinforcement.

What is included

  • Process diagnosis and use cases with measurable return
  • Model and vendor selection; data residency and governance
  • Twelve-month roadmap with owners, dates and budget
  • Fractional CTO or CISO and a regular technical committee
  • Training for management and technical teams

What is not included

  • Implementation of third-party software as a commercial partner

The strategy is written by the people who can build it and audit it afterwards.

How we work

Fixed engagements, no lock-in

Every engagement is scoped in writing and ends with a deliverable your team can act on independently.

ScopeGoal, systems involved, deliverables and schedule agreed before we start; fixed budget.
AccessNDA and GDPR Article 28 processor agreement before any information is received; evidence encrypted and deleted at close.
DeliverablesExecutive report, technical report and prioritised action plan; management presentation included.
ContinuityIf execution is needed, we can do it from cybersecurity or AI & development; if not, the plan stays with your team.

Next step

Tell us what decision you are facing

In an initial thirty-minute conversation we identify what to assess or oversee and propose scope and schedule in writing.

→

When you write to us, we process your contact details only to handle your request, as set out in our privacy policy.

Scope
Spain, Europe and international, remote
Languages
Spanish, Catalan, English, German
Independence
No vendor commissions, no licence resale
Data
Hosted in the EU; NDA signed before any information is received