Engagements
Engagement Catalogue
An engagement is a scoped piece of work with a written boundary, a named set of inputs, and a fixed list of artefacts you keep at the end of it. It is not a subscription, a licence or a standing retainer, and nothing in this catalogue runs continuously inside your estate. Each page states what the work covers, what it deliberately leaves out, and what you receive.
Grouped by category, in the order the work usually runs: inventory first, then a review of a single layer, then engineering, then the briefing that turns a position into decisions.
INVENTORY
Inventory
Establish what cryptography exists across the estate, where it lives, and how exposed each asset is. Everything else in this catalogue reads the register this produces.
REVIEW
Review
Go deep on one layer: transport and PKI, signing and identity, or key management. A review assumes the layer matters enough to warrant more than an inventory entry.
Transport & PKI Review
A review of X.509 chains, issuance and expiry, TLS terminators, cipher suites and key exchange, mutual TLS, and the internal certificate authorities behind them.
Read the engagementREVIEWSigning & Identity Review
A review of code signing and artefact provenance, token and assertion signing, document signing, and SSH host and user keys across the estate.
Read the engagementREVIEWKey Management Review
A review of KMS and HSM key inventory, rotation and custody boundaries, secrets stores, key lifecycle and escrow, and algorithm agility at the key layer.
Read the engagementENGINEERING
Engineering
Turn a scored register into an ordered programme of change, with a rollback at every step and the performance impact measured on your own workload first.
BRIEFING
Briefing
Take an exposure position into the room where budget is allocated, and leave with decisions, owners and a sequence an auditor can follow.
Scope comparison
Which engagement reads which surface
Five surfaces make up the estate we assess: transport and PKI, signing and identity, key management, the source tree and build chain, and the evidence pack an auditor or regulator receives. The grid below is derived from the catalogue itself, so it cannot drift out of step with the pages it summarises.
| Estate surface | Estate Inventory | Transport & PKI Review | Signing & Identity Review | Key Management Review | Migration Engineering | Executive Briefing | Engagements |
|---|---|---|---|---|---|---|---|
| Evidence and audit packThe reproducible pack an auditor, regulator or customer receives: register extract, attestation reference, hashed evidence and the method version behind each figure. | Covered | Covered | Covered | Covered | Covered | Covered | 6 |
| Transport and PKITLS terminators, X.509 chains, internal certificate authorities, mutual TLS between services, and the expiry calendar behind all of it. | Covered | Covered | Not covered | Not covered | Covered | Not covered | 3 |
| Signing and identityCode and artefact signing, token signing, SAML and OIDC assertion signing, document signing, and SSH host and user keys. | Covered | Not covered | Covered | Not covered | Covered | Not covered | 3 |
| Key managementManaged key services, hardware security modules, secrets stores, rotation and custody boundaries, escrow and destruction. | Covered | Not covered | Not covered | Covered | Covered | Not covered | 3 |
| Source tree and build chainRepositories, dependency manifests, resolved library versions, container base images, and the pipelines that sign what you ship. | Covered | Not covered | Covered | Not covered | Covered | Not covered | 3 |
| Surfaces covered | 5 | 2 | 3 | 2 | 5 | 1 | 18 |
Evidence and audit pack
6 of 6
The reproducible pack an auditor, regulator or customer receives: register extract, attestation reference, hashed evidence and the method version behind each figure.
Transport and PKI
3 of 6
TLS terminators, X.509 chains, internal certificate authorities, mutual TLS between services, and the expiry calendar behind all of it.
Signing and identity
3 of 6
Code and artefact signing, token signing, SAML and OIDC assertion signing, document signing, and SSH host and user keys.
Key management
3 of 6
Managed key services, hardware security modules, secrets stores, rotation and custody boundaries, escrow and destruction.
Source tree and build chain
3 of 6
Repositories, dependency manifests, resolved library versions, container base images, and the pipelines that sign what you ship.
Ordered by the number of engagements covering the surface, highest first. Surfaces level on that count keep their catalogue order. Columns follow catalogue order.
Assemble the scope you need
The scope builder takes the engagements and estate surfaces you select and writes out the resulting scope: the artefacts you would receive, the inputs we would need, and the surfaces left explicitly outside it. It produces a scope summary and no quotation. If you would rather talk it through, a demo is the faster route.