A security firm built by practitioners.
Grilli Security is built by senior practitioners — not resellers or generalist consultants. We work with organisations that need measurable security outcomes: reduced exposure, faster detection, audit success, and the capability to respond when something goes wrong.
WHO WE ARE
Three things make a partner worth paying for.
Practitioners, not generalists
- Every engagement is staffed by specialists in the relevant discipline — red team operators who have run full-chain campaigns, DFIR analysts who have handled major breaches, and engineers who build secure systems for a living.
- No account managers in the room. The person who scopes your engagement is the person who delivers it.
Outcomes, not reports
- We measure success by what changes: reduced MTTD/MTTR, fewer critical findings, clean audit outcomes, and post-breach environments that hold.
- Deliverables identify what to fix and how to fix it; validation or retesting is included only where the service and signed SoW provide for it.
Worldwide 24/7
- Continuous coverage for SOC, incident response, and emergency engagements — every hour of every day.
- Worldwide coverage with a European-centric delivery model and senior on-call escalation for off-hours emergencies.
- Website records and Grilli-hosted engagement data use EU storage by default, but storage location does not imply EU-only access: authorised personnel may work from Estonia or Argentina. EU-only access is available when agreed before data is shared.
HOW WE WORK
No ambiguity. No undisclosed subcontracting.
Our engagement model is designed to protect clients, eliminate ambiguity, and produce work that holds up to external scrutiny — legal, regulatory, and technical.
Before work begins
- Mutual NDA available before sensitive information is shared and required where the engagement terms or SoW call for it
- Defined scope, objectives, and deliverables agreed in writing
- IP ownership, transfer triggers, and any background-IP licences defined in the signed MSA and SoW
- Rules of engagement and authorisation chain documented for technical engagements
- Data processing agreement in place where personal data is in scope
During engagements
- Interim findings issued for critical and high severity issues — no waiting for the final report
- Encrypted, out-of-band communication channels for sensitive engagements
- Access limited to named personnel on a least-privilege, need-to-know basis
- All activity logged with analyst identity and timestamp for auditability
- No undisclosed subcontracting — specialists disclosed and client-approved in advance
At engagement close
- All access revoked on the day the engagement ends
- Evidence, exploits, and sensitive artefacts returned or securely destroyed with certificate
- Retest availability: validation that remediation was effective, not just attempted
- Retention period defined per contract; no open-ended storage of client data
WHO WE WORK WITH
Sectors and engagement models.
Industries we serve
- Payments & Finance — PCI DSS 4.0 compliance, cardholder data environment testing, and fraud-path red teaming
- Health & Life Sciences — HIPAA breach preparedness, medical device security, and clinical system hardening
- SaaS & Cloud — multi-tenant architecture review, supply chain security, and continuous compliance programmes
- Retail & eCommerce — PCI DSS scope reduction, API security, and fraud-vector penetration testing
- Public Sector & Critical Infrastructure — NIS2/DORA compliance, ICS/OT security assessment, TIBER-EU-aligned red teaming
- Defence & Aerospace — high-assurance engineering, Common Criteria readiness, FIPS 140-3 preparation, DO-178C alignment
Engagement types
- Project-based — defined scope, timeline, and deliverables for assessments, audits, and research campaigns
- Retainer — guaranteed response capacity with pre-agreed SLAs; recommended for SOC, DFIR, and ongoing advisory
- Embedded engineering — our practitioners integrated into your team for the engagement duration
- Advisory — design review, threat modelling, and strategic guidance without full implementation access
- Emergency — 24/7/365 incident response available on retainer or as an ad-hoc engagement with SLA commitments
BUYER DILIGENCE
Verify the entity, team, and evidence before signature.
Our public corporate identity is sourced from the Estonian e-Business Register. Email legal@grillisecurity.com with subject PROCUREMENT REVIEW for onboarding documents, or hello@grillisecurity.com for the wider diligence set.
Contracting entity
- Grilli OÜ is the legal entity behind Grilli Security: an Estonian private limited company registered under code 17417589.
- Registered office: Järvevana tee 9, 11314 Tallinn, Estonia.
- VAT status: not VAT-registered, as shown in the current Estonian e-Business Register record.
- Our operating locations are Tallinn, Estonia, and Buenos Aires, Argentina. Access location and any EU-only restriction are recorded before client data is shared.
Know who will do the work
- During scoping we provide the proposed named engagement lead and delivery roster, with each person’s role, seniority, delivery responsibility, and working location.
- Credential and certification evidence is available for buyer verification under NDA; a title or standard named on this website is not a substitute for that evidence.
- Conflicts of interest, specialist partners, and subcontractors are declared before approval. The agreed roster, responsibilities, escalation path, and material-substitution controls are recorded in the SoW.
Evidence for diligence
- References and anonymised work examples are shared only where client confidentiality and reference-client consent permit.
- The review set can include corporate details, the current security questionnaire and evidence index, the data-flow and subprocessor map, and standard MSA, DPA, SoW, and Rules of Engagement templates.
- Grilli’s security programme is aligned to ISO/IEC 27001:2022 control families but is not externally certified. Commercial and insurance requirements are confirmed during diligence; this page does not represent current policy limits.
STANDARDS
What we hold ourselves to.
Our internal standards
- Security programme aligned to ISO/IEC 27001:2022 control families — not externally certified; a dated evidence index is available during diligence
- Applicable EU and Estonian dual-use export-control and sanctions requirements, including Regulation (EU) 2021/821 where relevant, assessed for security tooling and research transfers
- Data-protection practices designed around GDPR requirements; engagement-specific DPAs negotiated where applicable
- Secure software development lifecycle aligned to OWASP SAMM
- We coordinate with certified assessors (QSA, 3PAO) and provide advisory supporting client certification — we do not issue certifications ourselves
Assurance & governance
- Personnel screening is risk- and role-based and conducted only where permitted by applicable law; Estonia-based checks may use Karistusregister, while other locations use appropriate lawful local processes. Least-privilege access applies to client systems and data throughout.
- Encrypted data in transit and at rest; time-bound retention with secure destruction
- Client-controlled, EU-only, or isolated processing can be scoped where required; the approved infrastructure, providers, access locations, and deletion terms are recorded before data is transferred
- Change control, peer review, and documented runbooks for all operational procedures
- Business continuity and disaster recovery planning with tested recovery procedures
- Third-party tooling and supply-chain risk evaluation before integration into engagements
- Quarterly access reviews; all client access revoked same day upon engagement close
Get a written proposal
Send scope + timeline. Initial response and next steps within 1 business day; proposal timing is confirmed after scoping.
Open the form →
Email a senior practitioner
Direct line for scoping questions. NDA available on request before you share details.
hello@grillisecurity.com →
Active incident?
24/7 incident line. Triage call + retainer set-up inside the hour for new engagements.
+372 5610 1641 →
