/ ai packages

Time-boxed AI offers with deliverables you can pin down.

Fixed scope, fixed timeline, named deliverables. Every package ends with a buildable backlog.

GenAI Discovery

2 weeks · fixed-fee

Opportunity map, architecture spike, eval harness and an executable Sprint-1 plan with cost model.

  • Opportunity register
  • Reference architecture
  • Eval baseline
  • Roadmap + cost model

RAG / GraphRAG Rollout

8–12 weeks

Production-grade retrieval over your corpus — hybrid search, evals, guardrails and observability.

  • Ingestion pipeline
  • Hybrid + graph retrieval
  • Eval & guardrails
  • Prod observability

MCP & Agentic Build-out

3–6 weeks

Custom MCP servers, tool-use, agent orchestration and human-in-the-loop checkpoints.

  • MCP servers
  • Tool registry
  • Agent graph
  • HITL controls

AI Readiness Assessment

1 week

Maturity scan across data, platform, governance and skills. Board-ready scorecard and 90-day plan.

  • Maturity scorecard
  • Gap analysis
  • 90-day plan
  • Exec readout
/ eu ai act readiness

Ship AI that survives 2026 scrutiny.

A focused programme to make your AI systems EU AI Act-ready: risk classification, Annex IV technical documentation, human-oversight controls, evals, red-teaming and post-market monitoring — wired into your SDLC, not a one-off audit.

  • Risk classification & use-case register
  • Annex IV technical file & data governance
  • Evals, guardrails & red-team harness
  • Human-oversight & incident response
  • Post-market monitoring & logging
/ security & compliance

Trust posture baked into the delivery stack.

Standards we align to. Certifications held are confirmed on request under MNDA.

GDPR & ePrivacy

Privacy-by-design, DPAs, SCCs, ROPA support.

EU AI Act

Risk classification, Annex IV docs, post-market monitoring.

ISO 27001 aligned

ISMS practices, access reviews, supplier controls.

SOC 2 ready

Evidence collection, change mgmt, logging baselines.

OWASP ASVS / SAMM

Secure SDLC, threat modelling, SAST/DAST in CI.

SBOM & supply chain

SLSA-aligned builds, SBOMs, signed artefacts.

EU data residency

EU/EEA-only data paths and inference on request.

DORA / NIS2 awareness

Operational resilience and incident playbooks.

Standards we align to. Certifications held are confirmed on request under MNDA.