Governance & assurance

Governance is a calendar and a named person

Not a promise in a relationship — a fixed cadence, published escalation times, and named controls we'll contract to.

Three-tier governance

Fixed cadence, a named owner at each level, and decisions made where they should be.

Quarterly
Executive

Value against the business case, roadmap, commercial performance, relationship health.

Monthly
Programme

Budget & burn, scope and change control, risk register, quality trend, team health.

Weekly / daily
Delivery

Sprint progress, blockers, defect trend, dependencies, next-sprint priorities.

Escalation we contract to

You can name the person who answers, and the time by which they must — in the SOW, not in a relationship.

  • P1
    Production down or data at risk

    Delivery lead, engagement manager & partner notified

    15 min ack4 hr target restore

  • P2
    Major function degraded

    Delivery lead & engagement manager notified

    1 hr ack1 business day

  • P3
    Minor defect or request

    Handled within the delivery tier

    Next business dayagreed sprint

Security & data protection

  • Zero-trust access, MFA enforced, least privilege with quarterly review
  • Client VDI / VPN-only working option; segregated client environments
  • Endpoint hardening, EDR and DLP; data residency options by jurisdiction
  • GDPR & DPDP alignment; client-led audit rights; full diligence pack on request

Full security & diligence pack available on request.

How an engagement starts

  • Discovery first. We run a paid discovery, then convert to fixed scope once it will hold — we don't fix-price an unknown.
  • A single scoped pilot with defined exit criteria, inside 90 days.
  • No minimum term beyond notice, no exclusivity.
  • Documentation is a Definition-of-Done item on every sprint.
Start here

Start with one sprint

Two to three weeks, one approver, a deliverable you keep. Tell us the problem and we'll come back within one business day with a scope, a date and a fee.

Scope a sprint →