Skip to content

IV

Capability catalogue

Everything Ordfall builds, secures and operates.

Three connected disciplines — software engineering, cybersecurity, and AI, data and cloud — with controls built in from the design stage.

Filter the atlas by domain

Use the arrow keys to move through the domains.

63 of 63 capabilities listed — All domains.

01

Software engineering

From product strategy to production reliability, Ordfall builds software ready for scale, control and long-term value.

16 capabilities

  • 001

    Product discovery and technical strategy

    Frames the problem, the scope and the technical choice before the first line of code.

    Product & architecture

  • 002

    Solution and domain architecture

    Separates domains, contracts and boundaries of responsibility inside the system.

    Product & architecture

  • 003

    APIs and integrations

    Versioned interfaces between owned and third-party systems, on an explicit contract.

    Product & architecture

  • 004

    Architecture decision records

    Every structural decision written down, dated and open to review.

    Product & architecture

  • 005

    Legacy assessment and decomposition

    Reads the existing system and proposes the cut that lets it evolve without stopping.

    Modernisation

  • 006

    Cloud-native migration

    Moves workloads to cloud with identity, network and cost designed in the same move.

    Modernisation

  • 007

    Performance and cost optimisation

    Profiles the critical path and attacks what actually drives latency and spend.

    Modernisation

  • 008

    Technical debt reduction

    Treats debt as a planned item, with a priority and a date — not as a complaint.

    Modernisation

  • 009

    Internal platforms and developer experience

    Paved paths so the team ships without rebuilding the basics every time.

    Platforms & automation

  • 010

    Workflow automation

    Takes the manual step out of the critical process and leaves a record of each run.

    Platforms & automation

  • 011

    Data and event integration

    Streams, queues and events with schema, ordering and reprocessing planned for.

    Platforms & automation

  • 012

    Infrastructure as code

    The environment described in a repository: reviewable, reproducible, reversible.

    Platforms & automation

  • 013

    Test strategy and automation

    Defines what is tested, at which level, and what stops a release from shipping.

    Quality & reliability

  • 014

    Observability and SRE practice

    Metrics, logs and traces designed to answer the question asked at 3 a.m.

    Quality & reliability

  • 015

    Resilience and recovery

    Failure designed for: controlled degradation and a rehearsed way back.

    Quality & reliability

  • 016

    Release engineering

    Frequent delivery, with a reversal available at any point on the path.

    Quality & reliability

02

Cybersecurity

Ordfall connects executive risk decisions to technical controls and disciplined execution.

32 capabilities

  • 017

    vCISO

    Contracted security leadership, with a defined agenda, priorities and reporting.

    Strategy & governance

  • 018

    Risk quantification

    Turns technical exposure into financial and operational impact a board can weigh.

    Strategy & governance

  • 019

    Roadmap and board reporting

    One programme view leadership can actually read and decide on.

    Strategy & governance

  • 020

    Policy and operating model

    A written rule, a named owner, and the routine that keeps both alive.

    Strategy & governance

  • 021

    Secure SDLC

    Controls inside the development flow, not in an audit that arrives later.

    Application security

  • 022

    Threat modelling

    Maps how the system would be attacked while it is still a drawing.

    Application security

  • 023

    Code review, SAST and DAST

    Human and automated analysis in one pipeline, with the noise kept under control.

    Application security

  • 024

    Dependencies and APIs

    The third-party chain inventoried and the public surface described, not assumed.

    Application security

  • 025

    Cloud posture, containers and Kubernetes

    Configuration, isolation and privilege reviewed on the plane the workload runs on.

    Cloud & platform

  • 026

    Secrets and infrastructure as code

    Credentials out of the repository; an environment change goes through review.

    Cloud & platform

  • 027

    Segmentation and logging

    Network boundaries designed, and telemetry enough to reconstruct what happened.

    Cloud & platform

  • 028

    Platform resilience

    Zones, replicas and limits set before the first spike, not during it.

    Cloud & platform

  • 029

    IAM architecture

    Who is who, in which system, with which permission — designed, not inherited.

    Identity & access

  • 030

    Privileged access and MFA

    A separate administrative path, with a second factor and a trail of what was done.

    Identity & access

  • 031

    User lifecycle and reviews

    Joining, changing role and leaving treated as security events.

    Identity & access

  • 032

    Zero trust

    Trust verified on every request, not granted by position on the network.

    Identity & access

  • 033

    Attack surface

    An inventory of what is exposed — including what nobody remembered publishing.

    Exposure & testing

  • 034

    Vulnerability management

    From discovery to fix, ordered by real impact rather than nominal severity.

    Exposure & testing

  • 035

    Authorised penetration testing

    Offensive testing with documented scope, authorisation and evidence.

    Exposure & testing

  • 036

    Authorised adversarial exercises

    Adversary simulation to test detection and response, not to score a point.

    Exposure & testing

  • 037

    Use cases and alerting

    Detection written from what matters to that operation, not from a stock catalogue.

    Detection & response

  • 038

    Playbooks and simulations

    Decisions rehearsed before the incident so they are not improvised during it.

    Detection & response

  • 039

    Incident coordination

    Command, communication and record-keeping while the event is still running.

    Detection & response

  • 040

    Recovery

    Back to operation with the cause understood, access reissued and the lesson recorded.

    Detection & response

  • 041

    Supplier due diligence

    Assesses who joins the chain before the contract is signed.

    Third-party risk

  • 042

    Contracts

    Security, notification and evidence clauses written into the agreement.

    Third-party risk

  • 043

    Critical dependencies

    Identifies who the operation truly depends on — and what to do without them.

    Third-party risk

  • 044

    Continuous review

    Suppliers reassessed through the relationship, not only at onboarding.

    Third-party risk

  • 045

    Evidence and controls for ISO 27001 and SOC 2

    Prepares controls, owners and evidence in the format an auditor asks for.

    Compliance readiness

  • 046

    PCI DSS

    Cardholder data scope bounded and the standard's controls mapped to it.

    Compliance readiness

  • 047

    LGPD

    Processing, legal basis and data-subject rights reflected in the system, not only in the policy.

    Compliance readiness

  • 048

    Client requirements

    Answers the buyer's security questionnaire with evidence that exists.

    Compliance readiness

03

AI, data & cloud

Ordfall accelerates AI and cloud adoption without losing visibility over identities, data, models, suppliers or decisions.

15 capabilities

AI governance delivery

A practical control model covering approved use cases, data boundaries, owners, evaluation criteria, incidents and evidence for executive oversight.

  • 049

    Secure architecture for copilots, agents and RAG

    Designs what the model may read, what it may call and what it may change.

    AI systems

  • 050

    Model and prompt threats

    Injection, exfiltration and misuse treated as attack surface.

    AI systems

  • 051

    Access control and human approvals

    A sensitive action requires an identity and a recorded human approval.

    AI systems

  • 052

    Evaluation, monitoring and audit trails

    System behaviour measured before and after it reaches production.

    AI systems

  • 053

    Third-party model and data risk

    Knows where the model and the data come from, and what the contract allows.

    AI systems

  • 054

    Data classification and ownership

    Every dataset with a declared level and an owner who has a name.

    Data protection

  • 055

    Encryption and key management

    Keys with a lifecycle, custody and rotation defined from the start.

    Data protection

  • 056

    Retention, minimisation and lineage

    Keeps what is needed, for the stated period, with the origin traceable.

    Data protection

  • 057

    DLP and sensitive data discovery

    Finds sensitive data out of place and closes the route it leaves by.

    Data protection

  • 058

    Privacy-by-design and LGPD support

    Privacy decided in the design, not appended at the end of the project.

    Data protection

  • 059

    Landing zones and guardrails

    The account is created with its limits, network and identity already defined.

    Cloud platforms

  • 060

    Identity-centred architecture

    Identity becomes the perimeter; the network stops being the only defence.

    Cloud platforms

  • 061

    Cloud and container posture

    Configuration drift detected and corrected as routine, not as a project.

    Cloud platforms

  • 062

    Resilience, backup and recovery

    Copy tested, restore rehearsed, dependency mapped.

    Cloud platforms

  • 063

    Security decisions with FinOps

    Cost and control argued inside the same architecture decision.

    Cloud platforms

04

Outcomes & measurement

Reliable progress for executives and technical teams.

Metrics are defined per engagement. The goal is to show how engineering and security change risk, speed, resilience and enterprise value.

01

Risk

  • Critical exposure reduced
  • Time to remediate
  • Identity coverage
  • Third-party risk closed
02

Resilience

  • Time to detect and contain
  • Recovery readiness
  • Backup validation
  • Critical availability
03

Engineering

  • Release frequency
  • Change failure rate
  • Technical debt removed
  • Automation coverage
04

Value

  • Enterprise sales unblocked
  • Audit and due diligence readiness
  • Cloud cost efficiency
  • Portfolio visibility

The metric set is agreed at the start of the engagement and reviewed in the executive cadence.

05

System index

Every capability above is executed inside one of these five systems.

See the five systems in detail