Companies selling to enterprises or regulated sectors
Navigating security, compliance and responsible AI
In short
Enterprise customers, regulators and boards increasingly ask for evidence, not intentions. I lead security and compliance work on your side, so the controls fit how your team already works, and help you adopt AI responsibly: evaluated, overseen and measured, in the product and in how your engineers work.
You might recognise this
- An enterprise deal depends on a SOC 2 report or an ISO 27001 certificate.
- You handle US health data and need to meet HIPAA requirements.
- You build or use AI in the EU and need to understand the EU AI Act.
- Your AI features demo well, but customers and auditors need them to be dependable.
What each involves
- SOC 2
- An attestation: an independent CPA firm examines your controls and issues a report. There is no SOC 2 certificate.
- ISO 27001
- A certification: an accredited certification body audits your information security management system and, if it conforms, certifies it.
- HIPAA
- US law protecting health information. There is no official HIPAA certification; the work is putting the safeguards, policies and evidence in place.
- EU AI Act
- EU regulation whose obligations depend on how your AI systems are classified and whether you provide or deploy them.
I am not an auditor or a lawyer. I lead the work on your side, alongside your auditor, certification body and legal advisers, who make the formal decisions.
How we might work together
Examples, not packages. They often overlap within one relationship, and we shape the work together.
- Leading the programme
- Scoping, controls, evidence and working with your auditor or certification body.
- Answering customers
- Security questionnaires and reviews answered with evidence.
- Responsible AI adoption
- Evaluation, guardrails and human oversight for AI features, and measured adoption of AI tools by your engineers.
Relevant experience
- Completed: led Remo’s engineering organisation through SOC 2 and ISO 27001 Read the case study
- Undertaken more recently: HIPAA and EU AI Act compliance work with companies I advise
- Rolled out HTTPS and a Tor mirror at BBC News and World Service to protect audiences under censorship Read the case study
- Helped move Deepnote from a data science platform to an agentic AI workspace
How we start
We start with a focused look at what you’re trying to achieve, what’s getting in the way, and how I could help. From there, we agree whether there’s a useful role for me and what it should involve.
- Understanding the business and what you are trying to achieve
- Meeting the people who matter to the work
- Looking at enough evidence to see where I could be useful
- Deciding together whether an ongoing role makes sense, and what it should be
Selected results
| Organisation | What changed |
|---|---|
| RemoCTO, 2021 to 2024. Events and remote-office SaaS | Led a 24/7 engineering organisation spanning GMT−8 to GMT+8 through pandemic hypergrowth, contraction and acquisition by Events.com. Cut infrastructure and vendor spend by more than 80% over 14 months, achieved approximately 99.99% uptime with recovery from live-event failures in under one minute, and achieved SOC 2 and ISO 27001. |
| DeepnoteFractional CTO. YC-backed, $23.5M raised | Moving the product from a data science platform to an agentic AI workspace, raising AI-native engineering standards and improving enterprise delivery. Server costs cut by 40%. |
Questions
Can you guarantee we will pass?
No one honest can. The auditor or certification body decides. My job is to make sure the controls are real, the evidence is ready and nothing is a surprise.
Do you give legal advice?
No. For HIPAA and the EU AI Act, I work alongside your legal advisers on the technical and organisational side.