Founding Practice

This Page Is Deliberately Empty

We're a new practice. We don't have case studies yet, and we're not going to borrow anyone else's or invent them. When we've done the work, this is where it will go — named or anonymised, with the client's permission.

Founding Client Work

Our first three engagements are priced differently

We need references more than we need margin right now, and that's a trade worth making explicit rather than dressing up. Founding clients get materially reduced pricing. In exchange we ask to publish the engagement as a case study — anonymised if you prefer, and only with your review and sign-off.

  • Senior attention — you get the principal, not a junior with a checklist
  • You keep every deliverable whether or not you continue with us
  • Case study published only after your review, or not at all
  • If we find you don't need us yet, we'll say so and stop the clock
Ask About Founding Pricing
Informed Opinion, Not Client Data

How We'd Approach A Rollout

Drawn from published guidance and the documented failure modes of the tools involved — not from a client base we don't have yet. Judge it on whether it sounds right to you.

Monitor before you enforce

Run any new policy in observation mode against real traffic first. It turns "will this break something?" into a data question you can answer before anything is blocked from a user.

Start with the pipeline in the deal

Cover the one system that's currently blocking a contract or an audit. A tidy full-estate rollout plan is easier to write and much harder to get funded.

Legal wants the evidence, not the filter

Engineering cares about the enforcement. Legal cares about the record of it. The logging is usually what makes the internal case, so don't treat it as an afterthought.

Fail-closed only where it earns it

Blocking on failure makes sense for health data and credentials. Applied to everything, it produces an outage, and the control gets switched off after the first incident.

Inventory first, always

Most teams can't produce a list of every model call in their product. You can't govern what nobody has written down, and the list itself is often the most valuable thing we hand over.

No control catches everything

Output filtering reduces risk. It doesn't eliminate it. It belongs alongside data minimisation at the source and human review for consequential decisions — never instead of them.

Our Commitment

What Will Appear Here, And What Won't

Will publish
  • Engagements we actually ran, with the client's written sign-off
  • Numbers we measured ourselves, with the method stated
  • Quotes from people who said them and approved the wording
  • The engagements that didn't go to plan, and why
Won't publish
  • Composite or illustrative "clients" presented as real
  • Benchmark figures we haven't run ourselves
  • Logos of companies that merely evaluated us
  • Anything a client hasn't read before you do

If you're evaluating us, that list is the most useful thing on this page. We're asking you to trust us with a governance function — the standard we hold our own marketing to is a reasonable proxy for the standard we'll hold your evidence to.

Be the first story on this page

Start with whichever pipeline is currently holding something up.