When a programme is questioned β by the NAO, a minister, a committee β the question is rarely just whether it shipped. It's which options you weighed, what evidence you had, and whether the benefits actually landed. Weaxen builds that answer as the work happens: structured appraisal, calibrated sign-off, and a line of sight from spend to outcome.
Green Book appraisal expects options considered, assumptions stated, and evidence weighed β real breadth of analysis, not a business case that asserts the answer. That rigour exists at approval and evaporates the moment delivery starts.
A programme is approved on the benefits it promises and judged later on whether they materialised. Between the two sits eighteen months where nobody is checking delivery against those benefits β until the post-implementation review, or the NAO, asks.
Civil servants rotate, suppliers change, programmes outlive parliaments. The people answering for a decision are rarely the ones who made it β unless the record they inherit explains the choice, the evidence, and the sign-off.
Public sector buyers don't take control claims on trust β nor should they. This is Weaxen's posture, stated plainly:
Held in the UK (AWS London region) by default, encrypted in transit and at rest. Where residency is mandated, we adapt to your region β up to sovereign, on-soil hosting.
MFA, and on enterprise agreements SAML 2.0 single sign-on with DNS-verified domains β including the option to enforce SSO for your whole organisation.
Organisation-level audit logging of access-control and configuration changes, plus versioned artefacts for every product decision.
RACI and phase sign-off are part of the framework itself β accountability is structural, not procedural.
Sovereign, on-soil, or air-gapped requirements are part of how we deploy, scoped to your programme. Start that conversation early at security@mindlace.co.uk.
Teams describe what they're building in plain language. No taxonomy to learn, no template to fill.
Path Forger recommends the right artefacts for your stage and risk level. A scrappy pre-seed run looks different to a Series A launch β same engine, right dose.
Every decision documented. Every assumption surfaced. Every risk traceable. Ready for engineers, boards, or Claude Code.
Yes. Workspace data is held in the UK by default, and where a programme mandates sovereign or on-soil hosting we adapt to that requirement. If your programme has hard hosting constraints, start the conversation before you shortlist: security@mindlace.co.uk.
Materially. The record of what was decided, when, on what evidence, and by whom is exactly the substrate those requests draw on β versioned and timestamped rather than reconstructed from inboxes.
Our security posture, subprocessor inventory, and data-processing documentation are available on request at security@mindlace.co.uk, alongside our published vulnerability disclosure policy.
Organisations support role-based membership with invitations under your control, so programme teams and suppliers work in one record β and access ends when the engagement does, with the audit log to show it.
For teams who treat "build the right thing" as a precondition, not a slogan. Start for free β