Approach
How we work
Cairn exists because critical British institutions were being asked to trade control for convenience. We don't make that trade, and we build so that you never have to either.
01 The principle
Sovereignty is a security property
The word “sovereignty” gets used loosely. We mean something specific and testable: you can inspect the software protecting you; you can host it where your legal and operational obligations require; and you can keep it running without any single vendor's permission.
If any of those three is false, you are carrying a risk you cannot fully see — and increasingly, one your assurance body will not accept.
02 Why open source
Why open source, precisely
Open source is not about cost. It is about auditability and ownership. Proprietary security asks you to trust a black box. Open foundations let us — and you, and your auditors — read exactly how detection, filtering, and hardening work.
When something matters this much, “trust us” is not an answer. “Read it yourself” is.
03 The three commitments
We build in the open
Detection rules, firewall policy, hardening baselines — all reviewable artefacts, not vendor secrets.
We host on your terms
UK or on-premises as your obligations require. No data leaves your jurisdiction without your explicit decision.
We design your exit
You can take the platform in-house or move providers without a rebuild. This is deliberate.
04 Pragmatism
Pragmatism, stated plainly
We are not purists for the sake of it. Some requirements are genuinely better served today by a proprietary component. When that is true, we tell you, we integrate it cleanly, and we write down the reasoning so the decision is yours and it survives staff turnover.
Open by default; honest about the exceptions.
05 Engagement
How a Cairn engagement runs, from first assessment to handover.
How an engagement runs
-
Assess
We map what you have, what you must protect, and what you are obliged to prove.
-
Design
An architecture on open foundations, with any exceptions justified in writing.
-
Build as code
Configuration and hardening delivered as version-controlled, benchmarked artefacts.
-
Operate
24/7 monitoring and response from a UK-based, cleared team.
-
Hand over the keys
Documentation and knowledge transfer so ownership is real, not nominal.