EPIC28 is a cyber security consultancy serving banking, healthcare, manufacturing, retail and government. We design security architecture, advise on AI security, and build products that turn security claims into evidence. Our first product is Raucle.
Target-state architecture, design reviews, control mapping and delivery roadmaps. We work to SABSA and to the standards your sector already recognises, and we stay engaged through build and operation, not just the review board.
We advise on securing AI systems and the agents that act on your behalf, from model selection to enforcement of what agents are permitted to do. Our advisory work aligns to the Code of Practice for the Security of AI, ETSI EN 304 223 and EU AI Act Article 12.
We design evidence trails that show controls operating, in a form an auditor, regulator or customer can verify independently.
Raucle came out of our advisory work. It gates every tool call an AI agent makes against a signed, least-privilege capability, and records each decision as a cryptographic receipt. Receipts are immutable and can be verified offline by any auditor, regulator or partner, without contacting us. Documentation, the specification and a live demo are at raucle.com.
raucle.com — the product site github.com/epic28-ltd/raucleEPIC28 Ltd is a cyber security consultancy. We design security architecture for regulated organisations and build products that produce evidence, not assertions.
Our consultants have spent twenty-five years in banking and capital markets, central government and defence, manufacturing, retail, telecoms and software security.
Raucle, the product above, is the result: open source under Apache-2.0.
For engagements, Raucle deployments or press, use the address that fits. Every message reaches a consultant.