
Velinor is a UK-based assurance firm helping defence, government, and regulated-industry organisations prove their cyber security posture and AI systems would survive audits and regulatory scrutiny. The company provides exposure assessment, evidence-pack creation, and AI assurance services aligned with the MoD's Cyber Security Model v4 and Def Stan 05-138 Issue 4 standards. Velinor's approach ranks real-world risks and keeps evidence current for assessors, primes, or regulators.
Funding
Funding not disclosed
Founders
Product
Problem
Most organisations cannot accurately state what of their digital estate is exposed to the internet at any given time, nor can they produce evidence that their AI systems would withstand an audit or regulatory review. This becomes critical for defence suppliers facing the 31 December 2026 deadline under Industry Security Notice 2025/07, which mandates compliance with Cyber Security Model v4 and Def Stan 05-138 Issue 4 for all MOD contracts carrying DEFCON 658.
Solution
Velinor provides cyber and AI assurance services that help organisations identify what is actually at risk, prove it is managed, and keep the evidence current. The company assesses internet-facing exposure and AI use cases against real-world threat, producing a ranked risk register and an evidence pack that stands up to boards, regulators, assessors, or insurers. Velinor's methodology is grounded in the AI Blindspot Framework, a risk taxonomy calibrated against documented real-world AI failures. The firm also offers a free, no-sign-up twelve-question checklist that helps suppliers determine which Defence Cyber Certification level their contracts require, distinguishing between the three controls at Level 0 and the 101 controls at Level 1.
Target Audience
Primary customers are defence suppliers, government contractors, and organisations in critical national infrastructure and regulated industries that must meet MoD cyber certification requirements or prove AI assurance to auditors and regulators.
Features
- Exposure assessment that identifies internet-facing assets and ranks them against real-world threat
- AI assurance using the AI Blindspot Framework, a risk taxonomy built from documented AI failures in public sources
- Evidence-pack creation designed to satisfy assessors, primes, regulators, and insurers
- Free, no-sign-up DCC checklist covering twelve questions to determine required certification level
- Alignment with Def Stan 05-138 Issue 4 controls, including vulnerability management, patching policy, asset inventory, and security monitoring
- Continuous evidence maintenance to keep records current as the estate and rules evolve