Security Competency
Submitted for residency-first architecture, least-privilege identity, and audit trails designed in from the first schema.
- Under review
- August 2026
- Expected Q1 2027
- 2 submitted
What it covers
Constraints, not configuration flags.
Our submission centres on workloads where residency and auditability were architectural constraints from the first schema — public health records and regulated lending.
Data residency
Region-pinned storage and processing designed in, not retrofitted.
Identity & access
Least-privilege models with access reviewed as a standing practice.
Audit logging
Immutable trails that stand up to external examination.
Secure delivery
Scanning and policy checks inside the pipeline, not after release.
Validation criteria
What AWS assessed.
This competency is under AWS review. Two regulated engagements have been submitted; the technical review is scheduled for early next year.
How validation worksRegulated workloads
Public sector and fintech engagements with residency requirements.
Control mapping
PCI and SOC control coverage documented against real architectures.
Technical review
AWS security review scheduled for Q1 2027.
Final validation
Decision expected in the first half of next year.
Evidence
The engagements behind it.
These are the customer references submitted to AWS for this competency. Ask us about any of them.
0
Audit findings
Residency-first health registry
Region-pinned storage, least-privilege access, and immutable audit logging for sensitive population data.
1.8s
Decision latency
Credit decisioning with KYC trails
Underwriting pipeline with auditable decision records meeting KYC and AML requirements.
Architecture
Patterns behind this practice.
Services
What we build it on.
- IAM
- KMS
- CloudTrail
- Config
- WAF
- Shield
- Security Hub
Team on this practice
Security sits with the cloud practice — the same nine people who own the landing zone own the posture.
Other competencies.
All designationsMigration & Modernization
Validated for moving production estates onto AWS without a maintenance window, and for decom…
Cloud Operations
Validated for operating what we build — observability, incident practice, cost management, a…
Data & Analytics
Validated for warehouses, streaming pipelines, and managed ETL that stay operable after the …
Machine Learning
Submitted for applied AI that acts inside a product rather than alongside it — agent tooling…
Work with this practice
Workload an auditor will examine?
Discovery comes first — a short, bounded review that ends in an architecture, a scope, and a price. You keep the output either way.