Services from the team that builds Purogaly

Consulting & Training

Purogaly is an AI access security and governance platform. The same expertise that built it is available as advisory, assessment, and enterprise training engagements — AI security and governance first, human risk and GRC alongside it.

Consulting engagements are advisory and are scoped separately from platform licensing.
Primary practice

AI Security & Governance Consulting

Establishing how an organisation governs AI — what is in use, who may use it, under what controls, and what evidence proves it. Grounded in the same control model that runs inside the Purogaly platform.

Assess
  • Enterprise AI security and governance assessments
  • AI risk assessments
  • Shadow AI risk and governance
  • AI inventory and classification
  • AI third-party and vendor risk
Design
  • AI governance program design
  • AI acceptable-use policies
  • AI security controls
  • Human-in-the-loop and approval governance
Access and identity
  • AI access governance
  • AI agent and non-human identity governance
Align and prove
  • NIST AI RMF alignment
  • ISO/IEC 42001 alignment
  • AI auditability and evidence
Enable
  • AI governance workshops for security, risk, compliance, and leadership teams
Discuss an AI governance engagement →

Security Awareness & Human Risk Training

Enterprise awareness and human-risk programs — designed, delivered, and measured. Program strategy and content, including AI-specific awareness for organisations rolling out GenAI.

Programs
  • Enterprise cybersecurity awareness training
  • New-hire security awareness
  • Role-based security training
  • Security policy and acceptable-use training
Threat-specific
  • Phishing and social-engineering awareness
AI-specific
  • AI security awareness
  • Safe employee use of GenAI
  • Shadow AI and sensitive-data awareness
Culture and leadership
  • Security culture and human-risk programs
  • Executive and leadership security briefings
Measure
  • Security awareness program assessments
  • Awareness metrics and behavior-risk measurement
Discuss a training program →

GRC & Security Consulting

Governance, risk, and compliance support across audit cycles and control frameworks — from policy and control design through to audit readiness and executive reporting.

Advisory and policy
  • Security and GRC advisory
  • Security policy development and review
Assess and control
  • Risk assessments
  • Security control design and assessment
  • Third-party security risk
Audit and frameworks
  • SOC 2 Type II support
  • SOX ITGC support
  • ISO 27001 readiness and support
  • Audit readiness and evidence management
Report
  • Security metrics, KRIs and KPIs
  • Governance and executive reporting
Discuss a GRC engagement →

How engagements work

Assessment

A scoped review against a defined standard, ending in findings, risk ratings, and a prioritised remediation plan.

Program design

Building the governance structure itself — policies, controls, roles, and the evidence model that supports them.

Workshop

A focused working session for security, risk, compliance, or leadership teams. Half-day or full-day.

Ongoing advisory

Retained hours for audit cycles, framework alignment, or standing governance support.

Why Purogaly

Most AI governance advice comes from consultancies that have never had to enforce it, and most enforcement software comes from engineers who have never sat through an audit.

Purogaly's consulting practice sits on both sides: a background in GRC and compliance — SOC 2 Type II, SOX ITGC, ISO 27001, and identity governance — and a production AI security and governance platform built against those same requirements. Recommendations are made by someone who has had to implement them in software and defend them as evidence.

Start a conversation

Tell us what you are trying to govern, assess, or train for. We will tell you honestly whether it is an advisory engagement, a platform deployment, or neither.