Goolean

Security & Compliance

Controls that are implemented, not just documented.

We build security into the systems we deliver and retrofit it into the ones you already have: identity, least privilege, encryption, logging that can't be tampered with, and evidence collection that makes the next audit a formality.

What's included

Capabilities

01

Identity & access

SSO, MFA, Entra ID / Okta integration, role design and periodic access reviews across your applications.

02

Application security

Threat modelling, secure SDLC, dependency and secret scanning in CI, and penetration-test remediation.

03

Data protection

Encryption in transit and at rest, key management, data classification and residency controls, PII redaction pipelines.

04

Audit & evidence

Append-only logs, hash-chained ledgers and automated evidence collection mapped to SOC 2, ISO 27001, HIPAA or GLBA controls.

05

Cloud security posture

Guardrails, CSPM findings triage, network segmentation and incident response runbooks.

06

Vendor & edge security

Signed releases, outbound-only edge connectivity, TLS everywhere, loopback-only services until exposure is earned.

How we work

From first call to steady state.

  1. Step 1

    Assess

    Gap analysis against the framework you're targeting, prioritised by exploitability rather than checkbox order.

  2. Step 2

    Remediate

    Engineering fixes, not policy PDFs. Each control gets an owner, an implementation and a test that proves it holds.

  3. Step 3

    Evidence

    Automate the collection of proof so the audit is a query, not a quarter.

  4. Step 4

    Sustain

    Continuous scanning, access reviews and tabletop exercises under a managed agreement.

What you get
  • ✓Least-privilege access enforced through your identity provider
  • ✓Audit evidence generated by systems, not assembled by hand
  • ✓Secrets never in code, logs never carrying content
  • ✓Controls with a named owner and a test in CI
Typical stack
Entra IDOktaAWS IAMKMSVaultCloudflareLet's EncryptSnykTrivyOpenTelemetryWazuh

Case studies

Related work

Anonymised where the client asked for it. Every outcome listed is one we can substantiate.

Questions

Frequently asked

Do you provide SOC 2 certification?+

We do the engineering and evidence work; certification is issued by an independent auditor we'll work alongside.

Is there a product, or only services?+

Both. CAM, our AI-powered compliance and audit management platform, runs audits, vendor responses, policy approval, training and certificate tracking as a service we host. We configure it for the frameworks you're audited against and engineer the controls it tracks.

Other services

Talk to us about security & compliance.

One scoping call with a delivery lead and an architect. We'll say plainly whether — and how — we'd take it on.

Talk to us