Skip to main content
Data center racks with power management equipment and network cabling

Canadian AI governance + security

Signal & Soil

Evidence-led AI governance for organizations that need their systems to stand up to scrutiny, incident pressure, and board-level questions.

Paris 2024 Olympics & Paralympics security

iPhone launch security architecture

Microsoft Trustworthy Computing

What we look for

The work starts below the surface.

Generic AI sites sell certainty. Real AI governance has to expose the awkward parts: unclear ownership, brittle vendors, missing logs, untested controls, and promises no one can prove.

Surface claim

A tool inventory

Evidence needed

Which workflows depend on AI, who owns them, where data moves, and what evidence proves the control works.

Surface claim

A policy PDF

Evidence needed

Decision rights, escalation paths, exception handling, vendor obligations, and board-ready reporting cadence.

Surface claim

A model assessment

Evidence needed

Threat paths across prompts, retrieval, agents, identity, monitoring, logging, and operational recovery.

Signal is what the system says. Soil is the operating reality beneath it. We work where the two disagree.

Track record

Receipts before roadmaps.

The useful part of experience is pattern recognition: knowing which risks are real, which controls are performative, and what proof survives operational pressure.

Global platforms

AI governance and security programs for products serving 100M+ users

Telecom + mobile

Security design and implementation for the iPhone launch at AT&T

Microsoft

Trustworthy Computing, open source security assessment, and customer-facing security

Major events

Cybersecurity for the Paris 2024 Olympics & Paralympics

Critical systems

E-voting, anonymization, internet backbone, and cloud infrastructure security

Standards used as tools, not wallpaper

NIST CSF 2.0 NIST AI RMF ISO 42001 ISO 27001 ISO 31000 FAIR SOC 2 OWASP LLM Top 10 OWASP Agentic AI Google SAIF

Method

Start with the ground truth. Then build the system.

Governance fails when it starts as a slide deck. We start with the operating environment, then turn findings into repeatable controls.

01

Map

Locate the AI systems, vendors, data paths, owners, and unspoken dependencies.

02

Stress

Test assumptions against security threats, failure modes, regulatory duties, and recovery pressure.

03

Govern

Define decisions, controls, monitoring, exceptions, and evidence that people can actually maintain.

04

Transfer

Leave teams with artifacts, operating rhythms, and reporting they can run after the engagement.

Trust signals

Built for the infrastructure you already run.

AWS

Cloud control design

GCP

Data and platform risk

Azure

Enterprise identity and governance

Identity Data lineage Vendor risk Logging Incident response CISSP ISSMP

Where this matters

Useful when failure has consequences.

AI governance gets real when a missed control affects citizens, patients, customers, infrastructure, or the board packet due next week.

01

Public Sector

Citizen-facing AI, public safety workflows, procurement scrutiny, and audit-ready accountability.

02

Financial Services

Model governance, third-party concentration, fraud systems, operational resilience, and regulator evidence.

03

Healthcare

Clinical decision support, privacy, safety review, incident response, and patient-impact escalation.

04

Energy & Utilities

Critical infrastructure, predictive maintenance, OT/IT security boundaries, and continuity planning.

05

Tech & SaaS

LLM features, agentic workflows, customer trust, platform security, and security review at product speed.

06

Professional Services

Knowledge automation, client confidentiality, workflow redesign, and defensible AI use policies.

Start here

Bring the messy version.

A useful first conversation starts with what is already in motion: the tools, vendors, pressure, incidents, audit asks, and executive questions that do not fit neatly in a slide deck.