Articles · AI Security · DevSecOps · ISO 27001 · CRA · EU AI Act · NIS2

Field analyses and operational deep dives.

Articles on AI security, DevSecOps, ISO 27001 certification and EU regulation (CRA, AI Act, NIS2, DORA). Continuously updated, written from the field.

Compliance

SOC 2 Type II: the audit your enterprise clients require

SOC 2 Type II is the de facto standard for B2B SaaS selling to enterprise clients in the United States. Here is what it really is, what it covers (and doesn't), and how to obtain it in 9-12 months — alone or paired with ISO 27001.

· 9 min
AI Security

Securing RAG systems in production: ingestion, indexing, multi-tenancy

A RAG (Retrieval Augmented Generation) in production combines an LLM with an external knowledge base. Three specific attack families: index poisoning, cross-tenant leakage, indirect prompt injection via retrieved documents. Here is the defensive pipeline.

· 10 min
Compliance

EU Cyber Resilience Act roadmap: 09/2026 and 12/2027 milestones

The Cyber Resilience Act is probably the most impactful European regulation for software publishers in 2026-2027. Its scope is broad: any product with digital elements placed on the European market. Sanctions on arrival are severe: no CE marking = no market placement, including updates of products already deployed.

· 10 min
Compliance

EU AI Act high-risk systems: application August 2, 2026

On August 2, 2026, the EU AI Act enters its most structuring phase: high-risk system obligations defined in Annex III. Here is the operational roadmap for providers and deployers, with the 7 mandatory technical pillars in production.

· 11 min
Compliance

NIS2 compliance for French and European companies in 2026

The NIS2 Directive (EU 2022/2555) has been transposed in France in 2025. Companies in 18 strategic sectors must achieve compliance before October 2026. Here is the operational guide for European SMBs and scale-ups.

· 10 min
Compliance

ISO 27001 for B2B SaaS: 12-month roadmap

For a B2B SaaS targeting enterprise clients in Europe, ISO 27001 has become a de facto entry requirement. Here is the realistic 12-month roadmap, the budget envelope, and the articulation with SOC 2 Type II for those who also want to address the US market.

· 11 min
DevSecOps

DevSecOps in CI/CD: quality gates that actually block

DevSecOps in CI/CD = automated security at every commit/build/release, without blocking the product roadmap. Here is the operational stack and the four blocking quality gates that should never be optional in 2026.

· 9 min