Sensitive data mapping
Find where regulated and sensitive data actually lives — including the copies in test environments, exports and mailboxes that no architecture diagram shows.

Find the sensitive data you did not know you held, control who can reach it, and secure the software that touches it — with the registers, matrices and logs to prove it.
Most breaches are embarrassing rather than sophisticated: sensitive data sitting somewhere nobody knew about, with permissions nobody reviewed. This is the work that closes that gap.
Find where regulated and sensitive data actually lives — including the copies in test environments, exports and mailboxes that no architecture diagram shows.
A classification scheme your staff can actually apply, backed by a classification register, so protection is proportionate instead of uniform and ignored.
DLP policy design and tuning, with an incident log that records what was blocked and why — the evidence auditors ask for and most organisations cannot produce.
Encryption at rest and in transit, with a key management process that survives staff turnover rather than living in one person head.
An access rights and permissions matrix showing who can reach what, so the quarterly review becomes a task rather than a project.
Document retention and secure disposal schedules, because data you no longer need is pure liability the day you are breached.
Fixing a vulnerability in design costs a conversation. Fixing it in production costs a weekend, a disclosure and sometimes a customer. We move the work left.
SAST wired into your pipeline with the findings triaged, so developers get the handful that matter rather than a wall of noise they learn to skip.
A secure coding checklist your team will actually use, aligned to the languages and frameworks you build in rather than a generic list.
Rank your application estate by exposure and business impact, so remediation effort lands where a breach would hurt most.
A patch and update tracker across applications and dependencies — the boring control that prevents most of the incidents we get called to.
Security misconfiguration assessment across app servers, frameworks and cloud services, where the default setting is very often the vulnerability.
Secure mobile testing for iOS and Android builds, covering storage, transport, authentication and the third-party SDKs nobody audited.
Mobile development ›Every engagement leaves you with artefacts your team can operate and your auditor can read. These are the deliverables, not a summary of them.
Most organisations find out during an incident. A data discovery and classification assessment answers it in weeks, for a fixed price.
Book a Data Security AssessmentPublished
With discovery. Until you know where sensitive and regulated data actually lives — including copies in test environments, exports and mailboxes — every other control is guesswork. A data mapping and classification assessment is the usual first engagement and is quoted as a fixed price.
It is a scheme that rates data by sensitivity so protection is proportionate. Without it, organisations either protect everything equally (expensive and ignored) or nothing consistently. You get a classification register your staff can actually apply.
Yes — policy design, deployment and the tuning that decides whether staff work with it or route around it. You also get a DLP incident log recording what was blocked and why, which is the evidence auditors ask for and most organisations cannot produce.
Yes. We produce an access rights and permissions matrix covering systems, shares and applications, so the quarterly access review becomes a routine task rather than a project nobody starts.
Static code analysis wired into your pipeline with findings triaged, secure coding standards for the languages you actually use, an application risk matrix, patch and dependency tracking, security misconfiguration review, and mobile app testing for iOS and Android.
Only if it is left untuned. Raw SAST output is mostly noise, and developers learn to skip it. We triage findings so the team sees the handful that matter, which is the difference between a control that works and one that is bypassed.
Yes — storage, transport security, authentication and the third-party SDKs that nobody audited, across iOS and Android builds. It pairs naturally with our mobile development practice if you also need the fixes implemented.
Documents, not a slide deck: sensitive data map, classification register, permissions matrix, DLP incident log, key management process, retention and disposal schedule, application risk matrix, secure coding checklist and a patch tracker.