UK cyber security consultancy / EPIC28 Ltd

Security you can prove.

EPIC28 designs security architecture for organisations that cannot afford to assert and hope: banks, hospitals, retailers, manufacturers and government. We advise, we design, and we build the products that turn security claims into evidence. Our first, Raucle, puts every AI agent action on the record.

Work with us Explore Raucle
live traffic · hover a request for its receipt · denied calls stop at the seam
01 / Why EPIC28

A bank answers to the FCA. A hospital answers to its board. A retailer answers to the card schemes. A manufacturer answers to the customers who audit its supply chain. In every sector the standard is the same: prove it. Most security work stops at policy. Ours ends in evidence.

The practice

Advisory
01

Security architecture

SABSA-driven target architecture for organisations modernising under pressure. Design reviews, control mapping and delivery roadmaps that stand up in the architecture review board and in operation. From zero-trust patterns to the operating model that makes them stick.

02

AI security advisory

AI is now part of your attack surface and your delivery pipeline. We advise on securing AI systems and the agents that act on your behalf: how safeguards, sandboxing and active oversight become controls you can enforce. Aligned to the Code of Practice for the Security of AI, ETSI EN 304 223 and EU AI Act Article 12 logging duties.

03

Assurance and audit readiness

Assurance for organisations under audit everywhere: evidence that controls operate, not claims that they exist. We design the evidence trail an auditor, regulator, customer or supervisory review can verify independently.

Products

01 / Raucle

Raucle. Our first product.

We build what we advise. Raucle came out of advisory work with organisations that needed more than assurance on paper: proof of what an AI agent was authorised to do, and what it actually did. Every tool call an agent makes is gated against a signed, least-privilege capability, and every decision produces a cryptographic receipt. Receipts are content-addressed, immutable and verifiable offline by any auditor, regulator or partner organisation, with no vendor contact required. Full detail, documentation and the live demo live at raucle.com, the product's home.

raucle.com — the product site github.com/epic28-ltd/raucle
100%
block rate on attacker-controlled tool calls, AgentDojo banking suite
69 µs
median gate decision per call, no attenuation chain
4+
framework adapters: Microsoft Agent Framework, LangChain, AutoGen, MCP gateway
Apache-2.0
open source; Lean proofs, benchmark harness and paper draft published with the code
Live topology simulated agent traffic, real enforcement semantics
allow deny Zoomed to the busiest nodes at first. Drag to pan, scroll to zoom, click a node to isolate its paths.

About

EPIC28 Ltd is a cyber security consultancy built around one idea: security you can prove.

Our consultants have spent twenty-five years inside banking and capital markets, central government and defence, manufacturing, retail, telecoms and software security. The work has always been the same: architecture that survives contact with regulators, auditors and attackers.

We advise on security architecture for the age of AI, and we build what we recommend. Raucle, our first product, came out of that advisory work. Regulated organisations need proof of what an agent was allowed to do and what it actually did, and that proof has to survive outside a vendor's log file. So Raucle is open source, cryptographic and independent.

Contact

Start a conversation.

Engagements across finance, healthcare, manufacturing, retail, defence and the public sector, Raucle deployments and press enquiries.

Engagements and Raucle[email protected]