Security by Design fintech platforms tailored to your operating model

Over a decade of building regulated, resilient software that brings compliance, cybersecurity, and customer journeys together.

Get in Touch See How We Build

Who We Are

We are a Lisbon-based team of architects, security engineers, and product strategists dedicated to shipping software that financial institutions and critical infrastructure can trust. Every engagement follows our four pillars: Design-first discovery, Secure SDLC, Compliance accelerators, and measurable outcomes.

That approach has helped Siemens, Nokia, SIX Group and other leaders modernize payments, automate SOC workflows, and bring new digital products to market faster.

Products

Crafted solutions designed to solve real-world business challenges. Pick one to see how it is put together.

Sovereign AI Platform

Meerkat

Meerkat is a local AI deployment your people can actually use, with a border post in front of the internet. One machine holds the chat interface, the local model and your documents, and has no route out. A second holds the cloud credentials and decides, for every single request, whether it may leave.

  • The machine holding your documents has no route to the internet
  • A per-request decision, made in exactly one place
  • Users can force local, and can never force cloud
  • A decision log you can check against your own firewall telemetry
Learn More Get in Touch
How the gate works
A
Your documents, chat, local model

No route to the internet. It can refuse, it cannot send.

B
The border post

The only machine holding cloud credentials. It decides, and it logs.

Stays local Anything touching protected material
Allowed out Answered by a frontier model
SIEM Governance Layer

ALPACA

ALPACA does not replace your SIEM, it completes it. QRadar, Splunk, Sentinel and Elastic handle the events. ALPACA answers what they leave unsaid: who owns each log source, how critical it is, how long its data is kept, and which assets are escaping security coverage entirely.

  • Every log source with a named owner, a criticality and a retention period
  • CMDB assets correlated against what actually reports, so blind spots surface by name
  • Read-only visibility into SIEM configuration and detection rules, with change history
  • Entry, update and decommission under approval, by assistant or API
Learn More Get in Touch
Where the blind spots come from
CMDB The assets of record
Log sources What actually reports
SIEM Rules and configuration, read-only
ALPACA registry

One governed record per source: owner, criticality, retention.

Covered Asset reports, source owned, retention set
Blind spot An asset in the CMDB with nothing reporting
Air-Gapped Security Appliance

IBEX

IBEX is a sealed appliance that runs on its own hardware inside your perimeter. It maps the attack surface of the environments the cloud can never reach, scans the code your teams build, and governs every model and agent on the network. It has no route to the internet, and the only thing that leaves is the evidence.

  • Its own hardware inside your perimeter, with no cloud and no data egress
  • Discovers hosts, services and AI systems, including the models nobody declared
  • Inline enforcement on live AI traffic: block, redact, or alert
  • Findings ranked against a locally held vulnerability database, with no external lookups
Learn More Get in Touch
What is sealed, and what comes out
The internet No route out, in either direction
Your perimeter
IBEX appliance

Own hardware, on-board model, local vulnerability database.

Network & AI Hosts, services, models, agents
Code Dependencies, secrets, IaC
Runtime Inline AI gateway
Auditor-ready evidence Leaves as a document, not as a connection
Governed Knowledge Retrieval

ALF

ALF puts a team's own knowledge behind a question box. It ingests the playbooks, product documentation and tickets that already exist, and answers in plain language with the source and its owner attached, under the access rules your directory already enforces.

  • Domain-adaptive retrieval across manuals, tickets and knowledge bases
  • Plain-language questions answered with cited sources and ownership context
  • Role-based governance through your existing AD or SSO, with an audit trail
  • Deployed on-premises, in a private cloud, or fully isolated
Learn More Get in Touch
How an answer is made
  1. Once, at setup
  2. Ingest your own material

    The playbooks, product documentation, tickets and knowledge bases your company already has, indexed with their owners and the access rules they already carry.

  3. Then, on every question
  4. Ask

    A question in plain language, from a person with a role.

  5. Retrieve

    Only from the material that role is cleared to read.

  6. Answer

    With its sources cited and their owners named.

Where it runs On-premises, in a private cloud, or fully isolated

Clients

Trusted by leading organizations across industries.

Siemens
Leaseplan
Holmes Place
SIX Group
Nokia
Automonitor
Nestle Waters
The Lisbon Concierge

Ready to transform your business?

Schedule a personalized demo to see how our solutions can help you.