Consultancy, no licence
Typical models (examples)
What the software needs
Strong access control. Encryption everywhere. Minimal logging of client data.
Security & intelligence
For penetration-testing firms, OSINT and investigations practices, threat-intelligence vendors, secure-communications providers and protective-services firms whose tooling is the product.
| Rung | Typical models (examples) | What the software needs |
|---|---|---|
| Consultancy, no licence | Advisory, OSINT, research | Strong access control. Encryption everywhere. Minimal logging of client data. |
| Registered security services | Jurisdiction-specific private-security or investigations licences | Client segregation. Retention-policy enforcement. Audit logs. Evidence integrity. |
| Certified and government-facing | ISO 27001, SOC 2, CREST | Certification-grade controls. Assurance reporting. Continuous control monitoring. |
Typical models (examples)
What the software needs
Strong access control. Encryption everywhere. Minimal logging of client data.
Typical models (examples)
What the software needs
Client segregation. Retention-policy enforcement. Audit logs. Evidence integrity.
Typical models (examples)
What the software needs
Certification-grade controls. Assurance reporting. Continuous control monitoring.
Models are examples only. Nothing on this page is legal advice; we build the software your advisers specify.