Guides for running a testing firm, written by people who run one.
These are the answers we have had to work out ourselves: what a client is really asking in a supplier assessment, why generated reports drift, what local inference is actually good at, and how to move a firm off a shared drive without stalling for a quarter. No product pitch inside them.
Where your engagement data should live, and how to defend the answer
Findings are the most sensitive artefact a consultancy produces. A practical look at custody, residency and what a client is really asking when they ask where their report is stored.
Answering a client security questionnaire about your own tooling
Consultancies increasingly get assessed by the people hiring them. What the questions are actually probing, and how to answer without either overclaiming or losing the deal.
Sending client email from your own domain, properly
SPF, DKIM and DMARC for a consultancy running a client portal. Why platform email lands in junk, what actually has to be aligned, and the order to do it in.
Running AI report writing on your own hardware
Local inference for finding write-ups and executive summaries: what it is genuinely good at, what it is not, the hardware that actually matters, and how to keep the output defensible.
Building a report template that renders the same every time
Why generated reports drift from the template they came from, what makes a Word document fragile to automation, and how to build one that survives contact with a generator.
Moving a consultancy off spreadsheets without losing a quarter
Most testing firms run on a shared drive, a spreadsheet and someone’s memory. A sequenced migration that does not require stopping work while you do it.
Something here you would like covered properly?
Tell us what keeps coming up on your engagements and we will write it up.