What we do

Four productised offerings, plus the work around them.

Each is scoped, repeatable and produces an artefact you can hand to an auditor, a notified body or your own board.

AI Act applicability & role determination

Per AI system, establish whether you are provider, deployer, importer or distributor, classify risk, and produce an attested applicability determination with its basis recorded. The question every other obligation hangs from.

AI governance readiness assessment

Assess your AI management system against ISO/IEC 42001 and the applicable AI Act duty elements. The gap report names, for each unmet duty, whose condition prevents it, so remediation has an owner rather than a colour.

Evidence & technical documentation build

Build the Annex IV technical documentation and the ISO/IEC 42001 Statement of Applicability, with every claim traced to its source evidence rather than to a paragraph someone wrote.

Adversarial testing & AI red-teaming

Contained adversarial testing of deployed AI systems with a reproducible evidence record, addressing the Article 15 robustness and cybersecurity duties, which apply from 2 December 2027. Prompt injection, tool poisoning, excessive agency and egress abuse, proven rather than asserted.

Security posture assessment & threat modelling

We map your real attack surface across applications, APIs, cloud and identity, then model it with STRIDE and, for AI systems, agentic frameworks. Findings ranked by exploitability and impact, not raw CVSS.

Continuous advisory

A standing relationship for teams without a full security function. We review designs, triage risk and keep your posture current as you ship, including as your AI footprint grows.

Engagement shapes

Scoped before it starts.

Indicative sizing so you can budget before a first call. Final scope is agreed in writing after discovery.

EngagementTypical sizeWho buys itWhat you get
AI Act applicability & role determination5–10 daysLegal / Compliance + CIOAttested applicability determination per AI system
AI governance readiness assessment8–15 daysCISO / CIOGap report with each unmet duty attributed
Evidence & technical documentation build15–30 daysProduct / Quality managementAnnex IV documentation and Statement of Applicability
Adversarial testing & AI red-teaming10–20 daysCISOReproducible evidence record of what was tried and what worked
Security posture assessmentScoped per environmentCTO / Head of EngineeringRanked findings with a remediation plan
Continuous advisoryRetained, monthlyFounders / Heads of PlatformStanding design review and risk triage
Compliance we guide

Get audit-ready without stalling the roadmap.

We translate dense standards into a backlog your engineers can actually work through.

EU AI Act ISO 42001 ISO 27001 SOC 2 NIS2 DORA GDPR PCI-DSS 4.0

EU AI Act and ISO 42001

The binding EU regulation and the certifiable AI management standard. Germany's market surveillance architecture went live under the KI-MIG on 29 July 2026 with the Bundesnetzagentur as central authority, so the question is no longer whether someone will ask. ISO 27001 holders get a large head start, and we map the rest.

NIS2 and DORA

The German NIS2 implementation act has been in force since 6 December 2025 and expanded the regulated population to around 29,500 entities, according to the BSI. Management must implement and oversee the risk measures, attend regular training, and is liable to the entity for culpable breaches. DORA has applied to financial entities since January 2025. We turn both into concrete technical and organisational measures.

ISO 27001 and SOC 2

The information security baselines most enterprise buyers require. We scope the controls, fix the gaps, and stand up the evidence trail so the audit is a formality, not a fire drill.

GDPR and PCI-DSS 4.0

Data protection obligations turned into measures rather than another policy nobody reads, and a clear path through the latest payment requirements, with Cyron API Security available where API monitoring evidence helps your case.

How we engage

A simple, honest cadence.

1. Scope

A short discovery call to understand your systems, your AI footprint, your customers and the standard you are chasing.

2. Assess

We test, model and review, then hand you findings ranked by real risk, with every conclusion carrying how it was established.

3. Close the gap

We work alongside your team to fix issues and prepare the evidence, all the way to audit.

Where advisory ends and product begins

An engagement is a point in time. Our products are continuous.

An assessment tells you which agents have unmonitored tool access and unbounded egress today. Cyron AI Security keeps protecting that traffic, and Cyron API Security does the same for your APIs. Cyron AI Compliance, in development, will keep the evidence current. We will tell you honestly which of the two you need.

Tell us where it hurts.

A short discovery call, an honest scope, and a written proposal. No pipeline theatre.