Werk 07 — who carries it
Security in this collective is an architecture discipline, not a scanning practice. The question it answers is whether a regulated system can prove what it did, to a regulator, months later.
The offer
Controls that can be shown to a regulator because they were designed in — isolation, identity, continuity and the evidence trail, not a remediation backlog written after the audit.
Regulatory obligations mapped onto architecture decisions — GDPR, DORA, NIS2, sector rules — with the control owner named for each.
Threat modelling, secure defaults, secrets handling and the AppSec gates wired into the pipeline rather than bolted onto release.
IAM model, multi-tenant isolation, least-privilege access and the review cycle that keeps entitlements from drifting.
RTO and RPO set with the business, tested failover, and an incident practice rehearsed before it is needed.
Control gap map, risk register, prioritised remediation plan.
Architecture review, regulator-facing documentation, audit support.
The control estate built and evidenced.
State of the proof
Experiences that prove it
Sub-capabilities and evidence
Publishable figures
Questions
- Where is the real proof?
- In a trading-platform audit and redesign with regulatory alignment at VERMEG, in a medtech telemonitoring platform migrated onto secure European infrastructure for EU market entry, and inside the On-Kare venture, where consent guards fail closed and every sensitive field is encrypted at rest.
- What is out of scope?
- Penetration testing, SIEM operations and identity platform builds. They are listed as declared so a buyer knows to bring a specialist rather than discovering the gap mid-mandate.
- What does a regulated architecture have to prove?
- That it can reconstruct what it did. VERMEG's core trading-platform interfaces were audited and redesigned with regulatory alignment inside a capital-markets vendor, where the interface is the control surface a regulator reads. Satelia's telemonitoring platform was migrated onto secure European infrastructure because data residency was a market-entry condition, not a preference.
- What does fail-closed mean in practice?
- That a missing decorator denies access rather than granting it. On the On-Kare platform, a controller touching patient data without an explicit consent declaration returns a refusal at runtime — the absence of a rule is treated as a denial, which is the only posture that survives an audit.
- Who should not hire this werk?
- An organization that needs a SOC stood up, a penetration-test programme run, or an identity platform built. Those are declared scope with no published proof, and the right answer is a specialist firm plus this collective on the architecture.