AI Governance · Azure · Regulated Enterprise

I build AI platforms that pass the audit.

Twenty years of Azure, AWS, identity and Kubernetes - and the control mappings that make a platform defensible to your risk committee. Most consultancies can write the mapping or ship the Terraform. I do both.

20+ yearscloud & platform architecture
Azure · AKS · Entra IDprimary stack, AWS/GCP secondary
DORA · NIS2 · PCI DSSmappings that survive review
ARB to terraform applygovernance and build, one person

Services

Three ways this usually starts

Each one is scoped to produce something your risk function can read and your platform team can deploy - not a slide deck.

01

AI Landing Zone

An API gateway in front of your model endpoints: model allowlists, per-team token quotas and chargeback, prompt and response logging, tenant isolation. Terraform, from day one. Ends the era of API keys in config files.

What's included →

02

AI Act readiness

Inventory what your teams have actually shipped, classify it against the Act, and map the Article 50 duties that already bite to concrete platform controls - with a runway to the December 2027 high-risk deadline.

What's included →

03

Identity & Zero Trust review

Entra ID architecture, Conditional Access design, Global Secure Access and workload identity - reviewed against the access-control clauses every framework opens with, and remediated in code.

What's included →

Is your AI platform defensible?

Thirty minutes, no deck. Tell me what your teams have shipped and where the audit pressure is coming from, and I'll tell you what I'd look at first - whether or not you hire me.