IT and security built for the pace of NewSpace.

A young space company moves fast: an ESA contract to deliver, a UK Space Agency grant to report against, a Series A round to close, and a small in house team running real time operations on expensive hardware. Each of those carries a security expectation that ordinary IT was never set up to meet. We run, secure, build, and prove the technology behind the work, so an ISO 27001 clause or a grant condition is never the thing that slows a launch. UK based, UKAS accredited, a Cyber Essentials certification body, and twenty minutes from the Harwell campus.

A satellite subassembly on a workbench in a clean room, with an engineer in protective dress
Verified
ISO 27001 & 9001UKAS accredited Cyber Essentials PlusCertified Cyber EssentialsCertification body CISSPIn house 5.0Google rating
Space Tech / 01 · The context

The contract, the grant, and the round all ask the same question now.

In space tech the security pressure does not arrive as an abstract policy. It arrives as a clause in an ESA contract that wants ISO 27001, a cyber hygiene condition attached to a UK Space Agency or Innovate UK grant, an investor diligence checklist in a Series A, and export control sitting over a stack full of US technology. For a ten to a hundred person company with one or two people holding IT and security together, that is a real workload. We know what each of those actually requires, and we build the posture and the evidence to satisfy it without pulling your engineers off the mission.

ESA supplier security ISO 27001 Cyber Essentials and Plus UKSA and Innovate UK grant terms ITAR and EAR aware Investor diligence
ESASupplier security attestationESA contracts routinely expect ISO 27001 and supplier side security evidence, with Cyber Essentials Plus often the practical stepping stone. We take you cleanly along that route.
UKSAGrant cyber conditionsUK Space Agency and Innovate UK grant terms increasingly carry cyber hygiene and reporting conditions. We put the controls and the reporting behind them so the condition is genuinely met.
A+Investor diligenceSeries A and later rounds now surface cyber and IT governance as a diligence item. We get the evidence in order before the data room opens, not after a question lands.
Space Tech / 02 · On your doorstep

Reading to Harwell is twenty minutes, not a video call.

Our base is in Reading, around twenty minutes from the Harwell campus and the cluster of space organisations around the UK Space Agency, the European Space Agency's UK presence, and RAL Space. That matters when a ground station rig needs a hands on look or a launch window is close and you want someone on site, not a ticket in a queue. The wider UK space sector is spread from Glasgow to Bristol and the Surrey heritage cluster, and modern IT and security mean we can support companies there securely and remotely. The genuinely local part, the part we can prove, is Harwell.

01HarwellTwenty minutes from our Reading base. On site when it counts.
02GlasgowLaunch and small satellite manufacturing, the Scottish cluster.
03BristolPropulsion and ground segment, the south west cluster.
04SurreySatellite heritage and the spinouts that came from it.
Space Tech / 03 · The pressures

What we hear from space companies.

The pressures are specific to a fast growing space business, and so is the cost of getting them wrong. These are the problems we are most often brought in to solve.

01Win the work

A clause you did not plan for

An ESA contract or a grant lands with an ISO 27001 expectation or a cyber condition attached, and the team has no certification and no time to build one from scratch. The deadline does not move to suit your IT. We close that gap on a timeline that fits the contract.

02Stretch further

One or two people holding it all

A small in house team is running real time operations on costly hardware and keeping the office working, with no capacity left for security. Things get missed, not through carelessness but through sheer load. We take the security weight off them and give the operation room to breathe.

03Protect the IP

Designs and data worth taking

Payload designs, mission data, control links, and the export controlled components in your stack are exactly what a capable adversary or an over broad collaborator could reach. The work has to be defended, segmented, and recoverable, and you need to be able to show that it is.

Space Tech / 04 · How we help

One accountable partner, across all four pillars.

We do not sell space a different product. We point the same four disciplines at the obligations and risks that are specific to it, and link you to the service that does the work. One partner, no gaps between suppliers for a failure to hide in.

01Run it

Managed IT and cloud for heavy compute

UK based support and UK hosted infrastructure for a team that runs simulation, image processing, and mission operations. We manage the cloud the heavy compute leans on and keep a demanding operation online, with MDR included as standard rather than sold as an upsell.

02Secure it

Cyber Essentials and certification

We are a Cyber Essentials certification body, so the route from a grant or contract that requires it to being certified runs through us directly, with no third party handover. Email and endpoint security sit behind it, hardening the everyday systems an attacker reaches for first.

03Build it

Software, secure by design

Bespoke software, integration, and applied AI built by the same team that runs and secures it, on UK hosted infrastructure with a full audit trail. The tooling that sits around your mission systems is the thing we build, and the thing we can stand behind and account for.

04Prove it

ISO 27001 and the evidence funders want

We are ISO 27001 certified ourselves and UKAS accredited, and we advise growing companies through the same standard, building the policies, controls, and audit trail an ESA assessor or an investor expects to inspect. The evidence is produced as you go, not reconstructed under pressure before a review.

We are loud about the work, never about the client. In space and defence especially, we describe the sector and the capability and keep the rest confidential. The detail that would identify a client, or help an attacker, stays behind closed doors.
Space Tech / 05 · Export control and residency

British owned, UK based, and clear on where the line sits.

US technology components are everywhere in a modern space stack, so ITAR, EAR, and UK export controls are part of normal compliance rather than an edge case. We build and run the access controls that keep restricted material away from unauthorised foreign access, with UK based staff and UK data residency throughout. The legal interpretation of what is controlled and who may see it stays with your export control advisers. The technology that enforces it is ours.

01StaffUK based support. No offshore centre touching your environment.
02DataUK cloud and UK backups. UK jurisdiction throughout.
03AccessNeed to know controls around restricted and export controlled material.
04ITAR and EARWe build the controls; export control law stays with your specialist advisers.
FAQ

Common questions

Our ESA contract asks for ISO 27001 and we have nothing in place. Where do we start?

With a clear read of what the contract actually requires, which is often ISO 27001 with Cyber Essentials Plus as a practical first step. We are ISO 27001 certified and UKAS accredited ourselves, and a Cyber Essentials certification body, so we can take you from a standing start through certification on a timeline built around the contract rather than a generic compliance plan. You get one team for both, not a handover between an advisor and an assessor.

A UK Space Agency or Innovate UK grant has cyber conditions attached. Can you handle that?

Yes. Grant terms in this sector increasingly carry cyber hygiene and reporting conditions, and the honest answer to what they need depends on the specific wording, which we will read with you. In most cases Cyber Essentials or Cyber Essentials Plus, with the controls and reporting genuinely in place behind it, satisfies the condition. We put that in place and keep producing the evidence the funder expects to see.

We are a small team raising a round. How do we get ready for the cyber side of diligence?

Series A and later rounds now routinely surface cyber and IT governance as a diligence item, and the time to get it in order is before the data room opens. We assess where you stand, close the obvious gaps, and assemble the policies, controls, and evidence an investor will ask for, so the question is answered with a document rather than a scramble. It is the same groundwork that supports ISO 27001, so the work does double duty.

We are right by Harwell. Are you actually local, or is that just a postcode?

Genuinely local. Our base is in Reading, around twenty minutes from the Harwell campus, so when a ground station rig or a test setup needs a hands on look, or a deadline is close and you want someone on site, that is straightforward for us. For space companies elsewhere in the UK, we work securely and remotely, the way modern IT and security already work, with on site visits arranged where they help. The Harwell proximity is the part that is genuinely local, and we are happy to prove it.

We handle ITAR or export controlled technology. Can you support us?

We can build and run the IT environment that keeps restricted material away from unauthorised foreign access, with UK based staff, UK data residency, and need to know access controls. ITAR, EAR, and UK export control compliance itself is primarily a legal and procedural matter, so we work alongside your export control advisers rather than replacing them. The technology controls are ours; the legal interpretation stays with the specialists.

The mission is demanding. So is the rigour.

Send us the clause in your contract, the conditions on your grant, or the diligence list from your investors. We will tell you plainly where you stand and what it takes to close the gap. We reply within one working day, and you will speak to an engineer, not a salesperson.

Reading, Berkshire, twenty minutes from Harwell  /  UKAS accredited, UK data residency  /  reply within one working day