Singapore · London · Lagos · Rwanda · South Africa · Kenya

We put AI to work where the data is sensitive
and the mistakes are expensive.

AI enablement for energy, oil and gas. Crude marketing, cargo operations and structured finance. We build the systems, and help you govern the ones you already have.

  • NIST AI RMF
  • ISO/IEC 42001
  • ISO 27001
  • SOC 2
  • NDPA
  • PDPA
Data boundary · before the feature list
  • GreenPublic tier models. No restriction.
  • AmberContracted tenancy. Retention off. Logged.
  • RedNever leaves the boundary. Human gate.

Settled before anything is quoted. It sets the architecture, and it changes the price.

Where to start

Two very different problems. The same discipline.

You run the business

Two to sixty people, and you’re the bottleneck.

Professional services, studios, clinics, logistics, trading desks. It all lives in your head, your phone, or a spreadsheet nobody else understands. We find where your week actually goes, classify the data before designing anything, and build the two or three things that move a number.

  • Fixed fee, per module
  • Working software in weeks, not quarters
  • We’ll tell you which ideas aren’t worth building
Start with an AI opportunity assessment →
You govern it

You’re being asked to attest to an AI position.

Boards, audit committees, regulated firms, platform companies. AI is already in production somewhere in your organisation and nobody can evidence what it’s doing with the data. We find it, govern it, and give you reporting a board can act on.

  • Independent review of systems already live
  • Shadow AI discovery and agentic protocol audits
  • Board-ready reporting, not a slide deck
Request a board briefing →

Some of our recent work

Streaming media founder

The build we talked her out of.

The brief was an end-to-end AI posting pipeline. Three weeks into discovery it was clear that was the wrong build, so we killed it before writing a line of pipeline code and hand-ran a weekly analytics brief instead. No tooling cost, no live API into her accounts.

The highest-impact automation is sometimes the one you don’t build.

Interior design studio, 53 staff

Foundation before feature.

The stated pain was invoicing. The actual problem was that the whole business — client history, project status, pricing — lived in the CEO’s head. So invoicing came second. First was a morning briefing, a client list, and an automated onboarding questionnaire.

Automating invoices on top of nothing is automating nothing.

Commodity trading and structured finance firm

Enablement as discovery.

A function-specific programme across crude marketing, accounts, structured finance and the executive team. Each participant worked one-to-one on their own live files and left with a working tool they could run unaided. Now scoping a multi-module build programme.

An afternoon on someone’s real files beats a two-week requirements exercise.

See our experience →
Why you’d trust us with this

Cybersecurity is not our other service. It’s why the AI work is credible.

Most AI projects don’t fail on capability. They stall on two questions nobody in the room can answer: what happens to our data, and what happens when it’s wrong.

Those are not AI questions. They are control questions — and they are the ones we have spent twenty years being accountable for. Second line of defence at Tier-1 banks. Information security at a regulated trading firm. Singapore’s Critical Information Infrastructure regime. The job was deciding whether systems like these were safe to ship.

We now build them. The instinct is the same: work out what data the thing touches and where that data must never go, before deciding what it should do. Put the arithmetic in code where it’s exact. Leave the judgement to the model. Keep the sign-off with a named person.

Big-4 has the discipline and won’t build it. You get a report.

AI shops will build it and don’t have the discipline. You get a compliance breach with a nice interface.

We do both. That’s the whole proposition.

What we do

Four practice areas, in the order we’d recommend them.

AI Enablement & Capability

Your people are already using AI. Teach them to use it deliberately — on their own real work, with rules about what’s safe to paste.

Learn more →

AI Build & Automation

Put AI into the jobs that actually cost you time and money, built to a standard you can evidence, and handed over so you own it.

Learn more →

AI Governance, Assurance & Data Protection

Govern the AI your organisation is already using, and evidence what it’s doing with the data.

Learn more →

Cyber Resilience & Readiness

SOC 2 and ISO 27001 readiness, incident response you’ve actually rehearsed, and the capability programmes that build the next cohort.

Learn more →
How we build

The rules we build to

These aren’t preferences. They’re what twenty years of watching systems fail under pressure leaves you with.

01

The data boundary comes before the feature list.

Before asking what a system should do, we ask what data it touches and where that data must never go. That answer sets the architecture and it changes the price — so we settle it before quoting, not after building.

02

AI prepares, a human approves.

Nothing consequential publishes itself. No reconciliation goes out unreviewed, no order is submitted automatically, no recommendation reaches an executive unread.

03

Boring, hireable stacks — and you own it at the end.

Components you could administer yourself, inside tenancies you already pay for, transferred to accounts in your name with the keys rotated and the runbooks written.

04

Evaluation, not just deployment.

AI systems drift. A wrong figure in a board report is a reputational event, not a ticket. Live systems get a versioned test set and groundedness checks.

We build for clients, and we assure for others. Where we’ve built a system, our review of it is a quality gate, not independent assurance. If you need independence, we’ll say so and help you scope it elsewhere.

Africa

A specialist focus on Africa’s growth markets

African organisations are putting AI into live operations right now — in banks, payment rails, telcos, hospitals and energy operators. Very few of them have anyone who can both build the thing and answer the regulator about it.

Our Africa practice is led from Singapore and London, delivered with local legal, regulatory and implementation partners.

See our Africa advisory practice →
  • Nigeria
  • South Africa
  • Kenya
  • Ghana
  • Rwanda
  • Pan-African
Toolkits

Practical toolkits, ready to deploy

Most engagements leave your team assets they can re-use long after we’re gone.

Data Classification Framework
Green, amber, red — with the handling rule, tooling constraint and paperwork for each tier.
AI / Data Usage Policy Pack
Board-ready policies for staff use of generative AI, third-party models and customer data.
AI Opportunity & Value Model
Quantify what a manual process actually costs before deciding whether to automate it.
AI Handover & Runbook Pack
The handover discipline as templates — including the off-switch the owner can hit without calling anyone.
See the full toolkit library →
Start here

Start with the thing that’s costing you the most.

A 30-minute call, no charge. Tell us what ate your week. We’ll give you a plain, independent read on whether AI is the right lever on it, what it would take, and roughly what it’s worth — and if the answer is that you shouldn’t build it, you’ll get that too.