TechnologyFlagship industry

B2B technology. Buyers self-educate for months.

The product, the site and the assistant do the selling first.

Software, platform and IT-services companies selling to buying committees. We build the positioning, the product-led site, the assistants that answer like your best engineer, and the evidence procurement asks for before anyone books a call.

The number we move
Qualified pipeline
Where we work in B2B technology
  • SaaS
  • Enterprise software
  • Developer platforms
  • Data & AI platforms
  • Vertical software
Rules mapped
7 rules · 3 areas
Disciplines that lead
BrandAIProduct
Frameworks we build to
SOC 2 — Trust Services CriteriaISO/IEC 27001:2022 — Information security management systemsEU AI Act — Artificial Intelligence Act (EU) 2024/1689OWASP Top 10 for LLM Applications — LLM and generative AI security risksGDPR — General Data Protection Regulation (EU) 2016/679DPDP Act 2023 — Digital Personal Data Protection Act, 2023WCAG 2.2 AA — Web Content Accessibility Guidelines
The back of a wall of modular LED display panels, wired with black cables
B2B technologyBehind every screen a buyer sees is wiring they never will.

Where the rules biteMap of all forty-one industries

  • Claims Advertising & claims: Sometimes shapes the work
  • Regulator Sector regulator: Sometimes shapes the work
  • Payments Payments: Sometimes shapes the work
  • Data Personal data: Shapes most of the work
  • Security Security & incidents: Shapes most of the work
  • Access Accessibility: Often shapes the work
  • AI AI governance: Shapes most of the work

What is shifting

The buyer reads everything before your team hears a word.

Committees research through assistants, peers and your documentation, and procurement asks its questions first. Each shift names what it demands, with a signal you can check.

A presenter points to bar charts on a large screen while colleagues watch from the table
The buying committee meets long after it has done its research.
  1. Buying committees research through AI assistants and peer communities before talking to sales.

    It demandsPositioning that separates the product in a crowded category.

    SignalAssistants now summarise vendors, reviews and documentation on request.

  2. Procurement asks for security, privacy and accessibility evidence up front.

    It demandsA site and product experience that answer the questions sales keeps repeating.

    SignalSOC 2 reports and ISO/IEC 27001 certificates are standard asks in enterprise security reviews.

  3. Every product now ships AI features — and has to explain and govern them.

    It demandsAI features that are evaluated, governed and safe to demo.

    SignalEU AI Act transparency duties for AI that talks to people apply from 2 August 2026.

  4. Customers can now leave a cloud service on two months’ notice.

    It demandsExport and exit paths designed into the product, not negotiated later.

    SignalThe EU Data Act’s switching rules have applied since 12 September 2025.

The rulebook

Procurement reads the rulebook before it reads the deck.

The security attestations, AI rules and data duties enterprise buyers ask about, read for a typical software programme. Your counsel and auditors keep sign-off; we build the evidence they will look for.

Frameworks we build to

  • SOC 2 — Trust Services Criteria
  • ISO/IEC 27001:2022 — Information security management systems
  • EU AI Act — Artificial Intelligence Act (EU) 2024/1689
  • OWASP Top 10 for LLM Applications — LLM and generative AI security risks
  • GDPR — General Data Protection Regulation (EU) 2016/679
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • WCAG 2.2 AA — Web Content Accessibility Guidelines

Frameworks we design and build to — not a claim of certification.

Personal data

Shapes most of the work

  1. European Union · Government of India

    GDPR and DPDP Act

    Data-processing terms, consent and cross-border transfer for customer data.

    We designProcessing records and sub-processor lists are kept with the product, not in a drawer.

    Regulation (EU) 2016/679 · DPDP Act, 2023

  2. European Union

    EU Data Act — switching

    Cloud and SaaS customers may switch providers on at most two months’ notice with their data exportable; switching charges end on 12 January 2027.

    We designExport and exit paths are designed into the product and documented in the contract.

    Regulation (EU) 2023/2854, applicable from 12 September 2025 Official text: EU Data Act — switching

Security & incidents

Shapes most of the work

  1. AICPA · ISO/IEC

    SOC 2 and ISO/IEC 27001

    The security evidence buyers ask for; we build systems and documentation that support your audit. Reports and certificates come from independent auditors.

    We designControls and their evidence are built into delivery, so your auditor finds them where they belong.

    AICPA Trust Services Criteria · ISO/IEC 27001:2022

  2. Indian Computer Emergency Response Team

    CERT-In Directions, 2022

    Service providers in India report cyber incidents within six hours and keep ICT logs for 180 days.

    We designLogging and incident runbooks ship with the platform.

    CERT-In · Directions of 28 April 2022 Official text: CERT-In Directions, 2022

AI governance

Shapes most of the work

  1. European Union

    EU AI Act

    Prohibited practices since February 2025; transparency for AI that talks to people from 2 August 2026; high-risk obligations moved to December 2027 by the 2026 Digital Omnibus.

    We designAssistants say they are AI, and each feature’s risk class is documented.

    Regulation (EU) 2024/1689, as amended by the 2026 Digital Omnibus Official text: EU AI Act

  2. OWASP GenAI Security Project

    OWASP Top 10 for LLM Applications

    Prompt injection (LLM01), sensitive information disclosure (LLM02), excessive agency (LLM06) and the other risks we test assistants against.

    We designEvery assistant is red-teamed against the list before release.

    OWASP Top 10 for LLM Applications, 2025 edition Official text: OWASP Top 10 for LLM Applications

  3. ISO/IEC

    ISO/IEC 42001

    An AI management system standard: policy, risk and impact assessment and controls across the AI lifecycle.

    We designAI features ship with the records an AI management system expects.

    ISO/IEC 42001:2023 Official text: ISO/IEC 42001

Compiled 2 October 2026. Our reading of typical programmes, not legal advice. Rules change; your counsel confirms how each one applies to you.

Challenges

Answers before the first meeting, evidence before the shortlist.

What buying committees expect to find for themselves, and what it takes your teams to keep product, site and sales telling one story.

Your customers

  1. Answers before a meeting

    Buyers expect pricing logic, security posture and integrations to be public.

  2. A demo that proves it

    Buyers want to try the product, and the AI in it, on their own questions.

  3. Evidence for procurement

    Security, privacy and accessibility questionnaires decide the shortlist.

Two people working on code across large monitors in a bright office
Product and engineering ship the story as much as marketing does.

Your operation

  1. One story everywhere

    Product, site and sales materials drift apart without a shared system.

  2. AI features to govern

    Every AI feature needs evaluations, guardrails and a way to explain it.

  3. Long, many-person deals

    Each member of a buying committee needs different proof at a different stage.

What we build

Positioning, product and assistants, built as one system.

Product, brand and AI design lead a B2B programme; platform, CRM and content support them. Every line links to the capability that does the work.

Leads Core Supports Share of a typical programme, by role · illustrative
  1. 01

    Brand Design

    Leads

    Positioning, category narrative and a brand system for product and marketing.

  2. 02

    AI Design

    Leads

    Assistants with retrieval, evals, guardrails and human escalation.

  3. Product UX, onboarding and a design system shared with engineering.

  4. Web platforms, integrations and AI infrastructure.

  5. Lead scoring, routing and account journeys for long buying cycles.

  6. Category content and points of view that assistants can cite.

Programmes

Collect the buyers’ questions first, then build what answers them.

The way in gathers the questions buyers put to sales and procurement and shows which ones the site, the product and the documentation already answer. Lengths are typical, never promised.

The way in

Buyer-question and evidence audit

We collect the questions buyers put to sales and procurement, then show which ones the site, the product and the documentation already answer.

Package
Sprint · Fixed fee
Typical length
2–3 weeks
It sets
Sales-cycle length, as a baseline
  • Product experience audit
  • AI search visibility (AEO & GEO)

What it hands over

  • A buyer-question map with the gaps ranked
  • A trust-page outline for procurement
  • Answers to reuse in sales and in an assistant
Start here
  1. 02Project · 8–12 weeks

    Positioning and brand system

    A category story, a messaging hierarchy and a brand system that product and marketing both use.

    MovesQualified pipeline from organic and AI channels

    Services: Brand foundation & positioning · Brand narrative & messaging · Logo & identity system

    Enquire about Positioning and brand system
  2. 03Milestone · 3–6 months

    Product-led site and demo experience

    A site that answers the technical questions, with an interactive demo buyers can run themselves.

    MovesTrial-to-paid or demo-to-opportunity rate

    Services: Website · Vision prototype

    Enquire about Product-led site and demo experience
  3. 04Project · 8–12 weeks

    Sales and support assistant with evals

    An assistant grounded in your documentation, red-teamed and measured on an evaluation set before it meets a buyer.

    MovesAssistant answer accuracy on the eval set

    Services: AI knowledge assistant · AI assistant experience design · Brand fidelity evaluation

    Enquire about Sales and support assistant with evals
  4. 05Project · 8–12 weeks

    Design system shared by product and marketing

    Tokens and components that product, site and sales materials share, so the story never drifts.

    MovesTime to ship a new page or feature

    Services: Design system build · Design tokens & theming

    Enquire about Design system shared by product and marketing

How success is measured

The number we moveQualified pipeline

  • Qualified pipeline from organic and AI channels
  • Trial-to-paid or demo-to-opportunity rate
  • Assistant answer accuracy on the eval set
  • Sales-cycle length

AI, under the rules

An assistant that answers like your best engineer, and says when it does not know.

Every assistant is grounded in your documentation, red-teamed against the OWASP list and measured on an evaluation set before it meets a buyer.

Use case 01

Sales and support assistant

Measured byAnswer accuracy on the eval set

Tested forOWASP LLM01 · Prompt injection

agent / sales-and-support-assistant Guarded
  1. TaskAnswers technical and commercial questions from the docs, the trust page and the release notes.
  2. GuardrailCites a source for every answer, says “I don’t know” rather than guessing, and makes no roadmap promises.
  3. HumanPricing and contract questions route to a person.
  4. LogQuestions, sources and unanswered gaps go to the docs team.

Ships only with its evaluation set, its guardrail and an owner

Use case 02

Security questionnaire drafting

Measured byDays to return a questionnaire

Tested forOWASP LLM02 · Sensitive information disclosure

agent / security-questionnaire-drafting Guarded
  1. TaskDrafts answers to security and privacy questionnaires from approved policies and evidence.
  2. GuardrailUses approved answers only and flags every question that has none.
  3. HumanThe security lead approves every submission.
  4. LogEach answer tied to the policy version it came from.

Ships only with its evaluation set, its guardrail and an owner

Use case 03

In-product AI with evals

Measured byEvaluation pass rate per release

Tested forOWASP LLM06 · Excessive agency

agent / in-product-ai-with-evals Guarded
  1. TaskShips the product’s own AI features — summaries, search and agents — with an evaluation suite.
  2. GuardrailRed-teamed before release; tools limited to what each task needs.
  3. HumanThe product owner approves any release that changes behaviour.
  4. LogEvaluations run on every release and are kept with the build.

Ships only with its evaluation set, its guardrail and an owner

A deliverable, in working code

Clear a security review one answer at a time.

An enterprise security questionnaire in progress. Mark answers as ready and the tracker recounts what is still open before you can submit. Illustrative items.

Security review trackerIllustrative

Enterprise security questionnaire · in progress

Answers ready4 / 7 answered
  • AnsweredSSO (SAML / OIDC) and SCIMAnswered from the identity runbook
  • AnsweredData-processing agreementSigned template on the trust page
  • AnsweredData residency · India regionHosting map attached
  • AnsweredAI: no training on customer dataPolicy and model card linked
  • In progressPenetration-test summaryAwaiting the tester’s letter
  • In progressSub-processor listTwo vendors to confirm
  • To doAccessibility conformance reportScheduled after the WCAG audit

What it shows

An illustrative enterprise security review: SSO, the data-processing agreement, data residency and AI data use are answered; the penetration-test summary and sub-processor list are in progress; an accessibility report is still to do. Mark answers as ready and the tracker recounts what is open.

Figures

Every number here is an illustration of how the deliverable reads, never a client result.

Work and insights

Pipeline, demos and assistants, anonymised.

B2B projects, anonymised until each client approves the write-up, and what we have written on evaluations and guardrails.

All work in B2B technology

A typical programme · composite

A software company launched a product experience and an assistant that answers the questions sales kept repeating.

Anonymised and illustrative: the shape a programme takes, never a named client.

Questions

What product, marketing and security leads ask us first.

Something else on your mind? Ask us directly

Q.01Do you help with SOC 2 or ISO 27001?

We build systems and documentation that support your audit and prepare the evidence auditors ask for. The attestation report or certificate itself comes from an independent auditor.

Q.02Can our assistant be safe to demo to enterprise buyers?

Yes. It is evaluated on your buyers’ questions, red-teamed against the OWASP Top 10 for LLM Applications and limited to the tools it needs.

Q.03Does the EU AI Act apply to us?

If your product serves people in the EU, parts of it may. We document each feature’s risk class and build the transparency it needs; your counsel confirms the legal position.

Q.04Do you work alongside our product and engineering teams?

Yes. The design system and front-end work are shared with engineering, and squads can join your sprint cadence.

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced