Notes on certification, without the jargon
Practical guides on ISO 27001, ISO 42001 and the EU AI Act — written for founders and teams who want systems that actually work, not just pass an audit.
SOC 2 vs ISO 27001: which one do you actually need?
A report or a certificate, a US buyer or a European one — how to pick the right framework, and how to sequence both without doing the work twice.
The ISO 27001 Statement of Applicability, explained
The one document every auditor opens first — what belongs in each column, when exclusions are defensible, and the mistakes that turn into findings.
ISO 42001 explained: how to build an AI Management System from scratch
What ISO 42001 actually requires, who needs it, and a step-by-step path from zero to a certifiable AI Management System.
The EU AI Act compliance checklist for 2026
Risk tiers, obligations and deadlines — a plain-language checklist to find out what the EU AI Act means for your business and where to start.
ISO 27001 for startups: a realistic path to certification
Why enterprise clients ask for it, how long it really takes, what it costs in effort, and how to get certified without drowning your team in paperwork.
Not sure where to start?
Tell us where you are and what standard you're targeting — we'll reply within 48 hours, in writing.
Start with a Gap Analysis