Technology studio · Paris

Cybersecurity, artificial intelligence, automation. A partner on the engagement, a costed scope within fourteen working days.

ParisA partner per engagementReply within 24 hours

Technology partnerships

AnthropicGoogle for Startups
What we do

Three moves, one team.

Advice, architecture and operations never change hands here.

Secure.

Audits, Zero Trust, NIS2 and DORA. Controls that hold up in production, not in a binder.

Automate.

Agents, RAG and workflows wired into the tools you already run. The time handed back shows up in the first month.

Ship to production.

Architecture, operations, observability. What we design, we stand behind.

Engagements

NIS2, end to end.

Six formats following the compliance journey, from diagnosis to incident notification. A partner accountable for the outcome.

NIS2 · Starting point

NIS2 diagnosis

14 working days

Are you in scope, and how far from compliant?

  • Scope qualification: essential or important entity
  • Measured gap against the ten Article 21 measures
  • Asset and dependency mapping
  • Sequenced remediation plan, presented to the board
Request a call
NIS2 · Third parties

Supply chain security

4 to 8 weeks

The obligation almost nobody has tackled yet.

  • Third-party register with criticality ratings
  • Assessment questionnaires and scoring
  • Security clauses in contracts
  • Continuous monitoring and alerts
Request a call
NIS2 · Article 23

24-hour notification

readiness or activation

Twenty-four hours to raise the alert. That is not improvised.

  • Formalised decision and escalation chain
  • Pre-filled notification templates
  • Tabletop simulation exercises
  • 72-hour interim report, final at one month
Request a call
NIS2 · Article 20

Fractional CISO

monthly engagement

The directive makes management personally accountable. We carry the file with you.

  • Security posture and risk register steering
  • Monthly committee and board reporting
  • Management training required by Article 20
  • The person clients and authorities talk to
Request a call
AI & automation

AI sprint

4 to 6 weeks

Automate the compliance workload instead of hiring to carry it.

  • Automated evidence collection and filing
  • Agents and RAG over your internal frameworks
  • Production rollout with observability
  • Guardrails and EU AI Act classification
Request a call

The same formats cover DORA, ISO/IEC 27001 and GDPR, whose requirements overlap heavily with NIS2. Every engagement is scoped before it is priced: perimeter, sequencing and budget are agreed in writing, and do not move afterwards.

See the full breakdown
Method

From audit to operations, without a handover.

Four stages, a named owner, something useful delivered at each one.

  1. Diagnostic

    Exposure assessment, risk mapping, regulatory gap identification.

  2. Architecture

    Control design, technology choices, flow and accountability modelling.

  3. Implementation

    Control deployment, operational documentation delivery, knowledge transfer.

  4. Operation

    Maintenance, continuous review, long-horizon maturity support.

Proof through product

We run our own software.

The method we sell is the one we apply to ourselves first.

0platforms designed and operated in house
0frameworks mastered: NIS2, DORA, ISO/IEC 27001, EU AI Act
0 hworking-hours response time on any inbound request
Early access

Presidio

NIS2, DORA and ISO/IEC 27001 become tracked actions, evidence and decisions. One place, no more spreadsheets.

  • A clear view for the board and for operational teams
  • Centralised evidence with a complete audit trail
  • Action plans you can drive through to remediation
Presidio GRC dashboard: overall score 72 out of 100, NIS2, GDPR and ISO/IEC 27001 compliance
Our commitment

Whoever decides stays to execute.

No handover between advice, architecture and production.

01

Senior from the first call.

You speak to the people designing the solution. Never to a middle layer.

02

Built for production.

A recommendation becomes a control, a product or a dated plan. Otherwise it does not ship.

03

Secure by architecture.

Compliance and AI governance sit in the design, never bolted on afterwards.

Meet the team

Get in touch

Thirty minutes to find out if we are useful.

You lay out your context, you leave with a straight answer. Including when it is no.

Address
1 rue de Stockholm, 75008 Paris

Three formats, depending on where you are

  • Discovery call30 minutes · videoYou lay out your context, we tell you plainly whether we are the right fit.
  • Scoping workshop60 minutes · video or ParisScope, sequencing and budget for an engagement already qualified.
  • Client review45 minutes · videoFor existing clients: progress review or an urgent matter.

Write us a line or two and we come back with a slot within the working day.