Regulated platforms & data protection
UK GDPR and DPA 2018, KCSIE, the ICO Children's Code, PECR. DPIAs, ROPA, consent models, subject access requests, retention and erasure, field-level encryption, audit trails, WCAG 2.1 AA.
Independent practitioners
Calam Consultancy is a small network of practitioners who have spent their careers building, fixing and running software systems. Tell us the problem, and we put you in touch with the person who has solved it before.
We work independently, and we know each other well enough to know who is actually good at what. If the right person is not one of us, we will say so and point you to someone better.
admin@calamconsultancy.comHow it works
A paragraph in an email is enough to start. What is broken, what you have tried, and roughly when it needs to be different.
Someone who has done this specific thing before — not the person who happens to be free. If nobody here fits, you get a recommendation instead of a pitch.
An individual contract, on your terms and inside your tools. A few days of review, a fixed piece of work, or an ongoing part-time engagement.
Where we can help
UK GDPR and DPA 2018, KCSIE, the ICO Children's Code, PECR. DPIAs, ROPA, consent models, subject access requests, retention and erasure, field-level encryption, audit trails, WCAG 2.1 AA.
Schema and data modelling, multi-tenant isolation, API contracts and OpenAPI specifications, non-functional requirements, data classification, and architecture documentation people will read.
AWS, Azure and GCP. Migrations without downtime, monoliths broken into services that survive a roadmap, observability a team keeps using, and cloud spend brought back under control.
Connecting to the third-party platforms your sector is stuck with — school MIS, transport management systems, financial platforms — with the ETL, taxonomies and data-quality work that comes attached.
Where AI genuinely helps and where it does not. Prompt and context engineering, LLM security against the OWASP LLM Top 10, a maturity assessment, and enablement that survives the first month.
Retrieval and agent pipelines, MCP integrations, model selection and cost control, evaluation and guardrails — past the pilot and into something you can actually run.
Reverse engineering and decompilation, reconstructing readable source and behaviour from binaries, and documenting the systems nobody in the building owns any more.
Out-of-cycle release review, incident response runbooks and severity models, sprint and board analytics, and the unglamorous work of making delivery dates mean something.
Hiring, offshore centre build-out, the leadership bench, retention, and the cultural plumbing between time zones. Done at scale, including one centre built to 190 people.
Dynamic application security testing, penetration test coordination and remediation, Cyber Essentials readiness, and test strategy that catches the things that actually break.
An honest read on a codebase, a team or a platform before you invest in it, acquire it, or commit a roadmap to it. Written for the person making the decision.
Positioning for technical products, competitive analysis, launch planning and the material sales actually uses. Grounded in evidence, with the guesses labelled as guesses.
How we work
Who you will hear from first
Twenty years in engineering leadership, most recently six of them as CTO of a freight technology company, and before that leading platform and transformation work in healthcare and financial services. I have hired, scaled, migrated, restructured and occasionally rescued engineering organisations, and I still write code most weeks.
Calam Consultancy is how I take work on now, and how I pass it to the right person when that person is not me.
Get in touch
A short description of the situation is enough. You will hear back within 24–48 hours, either with the name of the person who can help or with a recommendation elsewhere.