Banks, hospitals, retailers, factories, defence programmes and government departments are putting AI agents to work. EPIC28 builds the security architecture that makes an agent's authority enforceable, and the evidence that proves what it did. Our first product, Raucle, delivers both.
SABSA-driven target architecture for organisations modernising under pressure. Design reviews, control mapping and delivery roadmaps that stand up in the architecture review board and in operation. From zero-trust patterns to the operating model that makes them stick.
Guidance on deploying AI agents safely: how safeguards, sandboxing and active oversight become controls you can enforce, and where an agent's authority should stop. Aligned to the Code of Practice for the Security of AI, ETSI EN 304 223 and EU AI Act Article 12 logging duties.
Assurance for organisations under audit everywhere: evidence that controls operate, not claims that they exist. We design the evidence trail an auditor, regulator, customer or supervisory review can verify independently.
Every regulated sector has the same audit problem. A bank must show the FCA what its agents did and under what authority. A hospital trust answers to its board, a defence programme to its accreditors, a government department to the National Audit Office. A retailer answers to the card schemes, a manufacturer to the customers who audit their supply chain. Raucle gates every tool call an agent makes against a signed, least-privilege capability, and produces a cryptographic receipt of what was authorised and what ran. Receipts are content-addressed, immutable and verifiable offline by any auditor, regulator or partner organisation, with no vendor contact required.
raucle.com github.com/epic28-ltd/raucleEPIC28 Ltd is a cyber security consultancy built around one idea: security you can prove.
Our consultants have spent twenty-five years inside banking and capital markets, central government and defence, manufacturing, retail, telecoms and software security. The work has always been the same: architecture that survives contact with regulators, auditors and attackers.
We advise on security architecture for the age of AI, and we build what we recommend. Raucle, our first product, came out of that advisory work. Regulated organisations need proof of what an agent was allowed to do and what it actually did, and that proof has to survive outside a vendor's log file. So Raucle is open source, cryptographic and independent.
Engagements across finance, healthcare, manufacturing, retail, defence and the public sector, Raucle deployments and press enquiries.