IV
Capability catalogue
Everything Ordfall builds, secures and operates.
Three connected disciplines — software engineering, cybersecurity, and AI, data and cloud — with controls built in from the design stage.
Filter the atlas by domain
Use the arrow keys to move through the domains.
Software engineering
From product strategy to production reliability, Ordfall builds software ready for scale, control and long-term value.
16 capabilities
- 001
Product discovery and technical strategy
Frames the problem, the scope and the technical choice before the first line of code.
Product & architecture
- 002
Solution and domain architecture
Separates domains, contracts and boundaries of responsibility inside the system.
Product & architecture
- 003
APIs and integrations
Versioned interfaces between owned and third-party systems, on an explicit contract.
Product & architecture
- 004
Architecture decision records
Every structural decision written down, dated and open to review.
Product & architecture
- 005
Legacy assessment and decomposition
Reads the existing system and proposes the cut that lets it evolve without stopping.
Modernisation
- 006
Cloud-native migration
Moves workloads to cloud with identity, network and cost designed in the same move.
Modernisation
- 007
Performance and cost optimisation
Profiles the critical path and attacks what actually drives latency and spend.
Modernisation
- 008
Technical debt reduction
Treats debt as a planned item, with a priority and a date — not as a complaint.
Modernisation
- 009
Internal platforms and developer experience
Paved paths so the team ships without rebuilding the basics every time.
Platforms & automation
- 010
Workflow automation
Takes the manual step out of the critical process and leaves a record of each run.
Platforms & automation
- 011
Data and event integration
Streams, queues and events with schema, ordering and reprocessing planned for.
Platforms & automation
- 012
Infrastructure as code
The environment described in a repository: reviewable, reproducible, reversible.
Platforms & automation
- 013
Test strategy and automation
Defines what is tested, at which level, and what stops a release from shipping.
Quality & reliability
- 014
Observability and SRE practice
Metrics, logs and traces designed to answer the question asked at 3 a.m.
Quality & reliability
- 015
Resilience and recovery
Failure designed for: controlled degradation and a rehearsed way back.
Quality & reliability
- 016
Release engineering
Frequent delivery, with a reversal available at any point on the path.
Quality & reliability
Cybersecurity
Ordfall connects executive risk decisions to technical controls and disciplined execution.
32 capabilities
- 017
vCISO
Contracted security leadership, with a defined agenda, priorities and reporting.
Strategy & governance
- 018
Risk quantification
Turns technical exposure into financial and operational impact a board can weigh.
Strategy & governance
- 019
Roadmap and board reporting
One programme view leadership can actually read and decide on.
Strategy & governance
- 020
Policy and operating model
A written rule, a named owner, and the routine that keeps both alive.
Strategy & governance
- 021
Secure SDLC
Controls inside the development flow, not in an audit that arrives later.
Application security
- 022
Threat modelling
Maps how the system would be attacked while it is still a drawing.
Application security
- 023
Code review, SAST and DAST
Human and automated analysis in one pipeline, with the noise kept under control.
Application security
- 024
Dependencies and APIs
The third-party chain inventoried and the public surface described, not assumed.
Application security
- 025
Cloud posture, containers and Kubernetes
Configuration, isolation and privilege reviewed on the plane the workload runs on.
Cloud & platform
- 026
Secrets and infrastructure as code
Credentials out of the repository; an environment change goes through review.
Cloud & platform
- 027
Segmentation and logging
Network boundaries designed, and telemetry enough to reconstruct what happened.
Cloud & platform
- 028
Platform resilience
Zones, replicas and limits set before the first spike, not during it.
Cloud & platform
- 029
IAM architecture
Who is who, in which system, with which permission — designed, not inherited.
Identity & access
- 030
Privileged access and MFA
A separate administrative path, with a second factor and a trail of what was done.
Identity & access
- 031
User lifecycle and reviews
Joining, changing role and leaving treated as security events.
Identity & access
- 032
Zero trust
Trust verified on every request, not granted by position on the network.
Identity & access
- 033
Attack surface
An inventory of what is exposed — including what nobody remembered publishing.
Exposure & testing
- 034
Vulnerability management
From discovery to fix, ordered by real impact rather than nominal severity.
Exposure & testing
- 035
Authorised penetration testing
Offensive testing with documented scope, authorisation and evidence.
Exposure & testing
- 036
Authorised adversarial exercises
Adversary simulation to test detection and response, not to score a point.
Exposure & testing
- 037
Use cases and alerting
Detection written from what matters to that operation, not from a stock catalogue.
Detection & response
- 038
Playbooks and simulations
Decisions rehearsed before the incident so they are not improvised during it.
Detection & response
- 039
Incident coordination
Command, communication and record-keeping while the event is still running.
Detection & response
- 040
Recovery
Back to operation with the cause understood, access reissued and the lesson recorded.
Detection & response
- 041
Supplier due diligence
Assesses who joins the chain before the contract is signed.
Third-party risk
- 042
Contracts
Security, notification and evidence clauses written into the agreement.
Third-party risk
- 043
Critical dependencies
Identifies who the operation truly depends on — and what to do without them.
Third-party risk
- 044
Continuous review
Suppliers reassessed through the relationship, not only at onboarding.
Third-party risk
- 045
Evidence and controls for ISO 27001 and SOC 2
Prepares controls, owners and evidence in the format an auditor asks for.
Compliance readiness
- 046
PCI DSS
Cardholder data scope bounded and the standard's controls mapped to it.
Compliance readiness
- 047
LGPD
Processing, legal basis and data-subject rights reflected in the system, not only in the policy.
Compliance readiness
- 048
Client requirements
Answers the buyer's security questionnaire with evidence that exists.
Compliance readiness
AI, data & cloud
Ordfall accelerates AI and cloud adoption without losing visibility over identities, data, models, suppliers or decisions.
15 capabilities
AI governance delivery
A practical control model covering approved use cases, data boundaries, owners, evaluation criteria, incidents and evidence for executive oversight.
- 049
Secure architecture for copilots, agents and RAG
Designs what the model may read, what it may call and what it may change.
AI systems
- 050
Model and prompt threats
Injection, exfiltration and misuse treated as attack surface.
AI systems
- 051
Access control and human approvals
A sensitive action requires an identity and a recorded human approval.
AI systems
- 052
Evaluation, monitoring and audit trails
System behaviour measured before and after it reaches production.
AI systems
- 053
Third-party model and data risk
Knows where the model and the data come from, and what the contract allows.
AI systems
- 054
Data classification and ownership
Every dataset with a declared level and an owner who has a name.
Data protection
- 055
Encryption and key management
Keys with a lifecycle, custody and rotation defined from the start.
Data protection
- 056
Retention, minimisation and lineage
Keeps what is needed, for the stated period, with the origin traceable.
Data protection
- 057
DLP and sensitive data discovery
Finds sensitive data out of place and closes the route it leaves by.
Data protection
- 058
Privacy-by-design and LGPD support
Privacy decided in the design, not appended at the end of the project.
Data protection
- 059
Landing zones and guardrails
The account is created with its limits, network and identity already defined.
Cloud platforms
- 060
Identity-centred architecture
Identity becomes the perimeter; the network stops being the only defence.
Cloud platforms
- 061
Cloud and container posture
Configuration drift detected and corrected as routine, not as a project.
Cloud platforms
- 062
Resilience, backup and recovery
Copy tested, restore rehearsed, dependency mapped.
Cloud platforms
- 063
Security decisions with FinOps
Cost and control argued inside the same architecture decision.
Cloud platforms
Outcomes & measurement
Reliable progress for executives and technical teams.
Metrics are defined per engagement. The goal is to show how engineering and security change risk, speed, resilience and enterprise value.
Risk
- Critical exposure reduced
- Time to remediate
- Identity coverage
- Third-party risk closed
Resilience
- Time to detect and contain
- Recovery readiness
- Backup validation
- Critical availability
Engineering
- Release frequency
- Change failure rate
- Technical debt removed
- Automation coverage
Value
- Enterprise sales unblocked
- Audit and due diligence readiness
- Cloud cost efficiency
- Portfolio visibility
The metric set is agreed at the start of the engagement and reviewed in the executive cadence.
System index
Every capability above is executed inside one of these five systems.
- 01SIGNALFinds the risks and obstacles that actually matter.Detects
- 02GUARDRuns risk, governance and evolution as a managed programme.Stabilises
- 03FORGEBuilds and modernises software, platforms, data and AI.Builds
- 04PORTFOLIOCreates a common operating model across multiple companies.Coordinates
- 05COMMANDUnifies evidence, exposure, remediation and the executive view.Unifies