Quote

A security firm built by practitioners.

Grilli Security is built by senior practitioners, not resellers or generalist consultants. We work with organisations that need measurable security outcomes: reduced exposure, faster detection, audit success, and the capability to respond when something goes wrong.

WHO WE ARE

Three things make a partner worth paying for.

Practitioners, not generalists

  • Engagement teams are staffed by specialists in the relevant discipline: red team operators who have run full-chain campaigns, DFIR analysts who have handled major breaches, and engineers who build secure systems for a living.
  • No account managers in the room. The person who scopes your engagement is the person who delivers it.

Outcomes, not reports

  • We measure success by what changes: reduced MTTD/MTTR, fewer critical findings, clean audit outcomes, and post-breach environments that hold.
  • Deliverables identify what to fix and how to fix it; validation or retesting is included only where the service and signed SoW provide for it.

Worldwide 24/7

  • 24/7 coverage for SOC, incident response, and emergency engagements.
  • Worldwide coverage with a European-centric delivery model and senior on-call escalation for off-hours emergencies.
  • Website records and Grilli-hosted engagement data use EU storage by default, but storage location does not imply EU-only access: authorised personnel may work from Estonia or Argentina. EU-only access is available when agreed before data is shared.
ENGAGEMENT CONTROLS

Named specialists remain accountable throughout the engagement.

The engagement model defines scope, responsibilities, and controls in writing. Deliverables are prepared to withstand legal, regulatory, and technical scrutiny.

Before work begins

  • Mutual NDA available before sensitive information is shared and required where the engagement terms or SoW call for it
  • Defined scope, objectives, and deliverables agreed in writing
  • IP ownership, transfer triggers, and any background-IP licences defined in the signed MSA and SoW
  • Rules of engagement and authorisation chain documented for technical engagements
  • Data processing agreement in place where personal data is in scope

During engagements

  • Critical and high severity findings issued immediately, without waiting for the final report
  • Encrypted, out-of-band communication channels for sensitive engagements
  • Access limited to named personnel on a least-privilege, need-to-know basis
  • All activity logged with analyst identity and timestamp for auditability
  • No undisclosed subcontracting, with every specialist disclosed and client-approved in advance

At engagement close

  • All access revoked on the day the engagement ends
  • Evidence, exploits, and sensitive artefacts returned or securely destroyed with certificate
  • Retest availability: validation that remediation was effective
  • Retention period defined per contract; no open-ended storage of client data
WHO WE WORK WITH

Sectors and engagement models.

Industries we serve

  • Payments & Finance · PCI DSS 4.0 compliance, cardholder data environment testing, and fraud-path red teaming
  • Health & Life Sciences · HIPAA breach preparedness, medical device security, and clinical system hardening
  • SaaS & Cloud · multi-tenant architecture review, supply chain security, and continuous compliance programmes
  • Retail & eCommerce · PCI DSS scope reduction, API security, and fraud-vector penetration testing
  • Public Sector & Critical Infrastructure · NIS2/DORA compliance, ICS/OT security assessment, TIBER-EU-aligned red teaming
  • Defence & Aerospace · high-assurance engineering, Common Criteria readiness, FIPS 140-3 preparation, DO-178C alignment

Engagement types

  • Project-based · defined scope, timeline, and deliverables for assessments, audits, and research campaigns
  • Retainer · reserved response capacity governed by pre-agreed SLAs; recommended for SOC, DFIR, and ongoing advisory
  • Embedded engineering · our practitioners integrated into your team for the engagement duration
  • Advisory · design review, threat modelling, and strategic guidance without full implementation access
  • Emergency · 24/7/365 incident response available on retainer or as an ad-hoc engagement with SLA commitments
BUYER DILIGENCE

Verify the entity, team, and evidence before signature.

Our public corporate identity is sourced from the Estonian e-Business Register. Email legal@grillisecurity.com with subject PROCUREMENT REVIEW for onboarding documents, or hello@grillisecurity.com for the wider diligence set.

Contracting entity

  • Grilli OÜ is the legal entity behind Grilli Security: an Estonian private limited company registered under code 17417589.
  • Registered office: Järvevana tee 9, 11314 Tallinn, Estonia.
  • VAT status: not VAT-registered, as shown in the current Estonian e-Business Register record.
  • Our operating locations are Tallinn, Estonia, and Buenos Aires, Argentina. Access location and any EU-only restriction are recorded before client data is shared.

Know who will do the work

  • During scoping we provide the proposed named engagement lead and delivery roster, with each person’s role, seniority, delivery responsibility, and working location.
  • Credential and certification evidence is available for buyer verification under NDA; a title or standard named on this website is not a substitute for that evidence.
  • Conflicts of interest, specialist partners, and subcontractors are declared before approval. The agreed roster, responsibilities, escalation path, and material-substitution controls are recorded in the SoW.

Evidence for diligence

  • References and anonymised work examples are shared only where client confidentiality and reference-client consent permit.
  • The review set can include corporate details, the current security questionnaire and evidence index, the data-flow and subprocessor map, and standard MSA, DPA, SoW, and Rules of Engagement templates.
  • Grilli’s security programme is aligned to ISO/IEC 27001:2022 control families but is not externally certified. Commercial and insurance requirements are confirmed during diligence; this page does not represent current policy limits.
STANDARDS

What we hold ourselves to.

Our internal standards

  • Security programme aligned to ISO/IEC 27001:2022 control families, though not externally certified; a dated evidence index is available during diligence
  • Applicable EU and Estonian dual-use export-control and sanctions requirements, including Regulation (EU) 2021/821 where relevant, assessed for security tooling and research transfers
  • Data-protection practices designed around GDPR requirements; engagement-specific DPAs negotiated where applicable
  • Secure software development lifecycle aligned to OWASP SAMM
  • We coordinate with certified assessors (QSA, 3PAO) and provide advisory supporting client certification; we do not issue certifications ourselves

Assurance & governance

  • Personnel screening is risk- and role-based and conducted only where permitted by applicable law; Estonia-based checks may use Karistusregister, while other locations use appropriate lawful local processes. Least-privilege access applies to client systems and data throughout.
  • Encrypted data in transit and at rest; time-bound retention with secure destruction
  • Client-controlled, EU-only, or isolated processing can be scoped where required; the approved infrastructure, providers, access locations, and deletion terms are recorded before data is transferred
  • Change control, peer review, and documented runbooks for all operational procedures
  • Business continuity and disaster recovery planning with tested recovery procedures
  • Third-party tooling and supply-chain risk evaluation before integration into engagements
  • Quarterly access reviews; all client access revoked same day upon engagement close
ACTIVE INCIDENT?→