The tools we operate ourselves.
Advising a company on security without giving it the means to act leaves it with the hardest part. These five platforms are built and operated by Luxgap, hosted in Luxembourg, and used by our own teams before our clients get them.
Sovereign managed SOC, 24/7
Your whole perimeter watched continuously: cloud, servers, endpoints, dark web, IoT and industrial systems. Detection targets the first hour, and every qualified incident comes with the regulatory notification that goes with it.
- Continuous monitoring of cloud, servers, endpoints and the dark web.
- Covers IoT and industrial environments, too often left out.
- Detection targeted within the first hour, then analyst qualification.
- Notifications ready for NIS 2, DORA and the CNPD — the regulatory clock is short, the file cannot be built afterwards.
Business mail, hosted and encrypted in Luxembourg
Mail hosted, encrypted and operated in Luxembourg, with as many addresses as you need — no per-user licence. And, for sensitive roles, mailboxes that not even your administrator can open.
- As many addresses and aliases as needed, with no per-seat billing.
- Hosted and operated in Luxembourg: data never leaves the EU.
- End-to-end encrypted mailboxes for management, HR and legal — the administrator has no access either.
- A concrete alternative when hyperscaler dependency raises a sovereignty or per-seat cost problem.
Continuous code monitoring, from €0.01 per line
Code written fast — by your teams or by an AI — still has to be held to a standard. The platform continuously monitors what gets written: code security, automated testing, penetration testing, and the evidence a regulator will ask for.
- Framed vibe coding: what an AI writes is reviewed and tested like the rest.
- Continuous code security analysis and penetration testing, not once a year.
- Automated tests maintained over time, not only at delivery.
- Usable evidence for NIS 2, GDPR and the AI Act.
- Priced per line of code, from €0.01 per line per month.
Build, maintain and activate your continuity plan
A console that supports an SME through the whole continuity cycle: from company profile and impact analysis to crisis mode, on the day it actually has to be used.
- Impact analysis (BIA) imported from Excel, then risk and strategy derivation.
- AI-assisted drafting of the sections, based on your company profile.
- Emergency playbooks ready to follow, rather than a binder nobody reopens.
- Real-time crisis mode with a timestamped log — the trail an auditor will ask for.
- PDF and Excel exports, sovereign EU hosting.
Governance, risk and compliance in one place
A GRC platform that holds together what usually lives scattered across spreadsheets: risk, compliance frameworks, third parties, incidents and resilience — with a sovereign AI copilot.
- Enterprise, cyber and operational risk in a single register.
- ISO 27001, NIS 2, DORA, AI Act and GDPR frameworks tracked side by side.
- Third-party and incident management, tied to risk rather than kept apart.
- Resilience: impact analysis, continuity plan and recovery plan.
- Evidence attached to requirements — exactly what is missing on inspection day.
Want to talk it through?
These platforms combine with our DPO and CISO mandates: the same teams operate them. Tell us what you need to cover and we will tell you what applies — and what does not.