Skip to content

Security and compliance

Systems that pass the review your customers, auditors, regulator and insurer will put them through, including the AI ones.Security architecture, review and remediation for the systems you run and the ones we build. ISO 27001 and Cyber Essentials readiness, EU AI Act readiness and AI governance mapped to ISO 42001, audit trails a regulator will accept, penetration test remediation, and the evidence a compliance colleague can file.

  • Companies whose largest customer has just sent a supplier security questionnaire.
  • IT directors preparing for ISO 27001, Cyber Essentials Plus, or a renewal.
  • Businesses in regulated sectors that need to show how their software handles data.
  • Deployers and providers of AI systems that the EU AI Act names as high-risk, and compliance functions asked to sign them off.
  • Firms whose auditor or regulator wants an audit trail the system produced rather than a record assembled afterwards.

Each capability has its own page with deliverables, process, measures and questions answered.

Engagement models that fit this service, in order of how often clients choose them.

  1. Stage 1.

    A fixed-price, fixed-length look at an idea, a process or an existing system, ending in a written report your board can act on: what it would take, what it would cost, and whether it is worth doing. Feasibility studies, technical assessments and due diligence all start here.

    Best for: Before committing to a build, a migration or an AI initiative. Also the starting point for a security review, an EU AI Act assessment, or due diligence on a system you are buying.

  2. Stage 2.

    Delivery and iteration

    Monthly retainer on 30 days’ notice, or fixed price per phase

    Software built or changed by a team in one of two shapes: embedded inside your business, on your tools and in your meetings, or run in-house at Hexploits with your stakeholders joining the demos. Bring a specification or we write one with you. Either way you get a written report every week, a working demonstration every fortnight, and live progress against the KPIs agreed at the start.

    Best for: Every build, integration, migration or AI system. Embedded when you have an internal team to work alongside; in-house when you would rather hand the work over and see it at the demo.

  3. Stage 3.

    Deployment and monitoring

    Rolling, 30 days’ notice

    Someone to own a system that is already live: deployment pipelines, monitoring, patching, backups, on-call and support, on a monthly contract with response times in writing. The monthly figure includes two hours of incident work; anything beyond that is billed per engineer per hour. Runs on your existing stack or on Hexploits Cloud.

    Best for: Anything in production that matters, where you would rather one contract covered deployment, support and small changes. Most clients choose it after a build; none are obliged to.

Technologies we’ve used on recent projects.

  • Languages

    • Java
    • Python
    • JavaScript
    • TypeScript
  • Frameworks & runtimes

    • Node.js
    • Spring Boot
    • .NET
    • Django
    • Flask
    • React
    • Next.js
  • Data & AI

    • PostgreSQL
    • SQL Server
    • pgvector
    • Claude
    • OpenAI
    • Open-weight models
  • Cloud & edge

    • AWS
    • Google Cloud
    • Azure
    • Cloudflare
    • Hexploits Cloud
  • Platforms & delivery

    • Kubernetes
    • Docker
    • AWS Lambda
    • Terraform
    • Helm
    • Argo CD
    • GitLab CI
    • GitHub
  • Monitoring & observability

    • Grafana
    • Loki
    • Prometheus
    • OpenTelemetry

We’re familiar with modern technology stacks beyond those shown here, and work with the languages, frameworks and platforms your business already uses.

Verified reviews, linked to Google where they were left there.

  • Director, IO Solutions

    Fantastic to work with. High level of attention to detail and flawless communication throughout. Would recommend to anyone looking to develop or improve a software product.

    Christian LorzaDirector, IO SolutionsRead the review
  • Director, Lothbury

    Top quality delivery, and reasonable price. Will be using again.

    Peter DentonDirector, LothburyRead the review
  • Director, PeppaSync

    Hexploits have been a breath of fresh air on Peppasync, an AI/ML autonomous decision platform for commercial leaders in retail and ecommerce. The depth and thoroughness the team brought to design and architecture was second to none.

    Banky AlaoDirector, PeppaSyncRead the review
Do you hold ISO 27001 yourselves?
Not today. Our engineering practice is built to ISO 27001-aligned controls and we say so as alignment, not certification. Our insurance cover, security practices and subprocessors are on the trust page, and we complete client security questionnaires with evidence.
Is this a penetration test?
No. We work with independent testers and we remediate. Keeping the testing independent is better for you and for the report.
Can you fill in our customer’s security questionnaire?
Yes. A completed questionnaire, with evidence, is a normal deliverable of a discovery engagement.
Do you cover the EU AI Act and AI governance?
Yes. EU AI Act readiness, AI governance mapped to ISO 42001, and the sector pages for finance and recruitment sit under Applied AI because the work is engineering, and they are listed on this page because a compliance function usually owns the question. We are the core engineering team behind swarmd.ai, an EU AI Act readiness platform.
What does an audit trail a regulator will accept look like?
Immutable, attributable and complete: every change and decision recorded with who, when and why, in a log that cannot be edited, produced by the system as it runs. We build it into the systems we deliver and retrofit it to systems we take over, and it is what swarmd.ai ships as its product.

Request a proposal.

Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.