Security and compliance
Systems that pass the review your customers, auditors, regulator and insurer will put them through, including the AI ones.Security architecture, review and remediation for the systems you run and the ones we build. ISO 27001 and Cyber Essentials readiness, EU AI Act readiness and AI governance mapped to ISO 42001, audit trails a regulator will accept, penetration test remediation, and the evidence a compliance colleague can file.
Who this is for
- Companies whose largest customer has just sent a supplier security questionnaire.
- IT directors preparing for ISO 27001, Cyber Essentials Plus, or a renewal.
- Businesses in regulated sectors that need to show how their software handles data.
- Deployers and providers of AI systems that the EU AI Act names as high-risk, and compliance functions asked to sign them off.
- Firms whose auditor or regulator wants an audit trail the system produced rather than a record assembled afterwards.
What’s included
Each capability has its own page with deliverables, process, measures and questions answered.
Security architecture review
Threat modelling and design review of existing and planned systems, with a prioritised remediation plan.
ISO 27001 and Cyber Essentials readiness
Technical controls, policies and evidence collection mapped to the standard you are certifying against.
Identity and access
Single sign-on, role design, least privilege and joiner/mover/leaver processes across your systems.
Penetration test remediation
Fixing what the report found, and changing the process so the same findings do not come back.
Data protection engineering
Encryption, retention, subject access and deletion built into the systems rather than handled by hand.
AI system security
Prompt injection, data exfiltration and model access controls for the AI systems you are adopting.
Consumer Duty and FCA evidence
Systems that produce the outcome and resilience evidence the FCA asks for, rather than assembling it by hand.
Candidate data: one record, one chain of custody
Consolidating decentralised candidate data into a governed record with provenance, retention and access enforced.
Enterprise readiness for start-ups
SSO, audit trails, tenant isolation and a security questionnaire answered from evidence.
EU AI Act readiness
Under Applied AI
Classification, documentation, logging and human oversight for the systems the Act names as high-risk, delivered by the team behind swarmd.ai.
AI governance and ISO 42001
Under Applied AI
The controls, documentation and oversight that let you show how your AI systems are tested, monitored and supervised, mapped to ISO 42001.
AI in payments, credit and fraud
Under Applied AI
Credit, pricing and fraud models built with the documentation and oversight the EU AI Act and the FCA expect.
EU AI Act for recruitment and HR
Under Applied AI
Hiring AI is high-risk under the Act; classification, documentation, bias testing and oversight built in.
How it’s delivered
Engagement models that fit this service, in order of how often clients choose them.
- Stage 1.
Discovery and assessment
2–4 weeks
A fixed-price, fixed-length look at an idea, a process or an existing system, ending in a written report your board can act on: what it would take, what it would cost, and whether it is worth doing. Feasibility studies, technical assessments and due diligence all start here.
Best for: Before committing to a build, a migration or an AI initiative. Also the starting point for a security review, an EU AI Act assessment, or due diligence on a system you are buying.
- Stage 2.
Delivery and iteration
Monthly retainer on 30 days’ notice, or fixed price per phase
Software built or changed by a team in one of two shapes: embedded inside your business, on your tools and in your meetings, or run in-house at Hexploits with your stakeholders joining the demos. Bring a specification or we write one with you. Either way you get a written report every week, a working demonstration every fortnight, and live progress against the KPIs agreed at the start.
Best for: Every build, integration, migration or AI system. Embedded when you have an internal team to work alongside; in-house when you would rather hand the work over and see it at the demo.
- Stage 3.
Deployment and monitoring
Rolling, 30 days’ notice
Someone to own a system that is already live: deployment pipelines, monitoring, patching, backups, on-call and support, on a monthly contract with response times in writing. The monthly figure includes two hours of incident work; anything beyond that is billed per engineer per hour. Runs on your existing stack or on Hexploits Cloud.
Best for: Anything in production that matters, where you would rather one contract covered deployment, support and small changes. Most clients choose it after a build; none are obliged to.
Technologies & frameworks
Technologies we’ve used on recent projects.
Languages
- Java
- Python
- JavaScript
- TypeScript
Frameworks & runtimes
- Node.js
- Spring Boot
- .NET
- Django
- Flask
- React
- Next.js
Data & AI
- PostgreSQL
- SQL Server
- pgvector
- Claude
- OpenAI
- Open-weight models
Cloud & edge
- AWS
- Google Cloud
- Azure
- Cloudflare
- Hexploits Cloud
Platforms & delivery
- Kubernetes
- Docker
- AWS Lambda
- Terraform
- Helm
- Argo CD
- GitLab CI
- GitHub
Monitoring & observability
- Grafana
- Loki
- Prometheus
- OpenTelemetry
We’re familiar with modern technology stacks beyond those shown here, and work with the languages, frameworks and platforms your business already uses.
Proof
Outcomes with numbers and named clients.
swarmd.ai · Software vendor · 6 months
Enterprise AI control plane delivered in six months at 75% under budget for a UK software vendor
Gradvisor · Charity · 8 weeks to production, then ongoing
98% faster page loads and a 12% smaller cloud bill for a UK careers charity
What clients say
Verified reviews, linked to Google where they were left there.
Director, IO Solutions
“Fantastic to work with. High level of attention to detail and flawless communication throughout. Would recommend to anyone looking to develop or improve a software product.”

Director, Lothbury
“Top quality delivery, and reasonable price. Will be using again.”

Director, PeppaSync
“Hexploits have been a breath of fresh air on Peppasync, an AI/ML autonomous decision platform for commercial leaders in retail and ecommerce. The depth and thoroughness the team brought to design and architecture was second to none.”

Insights
AI Sovereignty: What It Costs to Teach an AI Your Business
AI agents can triage support tickets, write your documentation, and answer questions from your own records - but only if you feed them your data. Here is what that trade actually costs, and how AI sovereignty lets you get the value without giving up control.
EU AI Act High-Risk Series, Part 2: Finance & Insurance
Credit scoring and life or health insurance pricing are high-risk under the EU AI Act, with a mandatory impact assessment for every deployer. What a lender, insurer or payments business has to build by December 2027, and how to do it once for every regulator.
EU AI Act High-Risk Series, Part 4: Healthcare & MedTech
Healthcare AI has two EU AI Act deadlines eight months apart, and which applies depends on whether your product is legally a medical device. How to classify correctly, what goes in the technical file, and why health-system procurement is already asking.
Questions we get asked
Do you hold ISO 27001 yourselves?
Is this a penetration test?
Can you fill in our customer’s security questionnaire?
Do you cover the EU AI Act and AI governance?
What does an audit trail a regulator will accept look like?
Next step
Request a proposal.
Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.