AI and Microsoft 365, rolled out properly.
Securely, fitted to what you actually do, and without paying for capability you do not need.
60 minutes with a consultant, then your risks in writing. No charge.Does one of these sound like your week?
Each one is a thing we are called about. Follow the one that fits.
We are rolling out Copilot and AI agents, and nobody knows what they can reach or what data leaves with them.
See how we fix itMicrosoft 365 was set up and never hardened. Access is too wide, sharing is open, backup is not guaranteed, and the logs are thin.
See how we fix itWe have an audit finding or a Loi 25 obligation, and nobody inside owns it.
See how we fix itA major client sent a security questionnaire we cannot answer, and the deal is waiting on it.
See how we fix itWe are about to buy Copilot for everyone, and we are not sure everyone needs it.
See how we fix itWe want to use AI properly, but we do not know which tools, which licences, or where to start.
See how we fix it
What it costs to do this properly — and what it costs not to.
CA$8,550
A year of Microsoft 365 Copilot for 25 people, at CA$28.50 each per month — the licences alone, on top of the Microsoft 365 subscription you already pay for. Implementation runs CA$10,000–20,000, plus CA$1,000–2,000 to connect it to your own data.
How many of your 25 actually need it?
Microsoft 365 Copilot Business list price, Canada, September 2026
CA$8 or CA$800
The same Copilot Studio agent, per month. A scripted answer costs one credit; a reasoning-model answer costs a hundred. What it costs depends entirely on how it was built.
Which of your tasks actually need a frontier model?
Microsoft Copilot Studio credit pricing, 2026
3.85×
A business employing one dedicated cybersecurity professional is 3.85 times less likely to experience cyber victimization than a business with none.
Dupont & Roy, IMC2 – Université de Montréal, 2026
How the engagement works
Three phases. A deliverable in each one.
- Phase 1
Assess
We inventory your environment — what exists, who can reach it, what's exposed. You leave with a clear picture of your IT systems and a prioritized list of the controls that will secure them.
Deliverable : Full inventory and prioritized control plan.
Then what? The list is yours. Implement it in-house, hand it to another firm, or move to the next phase with us.
- Phase 2
Protect
We implement the controls alongside your engineers, then test the posture to confirm they hold.
Deliverable : Controls in place, posture validated by testing.
Then what? Your team owns the controls. You can stop here.
- Phase 3
Maintain
Security isn't a project that ends. Your environment changes, and so do your AI tools. We stay available, scaled to what you actually need.
Model : Retainer, billed hourly against the work required.
What we do
Three lines of work. Each situation above leads into one of them.
- AICopilot and AI agents are already running. We scope what they can reach, fit the rollout to how your teams actually work, and licence for what you need rather than what the vendor bundles.Inventory, access and data leakage · Fitted to how your teams actually work · Licensed for need, not the vendor bundle
- Microsoft 365 & WorkspaceNobody ever configured it — so access is too wide, sharing is open, there is no backup, and licences are billed for people who never touch half of them. We fix the configuration and right-size the count.Access, sharing and backup, fixed · Licensed for who is actually using it · Fixed scope, not a subscription
- Audits & QuestionnairesAn auditor found something, or a client sent a questionnaire — and the deal is waiting on an answer nobody inside can give.Answered, with evidence · Loi 25, SOC 2, ISO 27001 · The gaps closed, not just listed
We do not resell software. Nothing we recommend earns us a margin, so the licence count we arrive at is the one you actually need.
Who you are working with

Ahmed El Ghilani
AI, Application & Cloud Security Architect
Ahmed has spent 17 years in IT security — more than 10 of them in application and cloud security, and the last three securing enterprise AI platforms. He works in the places where security either holds or quietly fails: the delivery pipeline, the cloud platform, and the AI tooling that now writes a growing share of the code.
Read the full profileStart with the free evaluation.
Sixty minutes with a consultant, then a written read on what to roll out, to whom, what it should cost, and what is exposed today. We reply within one business day.