AI & Cloud Development Consultancy
AI and cloud development for teams shipping real systems.
Independent consultancy building LLM applications, AI agents and MCP integrations, and the Azure platforms they run on.
Deliverable-led engagements for teams that take AI seriously.
Azure
APIM, Functions, Entra ID
LLM apps & agents
RAG, evals, guardrails
MCP integration
Servers, clients, governance
Terraform / IaC
Repeatable environments
Hands-on engineering
The person you talk to is the person who builds it
Azure-native
Integration, APIM and platform work on Microsoft cloud
Shipped AI products
Built and operates the Sovara AI-governance family
UK-based
Direct access, UK company, no offshore handoffs
Services
LLM applications, AI agents and MCP integrations that make it to production - RAG, agent architectures, evaluation and guardrails.
AI Development →Cloud DevelopmentAzure-native integration and platform engineering - API Management, Functions, Entra ID, Terraform and the pipelines around them.
Cloud Development →AI Governance & SecurityControls for AI adoption, from usage policy to audit evidence - built on experience shipping AI-governance products.
AI Governance & Security →Web & Product DevelopmentFull-stack product engineering for web platforms - Next.js, .NET, headless CMS and the API layer underneath.
Web & Product Development →Latest posts
All posts →Privilege at the Tool Call: AI Agents Inside Law and IP Firms
Law and IP firms handle information where confidentiality is not a compliance box. It is the product. An AI agent with unrestricted tool access can waive legal professional privilege by surfacing protected material in the wrong context.
No Journal Postings at 3am: Time-Windowed Access as a Control
An allowlist controls which tools an AI agent can call. A time window controls when. A legitimate tool call at the wrong time is not legitimate at all.
Deny by Default: How AI Agents Quietly Accumulate Excessive Privilege
MCP servers expose every tool equally. The finance agent that posts journals can also call delete_account. Human users go through access reviews. AI agents get full tool access on day one.
Engagements
How engagements work
Every engagement is deliverable-led: a scoped piece of work with a defined outcome, not an open-ended retainer. Typical shapes are a short discovery or review, a fixed-scope build, or hands-on delivery alongside your team. You work directly with the engineer doing the work.
Talk about an engagement →Open Source
APIM MCP Reference Architecture
Production-ready Terraform modules to deploy Entra ID governed Model Context Protocol servers behind Azure API Management.
View on GitHub →