What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
What we do  ·  AI Cybersecurity

How long were they inside?

For organisations that cannot absorb a public failure. We operate the capability, we publish the dwell time we actually achieved, and we do not write the opinion on how well we did it.

24/7 OPERATEDDWELL TIME PUBLISHED, NOT PROMISEDTESTED BY SOMEONE ELSE
Why this pillar exists

The path in is rarely the part that hurts.

Almost every entry vector on this page is survivable. What decides the outcome is how long the path stayed invisible afterwards, and whether a gate existed where it mattered.

01

Coverage is a placement problem

Each path is defeated at a different stage. Buying one tool and calling it coverage leaves the stages that tool does not sit at completely unwatched.

02

The attacker arrives as a person

A convincing request from a familiar voice does not look like an intrusion at any stage a technical control is watching.

03

Operational estates cannot be patched on demand

Availability outranks confidentiality, maintenance windows are quarterly, and a recommendation that ignores that is not a recommendation.

How the path runs

Pick the way in. Watch how far it gets.

Five entry points, five very different journeys. What matters is not the entry — it is how long the path stays invisible, and where a gate could have existed.

ENTRY

FOOTHOLD

CREDENTIAL

LATERAL

OBJECTIVE

ATTACK PATH— GATES USUALLY PRESENT
Select an entry point

Five stages, from the way in to the thing the attacker came for. What changes between paths is how long each stage stays invisible.

Detection is not a product decision, it is a placement decision. Every path above is defeated at a different stage, which is why buying one tool and calling it coverage does not work.

AI Cybersecurity

Three ways in.

Three engagements, sold independently and architected as one. Start with the question you can name.

The boundary

We run it. We do not audit what we run.

Three moves. Two of them are ours, and the one in the middle is deliberately somebody else’s.

MOVE 01 — OURS

We operate the capability

Detection engineering, triage, response and the reporting that goes with it. This is an operational service with a named duty owner, not an advisory engagement.

MOVE 02 — NOT OURS

Somebody else tests it

Effectiveness testing of a service Orvix runs is performed by a party that does not report to the team running it. Where a regulator or a board needs the result to carry weight, that party is not Orvix.

MOVE 03 — OURS

We close what the test opened

Detection gaps found by the test become engineering work with a date against them, and the re-test is run by the tester rather than by us.

The sharpest argument we make about other suppliers is that nobody should audit their own estate. It applies here first.
How we engage

Defined engagements with a deliverable at the end.

Every engagement in this pillar is scoped, fixed-fee and finishes with something you can put in front of somebody else.

ENGAGEMENT
Operated service, or scoped assessment
DELIVERABLE
Detection coverage and measured dwell time
DELIVERED
Regional delivery; partner-attached where licensing requires
INDICATIVE FEE
[FEE BAND — pending sign-off]
Questions we are asked

Before you ask us.

Is Orvix an MSSP?
We operate detection and response as a service, so for that service the honest answer is yes. What we do not do is form the assurance opinion on our own operation — effectiveness testing is performed by a party that does not report to the team running it.
Where do you deliver from?
Regionally, and in licensed markets through named partners under their own licence rather than through a claim of our own. Where in-country delivery or national staffing is mandated, that requirement is met by the partner and stated in the contract.
How is this different from the assurance pillar?
This pillar runs things. AI Assurance forms opinions about things. They are deliberately separated, including internally, because an opinion written by the operator is worth very little to a board and less to a regulator.

Start with the path you cannot see.

Thirty minutes. Pick the entry vector you are least confident you would catch, and we will walk it end to end.

Book a 30-minute scoping call

ORVIX · INDEPENDENT AI & TECHNOLOGY ASSURANCE · WE DISCLOSE EVERY COMMERCIAL RELATIONSHIP ON THE PAGE FOR THE SERVICE IT BELONGS TO. WHERE LICENSING IS REQUIRED, DELIVERY IS PERFORMED BY NAMED PARTNERS UNDER THEIR OWN LICENCE.