§ 01About the firm
One contract for the people who build the estate and the people who defend it
Eigenvector IT LLC is an IT services and cybersecurity firm, a limited liability company registered in the United States. Two practices, Technology Services and Cyber Defence, design, run and defend the systems that banks, hospitals, utilities and government departments cannot switch off. The firm publishes the commitments written into its contracts, and reports every engagement against them in writing each month.
§ 02What we believe
The builder and the defender should answer to the same contract
On most estates the firm that builds the platform and the firm that defends it answer to different contracts, and neither will show the other its evidence. Eigenvector IT puts both under one contract, one service level schedule and one accountable lead. The firm has taken no outside investment and has never changed hands. The name is borrowed from mathematics: in a system under constant change, some directions hold. What the firm will stand behind is written down. The commitments below sit in the master services agreement, and the monthly service report measures the work against them.
§ 03Commitments
Four commitments, written into the contract
15 minutes
Priority one alert acknowledged1
30 minutes
Containment action taken2
90 days
Retest after remediation3
8
Service lines under two practices4
1 An analyst acknowledges and begins triage within 15 minutes of a priority one alert.
2 Actions in the authority matrix agreed at onboarding are taken without waiting for approval.
3 A retest within 90 days confirms each fix and closes the report at no additional charge.
4 Four in Technology Services, four in Cyber Defence, each scoped and reported on its own.
§ 04Operating principles
Four rules written into the contract
Each of the four is written into the master services agreement, not only onto this page.
01
Delivery is staffed by our own employees
Delivery is by our own employees, and nothing is subcontracted except hardware forensics beyond our laboratory and external legal counsel during a regulated incident, both named in the proposal and both under our contract. Named personnel are not substituted without notice and the replacement's résumé. The subprocessor list is contractual, any change requires 30 days' notice, and no client work moves to another firm without written consent. The work is done in-house across six disciplines:
- Cloud and infrastructure engineering
- Identity and platform operations
- Detection and response analysis
- Incident response and digital forensics
- Offensive security
- Governance, risk and compliance
02
We take no margin on what we recommend
Licences and hardware are contracted directly between the client and the vendor. Our engineers hold their vendor certifications personally, and the firm takes no rebate, referral fee or margin on anything it assesses, specifies or installs. There is no sales team. The lead who scopes the work is the one who delivers it and signs the report. Advice is priced as advice.
03
We report the months we miss
A service report covering every agreed service level for the previous month is issued on the fifth working day and signed by the service manager named in your contract. Missed targets are reported with the cause and the corrective action beside them. A review runs every quarter. Those reports are the evidence behind every service level figure the firm quotes.
04
Case data stays in the region that produced it
Client data is stored and processed in the region you select: northern Virginia for the United States, Frankfurt for the European Union, and Toronto for Canada on request. Monitoring data, forensic images and evidence stay inside the region that produced them. Telemetry is segregated per client. Access from outside the region takes place from managed devices under privileged access controls, and every transfer is requested in writing and recorded.
§ 05How we operate
Two practices, one contract, one accountable team
Technology Services builds and runs the estate. Cyber Defence watches and tests it. Each is led by a practice lead who still delivers, both sit under the same master services agreement, and both meet the same client each month.
Built and defended together
The person who builds your identity platform and the analyst who watches it work for the same firm, under one master services agreement and one accountable lead. There is no handover between suppliers, because there is only one supplier. Nothing is subcontracted, so no part of the estate falls between two contracts.
Evidence, not assertion
Every engagement produces artefacts a third party can check: test results with timestamps, a recovery time recorded during a failover you attended, control evidence mapped to the framework your auditor uses. The firm states what it commits to, then reports the measurement against it every month, so each claim can be checked against a document rather than taken on assurance.
Senior people on site
Everyone who will do the work is named in the proposal with the prior roles that qualify them, and the named person is the person who arrives. The lead who scoped the engagement attends the reviews and signs the final report.
Every board asks the same question: what happens if this stops. We are hired to answer it with evidence rather than assurance
Nadia Ben Salah
Chief Executive Officer
§ 07Leadership
Four people lead the firm, and no one else signs the work
Each is accountable for a defined part of the work, each still delivers, and each signs what they deliver.
Nadia Ben Salah
Chief Executive Officer
Accountable for the contract, the risk register and the financial services accounts. They sign the master services agreement on every engagement and chair the review that sets the firm's risk position each quarter.
Prior role: operations director at a European payments processor, running authorisation and settlement for 40 issuing banks across 9 countries · CISSP
Henrik Lindqvist
Practice Lead, Technology Services
Leads Technology Services and is accountable for cloud, infrastructure, identity, managed operations and continuity. They set the rule that a cutover does not proceed until the rollback has been tested.
Prior role: 12 years in grid operations technology, then platform migration lead at a European utility group with generation and distribution in 4 countries · Azure Solutions Architect Expert
Priyanka Raghunathan
Practice Lead, Cyber Defence
Leads Cyber Defence and is accountable for detection, offensive security, and governance and compliance. They own the containment authority matrix agreed with each client at onboarding.
Prior role: analyst at a national computer emergency response team, then built and ran the detection function for a multinational bank across 30,000 endpoints · CISSP · OSCP
Ifeoma Adeyemi
Lead, Incident Response and Digital Forensics
Accountable for retained response, digital forensics and the evidence standard. They write the single report that the regulator, the insurer and the board can each use, and they decide what the firm is willing to state as fact.
Prior role: 9 years in law enforcement digital forensics, then containment lead at a specialist response firm working an insurer's panel · GCFA
§ 08Credentials
Credentials held by people, not by the firm
Eigenvector IT holds no corporate certification. SOC 2 Type I is in preparation and the examination date is set. Everything below it is a personal credential, held by the named practitioner and verifiable with the body that issued it.
- SOC 2 Type IIn preparation. Not held.Readiness work with an independent CPA firm is underway. The Type I examination is scheduled for 1 December 2026 and the report is expected by 31 January 2027. The Type II observation window opens 1 January 2027 and closes 30 June 2027.
- CISSPNadia Ben Salah, Priyanka RaghunathanPersonal certification, ISC2
- OSCPPriyanka Raghunathan, Rania HaddadPersonal certification, OffSec
- GCFAIfeoma Adeyemi, Aleksandra NowakPersonal certification, GIAC
- CISASofia Marchetti, Katharina VogtPersonal certification, ISACA
- CCSPDiego SotomayorPersonal certification, ISC2
- AWS and AzureHenrik Lindqvist, Tobias Reinhardt, Diego SotomayorAzure Solutions Architect Expert and AWS Solutions Architect – Professional, held individually
§ 09Careers
We hire people who want to stay technical
Eigenvector IT pays for the qualifications the work requires — cloud engineering, OSCP, lead auditor, forensic certification — and study time is scheduled inside the working week rather than taken from evenings. Every candidate meets the lead who will manage them before an offer is made, and that lead reads the application. Vacancies are listed on the careers page.
§ 10Next step
Scoping is done by the lead who will sign the report
Every enquiry is answered by a named person within one working day. Retained clients escalate through the channel agreed in their retainer. Everyone else starts at enquiries@eigenvector.group.