Skip to content
Public, versioned, self-assessed

We build AI systems, engineered to a published standard.

Whole systems, end to end. We start with how the work actually happens, and hand over something your own team can run.

The problem

Most organisations cannot show how their systems work.

The work was never really visible. Leadership believes it runs through the platform; in practice a good deal of it runs through spreadsheets, re-keyed documents and people who know which fields to ignore.

AI has been layered on top of that, quickly, and often without controls. Software now makes decisions inside processes nobody had mapped, with permissions nobody set deliberately and a record nobody kept.

That was survivable while nobody was asking. It is not any more. Regulators, customers and auditors now expect organisations to produce an inventory of the AI they run, evidence of how it was built and tested, and a record of what it did. Most cannot.

63%of breached organisations had no AI governance policy to manage AI or prevent unsanctioned useIBM and Ponemon Institute, Cost of a Data Breach Report, 2025
97%of organisations that reported an AI-related security incident lacked proper AI access controlsIBM and Ponemon Institute, Cost of a Data Breach Report, 2025
40%+of agentic AI projects will be cancelled by the end of 2027, with inadequate risk controls among the causesGartner, June 2025

This is an engineering problem before it is a compliance problem. Controls that were never built cannot be documented after the fact.

What we do

Whole systems, in six areas.

Most projects draw on more than one. A system that only exists in one of them does not run in production.

01AI systems

AI systems

Agents, retrieval and language applications that do real work inside a business, not demonstrations.

  • AI agents
  • Retrieval & knowledge systems
  • Messy document processing
Learn more about AI systems
02Product engineering

Product engineering

The interfaces people actually use — internal tools, review dashboards and the consoles that keep a system supervised.

  • Internal tools & operational web apps
  • Human-in-the-loop review dashboards
  • Operator & oversight consoles
Learn more about Product engineering
03Automation & integration

Automation & integration

Connecting the systems you already run, so nobody reconciles anything by hand.

  • System plumbing & integration
  • Workflow automation
  • Integration into daily tools
Learn more about Automation & integration
04Data & analytics

Data & analytics

The platforms, pipelines and definitions that reporting and AI both depend on.

  • Data platforms & warehousing
  • Pipelines
  • Data quality & governance
Learn more about Data & analytics
06AI governance & compliance

AI governance & compliance

The documentation, logging and oversight that let you evidence what your systems do.

  • Conformity-ready build & governance setup
  • Article 50 transparency build
  • Decision records & human review
Learn more about AI governance & compliance
How we build

We publish the standard we build to.

Most firms describe their engineering practice in adjectives. Ours is written down, versioned, and public — the same document we work to and the same one you can hold us to.

It covers how we handle your data and credentials, how code is reviewed and released, how AI systems are scoped and tested, and what happens after we leave.

Built against the standards the industry actually uses:

OWASPLLM & AgenticTop 10

OWASP

Top 10 for LLM Applications and for Agentic Applications

SSDFSP 800-218 / 218A

NIST SSDF

SP 800-218, and 800-218A for generative AI

SLSABuild Level 3

SLSA

Build Level 3

AI RMFGovern · Map · Measure

NIST AI RMF

govern, map, measure, manage

CISCloudbenchmarks

CIS

cloud benchmarks

What you receive

Every project ships with these as standard, not on request:

  • Source and infrastructure as code — in repositories you own
  • Architecture documentation — what depends on what, and why
  • Threat model — what the system touches, and what happens when it misbehaves
  • Dependency inventory — a software bill of materials for every release
  • Build provenance — signed records of how each artifact was built, verifiable with your own tooling
  • Security review record — what was tested, what was found, what was done
  • Runbook — how to operate it, written for your team

You own all of it. None of it is contingent on continuing to work with us.

Industries

Built for sectors that still run on paper.

The same engineering, applied where the manual work is heaviest and the tolerance for error is lowest.

Dealer networks, warranty claims and parts catalogues held together by re-keyed documents and systems that were never meant to talk to each other.

What we build here

  • warranty and claims document processing
  • dealer and OEM system integration
  • parts and service data platforms
  • agents that triage service requests

Start with what you already run.

We work inside your existing stack — your cloud, your data platform, your model providers, your tools. The first thing we do is understand how the work runs today.

Your platforms, your accounts, your repositories. Everything we build is handed over and runs without us.

modularitiEngineering  :  
Available