Security
Security Engineering Practice
Security programmes often start at the perimeter and work inwards. We start from the other end. Once you know where your sensitive data is, who and what can reach it, and how it’s protected everywhere it gets copied, most of the other security decisions get easier.
From there we secure identity, the cloud platforms underneath, detection and response, and the AI systems that increasingly touch that data. We put controls into code and pipelines rather than documents, so they keep working when systems change, and the evidence an auditor asks for comes out of the same systems.

What we deliver
Policy enforced in three places
Confidential computing
Verified identity for people, services, and agents
Hardened cloud baseline
Detection and response
Secret and credential scanning
Guardrails for AI and agents
How we work
| CapabilityDelivered through | DesignProfessional Services: Assessment & Roadmap | BuildProfessional Services: Delivery Engagement | ManageManaged Services: co-managed, hybrid, or fully managed | GovernManaged GRC: evidence for EU, US, and international frameworks |
|---|---|---|---|---|
| Data protection | Design Find where regulated data lives and where it gets copied. | Build Labelling, data loss prevention, and policy enforcement. Security & Privacy Engineering | Manage Controls watched as your systems change. Security-Driven Operations & Compliance | Govern EUGDPR Article 32, through PraxisUSSOC 2, ISO 27001, and HIPAA attestation, with partners including Vanta |
| Identity | Design List every human and machine identity. | Build Workload identity and least-privilege access. | Manage Access changes watched continuously. Security-Driven Operations & Compliance | Govern
Access records for the frameworks you report against. INTLISO 27001USNIST CSF 2.0 |
| Platform | Design Review your cloud baseline against your policies. | Build Guardrails and permissions in code. Enclave | Manage Platform run with security in the runbook. Platform Engineering & DevOps Enablement | Govern Controls for GDPR and HIPAA enforced in code. |
| Detection | Design Review what you can see today, and what you can’t. | Build Detection rules, secret scanning, and response playbooks. | Manage Monitoring and response as a service. Security-Driven Operations & Compliance | Govern Supplier assurance under NIS2 and the UK Cyber Security and Resilience Bill. The Managed Provider Scorecard |
| AI | Design List your models, tools, and what each agent can reach. | Build Runtime policy and guardrails. Sentinel | Manage Agents run and monitored in production. MLOps & AI Agent Operations | Govern |
Security insights from the Sakura team

Your System Prompt Is Not a Trust Boundary
· 16 minutes
A text-to-SQL agent's system prompt cannot enforce a data rule. sql-guard v0.2.0 puts the rule in a parser instead, and closes eight …

Your Managed Providers Are About to Be Regulated. Here Is What to Ask Them.
· 11 minutes
The UK Cyber Security and Resilience Bill and NIS2 both regulate managed service providers directly, wherever they are established. Seven …

Identity Is the Bank Now
· 10 minutes
Fraud, financial crime, KYC, and customer experience have collapsed into a single engineering question about who the customer is. This final …