Radar is a quick scan that only looks at what is publicly visible (90 seconds). The Assessment (Diagnóstico) is the full audit: external, internal, processes and people, in 7 days. Contact us for a tailored quote.
Not at all. The Assessment stands on its own: you walk away with a plan you can execute with whoever you like. Ongoing support (Acompañamiento) is optional, with no lock-in, and only if it makes sense.
No. Every service has a fixed price, agreed in writing before we start, defined in the initial proposal. No surprises, no extras you were not told about. The price covers everything listed in the proposal. VAT not included.
Yes. Services can be paid in several instalments as we agree. We normally offer 2 instalments at no extra charge. Contact us for tailored options.
7 business days from kick-off. If a delay is on our side, we tell you in advance and give you the new date; you don't find out on the last day.
Remotely by default. If you need us on site (regulated sectors, industrial infrastructure), we travel anywhere in Spain with a travel surcharge.
Encrypted in transit and at rest. Access limited to the assigned team. Automatically deleted 90 days after delivery. We work to ISO 27001 and sign an NDA before we start.
No. The team that audits you is ours. For tooling we use audited software (Nessus, Burp, etc.) on our own infrastructure in the EU.
NIS2 (the EU cybersecurity directive, 2022/2555) is aimed at medium and large companies in essential and important sectors: energy, transport, healthcare, digital, food, critical manufacturing and more. Spain has not yet passed the law transposing it, so today there is no direct legal obligation. What is already happening is the indirect effect: if you supply a company that is preparing for NIS2, your customer will ask you for supply-chain security measures, usually in the form of a security questionnaire. In practice, many Spanish SMEs will need to demonstrate basic cybersecurity to keep selling to their large customers, with or without the law.
ENS (Spain's National Security Framework, Royal Decree 311/2022) is the mandatory security framework for Spanish public administrations and for the private companies that provide them with services or technology solutions. If your SME wants to work with town councils, provincial councils or any public body, it is increasingly common to be asked for an ENS certification at Basic or Medium level. We help you assess which level you need and achieve it.
Yes. The Kit Digital programme (Spain's public digitalisation grants, EU funds managed by Red.es) includes vouchers for cybersecurity, and Kit Consulting subsidises specialist advisory services for SMEs with 10 to 249 employees. INCIBE (Spain's national cybersecurity institute) also offers free resources and a helpline (017). We point you to the grants that fit your case at no cost.
A small team based in Tarragona with fifteen years inside the marketing and SaaS data stack (analytics, consent, tags, CDPs, processors), tired of compliance reports nobody understood or acted on. We work with clients across Spain, remotely and on site. We will introduce the team by name and background as soon as the company is incorporated.
We do not yet hold certifications of our own to show. We work to ISO 27001, ENS (Spain’s National Security Framework) and GDPR, and we will publish each certification here with its number or registry link as soon as it exists. We would rather tell you that than show a badge we cannot back up.
No. Automations are designed so anyone on your team can use them. We give you a simple user guide and training. If anything is unclear, support is included.
Automations have defined limits and human validation checkpoints where needed. Critical tasks are always supervised. Maintenance also includes ongoing tuning to keep improving accuracy.
Between 10 and 20 business days for standard automations. More complex projects can take 4-6 weeks. We always give you a fixed timeline before we start.
Maintenance has a 12-month minimum term to guarantee stability. After that period, you can cancel with 30 days' notice.
Absolutely. We use enterprise-grade models with privacy guarantees. Your data is not used to train public models. We sign an NDA and comply with GDPR. Optionally, we can use private on-premise models.
Can't find what you're looking for?
[email protected] · reply within 4 business hours