About
A practitioner, not a panel of them.
You work directly with the advisor who writes your documents. No junior hand-off, no template mill.
Advisor
Nabiha Sofia Herradi
LL.B · CISM · CISACIPP/E · CIPP/US
CMMC-CCP
Fifteen years across governance, risk, compliance, privacy, cybersecurity, and regulatory readiness — now focused entirely on how organizations adopt AI without losing control of it.
The work sits where legal obligation meets operational reality. A policy that no one can follow does not reduce risk; a control with no owner does not survive its first audit. Every engagement is built backwards from the evidence someone will eventually ask you to produce.
How we work
- Fixed scope, fixed price. You approve the deliverables and the dates before work starts.
- Documents you own. Editable files, no locked platforms, no per-seat licensing.
- Plain language. Written so a business owner can act on it without a translator.
- Framework-traceable. Every recommendation maps to NIST AI RMF, ISO/IEC 42001, or a specific EU AI Act article.
What we don’t do
We do not provide legal advice, and we do not certify anyone against ISO/IEC 42001 — certification comes from an accredited body. We prepare you for it.
Defense-sector work involving Controlled Unclassified Information and CMMC is delivered separately through cyberdsc.com.
