Certifications and partners

    Two lists, deliberately kept apart: the vendors we hold an actual agreement with, and the technologies we are good at. Most firms merge them. The merge is easy to check and expensive when a client does.

    Why there are two lists

    Partner logo walls are the least trusted artefact on a consultancy website, because everybody knows the rule: a logo can mean a signed agreement with a tier and obligations, or it can mean somebody on the team once used the product. There is no way to tell from the wall, so buyers discount all of it.

    So we separate them. Below, first, the vendors we hold an agreement with. Then, separately, the technologies we work with and are good at, where no partnership exists and we are not going to imply one. If a client asks us to confirm a relationship in writing during due diligence, both lists survive the question — which is the only test that matters.

    Certifications held in the team

    Personal credentials, earned and maintained by individuals — the only way certifications of this kind exist. We list what is held, not what we have read about.

    • ISO/IEC 42001 Senior Lead Implementer
    • ISO/IEC 27001 Lead Implementer and Lead Auditor
    • ISO/IEC 27005 Risk Manager
    • EBIOS Risk Manager
    • ISO/IEC 20000 Lead Implementer
    • Microsoft data and business intelligence certifications
    • PECB Certified Partner, with an accredited trainer in the team

    Frameworks we work in

    These are not certifications and we do not present them as any. They are bodies of practice our consultants work in daily, and the distinction between holding a credential and knowing a framework is one we would rather draw ourselves than have a client draw for us.

    • COBIT
    • TOGAF
    • ITIL
    • Zachman
    • NIST AI Risk Management Framework

    For the organisational certification position, see the trust page.

    Accreditation

    PECB Certified Partner and authorised reseller. PECB personnel certifications are issued under ISO/IEC 17024, the international standard for bodies certifying persons. Our accredited tracks are ISO/IEC 27001, ISO/IEC 42001, ISO/IEC 38500 and ISO/IEC 20000. Course participants who complete a certificate programme hold a certificate; they are not thereby certified, licensed, accredited or registered to practise an occupation. Certification follows successful examination and verification of professional experience against PECB's published requirements.

    Partner agreements

    Netherlands — GSNA Solutions B.V.

    • Guardz — managed security partnership, under which we deliver SentinelOne
    • Axur — digital risk and exposure monitoring
    • Microsoft
    • HPE
    • Lenovo
    • PECB — Certified Partner and authorised reseller

    SentinelOne is delivered through our Guardz partnership rather than under a direct agreement, and we describe it that way deliberately. It is the kind of distinction that gets checked during vendor due diligence.

    Morocco — GSNA Solutions Africa

    • Sophos
    • Fortinet
    • Oracle Cloud
    • ACS

    No commercial relationship

    Technologies we work with — no partnership implied

    We build with these and we are good at them. We have no partnership, reseller agreement or commercial relationship with any of them, and we will not imply one. That independence is also useful to you: when we recommend a model or a platform for your workload, there is no margin riding on the answer.

    • OpenAI
    • Whisper
    • Google Gemini
    • Gemma
    • Claude
    • Kimi
    • DeepSeek
    • Mistral
    • Ollama

    The list moves. Model capability and pricing change every few months, and an application welded to one provider carries a repricing risk nobody agreed to — which is why we design the systems we build so the model can be changed, and tell you what changing it would cost.

    Questions buyers ask

    Are you a partner of OpenAI, Google or Anthropic?

    No. We work with their models, we are good at it, and we hold no agreement with any of them. Anyone claiming otherwise on a slide is describing an API key.

    Why does the SentinelOne relationship run through Guardz?

    Because that is how it is structured, and we would rather explain it here than have it surface in a due diligence questionnaire. The delivery and the support are ours; the vendor relationship sits under the Guardz agreement.

    Do your partnerships affect what you recommend?

    For security tooling, we hold agreements and we tell you which, so you can weigh the advice accordingly. For AI platforms we hold none, so the recommendation follows the workload, the cost envelope and your data constraints. Being explicit about where we do and do not have an interest is more useful than claiming to have none.

    Can you supply hardware?

    Through the HPE and Lenovo agreements in the Netherlands, yes. It is not the centre of what we do, and where a specialist reseller would serve you better we will say so.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.