werk 07 · security and compliance

Security.

Compliance, regulated architecture and security by construction — the controls a regulated estate has to prove, designed in rather than audited on afterwards.

FamilyRunCarried byAdvisoryCarried byInterimProven lines1 / 7Detailed mandates2SectorsFinance & Insurance, Health & Life Sciences

Werk 07 — who carries it

arms and mandates

Security in this collective is an architecture discipline, not a scanning practice. The question it answers is whether a regulated system can prove what it did, to a regulator, months later.

The offer

what is bought, and in what shape

Controls that can be shown to a regulator because they were designed in — isolation, identity, continuity and the evidence trail, not a remediation backlog written after the audit.

Compliance architecture

Regulatory obligations mapped onto architecture decisions — GDPR, DORA, NIS2, sector rules — with the control owner named for each.

Security by construction

Threat modelling, secure defaults, secrets handling and the AppSec gates wired into the pipeline rather than bolted onto release.

Identity, isolation and zero trust

IAM model, multi-tenant isolation, least-privilege access and the review cycle that keeps entitlements from drifting.

Continuity and resilience

RTO and RPO set with the business, tested failover, and an incident practice rehearsed before it is needed.

Assessment3 to 6 weeks

Control gap map, risk register, prioritised remediation plan.

AdvisoryFractional security authority

Architecture review, regulator-facing documentation, audit support.

Interim seat6 to 18 months, CTO or CISO-adjacent

The control estate built and evidenced.

Zero trustIAMSIEM and SecOpsPentest programmesDORA and NIS2 alignment

State of the proof

counted from the ledger below
7sub-capabilities
1proven · a published case carries a sourced figure
3held · carried by a named operator, no case published
3declared · in scope, no published proof today

Experiences that prove it

2 detailed mandates

Sub-capabilities and evidence

7 lines, each with its state
Regulatory alignment and compliance architectureprovenVERMEGSatelia
Security by construction in regulated estatesheldOn-Kare: fail-closed consent guards, AES-256-GCM field encryption, HMAC-chained audit trail across 12 compliance frameworks.
Multi-tenant isolation and access controlheldOn-Kare: tenant-scoped reads, cache-key isolation and role gating enforced by CI ratchets.
Business continuity and resilienceheldFive-nines availability held on a betting platform where downtime is lost stakes.
IAM and zero trustdeclared
AppSec and penetration testingdeclared
SecOps and SIEMdeclared

Publishable figures

named, sourced, attributable
12Compliance frameworks in scope · On-KareOn-Kare venture · platform scope, 2026
1Regulated EU market entry · medtech telemonitoringErwan Deschamps · interim CPTO, Satelia (2026)

Questions

answered, in the open
Where is the real proof?
In a trading-platform audit and redesign with regulatory alignment at VERMEG, in a medtech telemonitoring platform migrated onto secure European infrastructure for EU market entry, and inside the On-Kare venture, where consent guards fail closed and every sensitive field is encrypted at rest.
What is out of scope?
Penetration testing, SIEM operations and identity platform builds. They are listed as declared so a buyer knows to bring a specialist rather than discovering the gap mid-mandate.
What does a regulated architecture have to prove?
That it can reconstruct what it did. VERMEG's core trading-platform interfaces were audited and redesigned with regulatory alignment inside a capital-markets vendor, where the interface is the control surface a regulator reads. Satelia's telemonitoring platform was migrated onto secure European infrastructure because data residency was a market-entry condition, not a preference.
What does fail-closed mean in practice?
That a missing decorator denies access rather than granting it. On the On-Kare platform, a controller touching patient data without an explicit consent declaration returns a refusal at runtime — the absence of a rule is treated as a denial, which is the only posture that survives an audit.
Who should not hire this werk?
An organization that needs a SOC stood up, a penetration-test programme run, or an identity platform built. Those are declared scope with no published proof, and the right answer is a specialist firm plus this collective on the architecture.

Related werks

same family, shared proof
Discuss a security mandateHow Advisory runs itAll eleven werks