Securing data and the AI built on it

Security Engineering Practice

Security programmes often start at the perimeter and work inwards. We start from the other end. Once you know where your sensitive data is, who and what can reach it, and how it’s protected everywhere it gets copied, most of the other security decisions get easier.

From there we secure identity, the cloud platforms underneath, detection and response, and the AI systems that increasingly touch that data. We put controls into code and pipelines rather than documents, so they keep working when systems change, and the evidence an auditor asks for comes out of the same systems.

Sakura Sky: Security Practice Introduction
Sakura Sky: Security Practice IntroductionAI-generated overview

What we deliver

What your team keeps when the work is finished. Each engagement is scoped, so you might only need some of these. They’re in order, because each area builds on the one before it, and AI comes last for that reason.
Data protection

Labelling and tracking regulated data

We find and label sensitive and regulated data, track where it moves, and manage it through its lifecycle. Privacy controls go in during the first architecture conversation, not in the month before an audit.
Data protection

Policy enforced in three places

Data loss prevention and access rules enforced at the API gateway, inside the pipeline, and in the database itself, so one missed setting doesn’t expose everything.
Identity

Verified identity for people, services, and agents

Using workload identity and OIDC, every person, service, and AI agent gets an identity that can be checked, and only the access it actually needs.

How we work

How each capability is designed, built, managed, and governed, and which of our service lines does each part. Most engagements start with a short assessment.
CapabilityDelivered throughDesignProfessional Services: Assessment & RoadmapBuildProfessional Services: Delivery EngagementManageManaged Services: co-managed, hybrid, or fully managedGovernManaged GRC: evidence for EU, US, and international frameworks
Data protectionDesign Find where regulated data lives and where it gets copied.Build Labelling, data loss prevention, and policy enforcement. Security & Privacy EngineeringManage Controls watched as your systems change. Security-Driven Operations & ComplianceGovern
EUGDPR Article 32, through PraxisUSSOC 2, ISO 27001, and HIPAA attestation, with partners including Vanta
IdentityDesign List every human and machine identity.Build Workload identity and least-privilege access.Manage Access changes watched continuously. Security-Driven Operations & ComplianceGovern Access records for the frameworks you report against.
INTLISO 27001USNIST CSF 2.0
PlatformDesign Review your cloud baseline against your policies.Build Guardrails and permissions in code. EnclaveManage Platform run with security in the runbook. Platform Engineering & DevOps EnablementGovern Controls for GDPR and HIPAA enforced in code.
DetectionDesign Review what you can see today, and what you can’t.Build Detection rules, secret scanning, and response playbooks.Manage Monitoring and response as a service. Security-Driven Operations & ComplianceGovern Supplier assurance under NIS2 and the UK Cyber Security and Resilience Bill. The Managed Provider Scorecard
AIDesign List your models, tools, and what each agent can reach.Build Runtime policy and guardrails. SentinelManage Agents run and monitored in production. MLOps & AI Agent OperationsGovern
EUAI Act Article 15, through PraxisUSNIST AI RMF, OWASP AISVS, and ISO/IEC 42001, through Sentinel

Security insights from the Sakura team

Identity, guardrails for AI agents, and the evidence regulators ask for, from the engineers who do the work.
Identity Is the Bank Now

· 10 minutes

Fraud, financial crime, KYC, and customer experience have collapsed into a single engineering question about who the customer is. This final …

All Security posts