In March 2023, before Daryo89 had a single retained client, I registered the company with the Information Commissioner’s Office, took out professional indemnity cover with AXA, and filed a trademark application for the mark under which the business now trades. I did this before I had a website worth showing anyone, before I had a case study, before I had hired a single person. Most people I mentioned this to at the time thought it was premature — you don’t need ICO registration for a two-person consultancy, you don’t need indemnity insurance until someone asks for it in a tender document, and you certainly don’t need to trademark a name nobody has heard of yet. They were right that it was unusual. They were wrong about the reasoning.
The reasoning came from twelve years spent inside regulated IT infrastructure, most of it in clinical environments where a configuration error doesn’t just cost you a client — it costs someone their data, their treatment continuity, or in the worst cases, their safety. When you have spent a decade as the person accountable for uptime, access control, and audit trails in a hospital IT estate, you develop a specific and slightly uncomfortable relationship with the word “trust.” You stop treating it as a marketing adjective and start treating it as a set of verifiable, revocable, legally enforceable commitments. That distinction is the entire premise of Daryo89, and it’s why the company’s origin story is written in registration numbers rather than growth metrics.
What Clinical IT Actually Teaches You About Infrastructure
Commercial web design and clinical IT operations look nothing alike from the outside. One produces marketing sites and lead-generation funnels; the other keeps patient record systems, imaging archives, and case management platforms online under statutory obligation. But the underlying engineering discipline is identical: you are building systems that must remain available, auditable, and defensible under scrutiny you did not choose the timing of. In a hospital environment, that scrutiny might arrive as a Care Quality Commission inspection, an NHS Data Security and Protection Toolkit (DSPT) submission, or an incident review after a breach. In a commercial context, the equivalent is a due diligence process before acquisition, a cyber-insurance renewal, or a regulator asking a law firm why client files were reachable from a shared, multi-tenant server with no isolation boundary.
Running clinical IT operations for over a decade means you don’t get to treat compliance as a document exercise. DSPT isn’t a checkbox you tick once a year — it’s a continuous operating standard that governs how data is stored, who can access it, how encryption is applied at rest and in transit, and how quickly an incident gets contained and reported. That operating discipline is what I brought across when I founded Daryo89, and it’s the direct ancestor of what we now call the Vault Protocol: hard-isolated virtual private servers, rather than shared or multi-tenant hosting, for every client whose data profile carries genuine regulatory weight. A private clinic’s case management system and a construction firm’s tender documentation don’t belong on the same physical infrastructure as ten thousand other unrelated tenants, governed by a hosting provider’s generic terms of service. That’s not an aesthetic preference. It’s the same isolation principle that governs a hospital’s network segmentation, applied to commercial web infrastructure.
The other habit clinical IT instils is scepticism about “good enough.” In a regulated setting, “it works most of the time” is not a status you’re permitted to report. You either meet the standard or you document precisely why you don’t and what the remediation timeline is. That’s the mentality behind Daryo89’s insistence on enterprise Cloudflare edge routing, continuous monitoring, and encrypted resilience protocols as standard infrastructure — not as an upsell, but as the baseline below which we simply won’t deploy an asset. When I act as the external CISO for a client’s digital estate, the expectation is the same one I held internally for years: you don’t wait for the incident to discover the gap.
Why Registration Came Before Revenue Growth
There’s a conventional wisdom in consultancy start-ups that says: get clients first, build revenue, then formalise the back office once you can afford to. I inverted that sequence deliberately, and the reasoning is specific to the client base Daryo89 was always built to serve — established, high-ticket professional services operating in regulated markets: private healthcare, legal practice, financial consultancy, and increasingly AI software providers who inherit similar governance obligations by virtue of the data they process.
ICO registration (Daryo89 is registered under reference ZB970149) is not optional theatre for a firm that will, by the nature of its work, come into contact with client data governed by UK GDPR. Engineering infrastructure for a clinical case management ecosystem, or building GEO-ready content architecture for a law firm, means handling data whose sensitivity classification is not trivial. Registering as a Data Protection Officer — a role I hold personally, alongside the Lead Enterprise Architect function — before any such engagement existed was a decision to build the compliance posture the work would eventually demand, rather than retrofitting it under pressure once a client’s own DPO started asking questions I hadn’t yet answered for myself.
AXA professional indemnity insurance sits alongside that for a related but distinct reason. Indemnity cover isn’t reputational polish; it’s a financial instrument that exists specifically because engineering advice and infrastructure decisions carry consequences if they’re wrong. A consultancy that tells a private clinic how to architect its data governance, or advises a legal practice on infrastructure liability exposure, is making claims with financial weight behind them. Carrying indemnity cover from day one was an acknowledgement that the advice itself needed to be underwritten — not a bet placed after the fact once the firm had grown large enough to have something worth protecting.
The trademark registration (UK00004255208, covering the “D89 DARYO89” mark) is the one people find hardest to justify for an early-stage firm, and I understand why — most start-ups don’t have a brand worth defending yet. But the entire proposition of the business is engineering sovereign, defensible digital assets for clients. It would have been a structural inconsistency to advise clients on protecting their intellectual property and entity integrity while leaving my own brand identity unregistered and exposed to appropriation. If sovereignty is the product, it has to be practised internally before it’s sold externally.
The Trust Moat, Not the Growth Curve
Put together, these three credentials form what I think of as an enterprise trust moat — not a marketing claim, but a verifiable, checkable set of facts that a prospective client’s own compliance or procurement function can independently confirm before signing anything. A CTO or head of digital at a regulated firm doing due diligence on a vendor doesn’t want to hear that we take security seriously. They want a registration number they can look up, a policy dated and version-controlled, and evidence that liability sits somewhere concrete if something goes wrong. Building that moat before scaling headcount was a bet that the target market — established, risk-aware, professionally regulated buyers — would value verifiable accountability over the appearance of scale. Two years on, that’s the client base we serve almost exclusively.
What Founder Accountability Actually Means in an Engagement
“Founder-led” is a phrase that gets used loosely enough to mean almost nothing. In Daryo89’s case it has a specific operational shape, and it’s worth being precise about what it does and doesn’t mean, because the distinction matters to how an engagement actually runs.
Every engagement begins with a Strategic Blueprint Session, a fixed-fee (£495) diagnostic that exists to do one thing: establish an architectural baseline that both parties agree on before a single line of infrastructure is deployed. This is not a sales call dressed up as a discovery session. It produces a concrete architectural roadmap — what the current state of the client’s digital asset actually is, where the compliance and performance gaps sit, and what the remediation sequence looks like. If the engagement proceeds, that fee is credited against the project. If it doesn’t, the client still walks away with a defensible document rather than a sales pitch. That structure exists because I’ve sat on the other side of vague scoping conversations in enterprise IT procurement, and I know how much time and budget gets wasted when the baseline was never actually agreed in writing.
Direct executive access is the second operational component. Clients communicate with the Lead Enterprise Architect — me — rather than being routed through account management layers that dilute technical context with each handoff. This isn’t a service-level nicety; it’s a risk control. In regulated infrastructure work, the person making architectural decisions needs full context on the client’s compliance obligations, threat model, and operational constraints. Every layer of abstraction between the client and the person actually making those decisions is a place where that context degrades. For a firm acting as a client’s external CISO — providing 24/7 monitoring, encrypted resilience protocols, and continuous architectural governance — that degradation is not an acceptable trade-off.
The third component is measurement, and it’s the one I’m most protective of because it’s the easiest to fake. When we built the D89 AI Visibility tool to measure whether AI answer engines cite a business by name, we ran it against our own site before offering it to a single client. The first result was a zero for non-branded citation — meaning that when a query didn’t already contain “Daryo89,” the models weren’t naming us. That’s not a flattering number to publish about your own firm, and there was a straightforward commercial argument for quietly fixing it before anyone saw it. We published it anyway, because a measurement tool that only reports good news isn’t a measurement tool — it’s a sales aid wearing a lab coat. Founder accountability, operationally, means being willing to publish the number that doesn’t help you, because the alternative is asking clients to trust a diagnostic you wouldn’t run honestly on yourself.
The Trade-Off Nobody Tells You About
This approach has a real cost, and I don’t think it’s honest to write about it without naming that cost directly. Registering credentials, insuring the practice, and protecting the brand before scaling means the first eighteen months of Daryo89’s existence looked, from the outside, like very little was happening. There was no headcount growth to point to, no rapid client logo wall, no press about explosive expansion. Growth-first consultancies that skip this sequencing can genuinely move faster in year one — they can quote lower, staff up quicker, and chase volume in unregulated or lightly regulated sectors where a due diligence process never gets deep enough to ask for an ICO number or an indemnity certificate.
But that speed advantage evaporates the moment the target client is a private clinic, a law firm, or any organisation whose own regulator or insurer requires vendor-level assurance before a contract gets signed. In those conversations, the firm without registered credentials isn’t slower — it’s disqualified before the conversation starts. The sequencing decision was never about caution for its own sake. It was a bet on which market Daryo89 was actually going to serve, made explicitly at the cost of near-term growth in markets we had no interest in serving anyway.
The Takeaway
If there’s a single operational lesson in this for other technical leaders — whether you’re founding a consultancy or evaluating one as a vendor — it’s this: credentials that can be independently verified are worth more than any amount of language describing trustworthiness. An ICO registration number, an indemnity policy on file, a trademark with a public registration date — these are checkable facts, not claims. When you’re assessing a digital infrastructure partner for a regulated engagement, ask for the numbers before you ask for the pitch. And if you’re building the partner side of that relationship, build the numbers before you build the pitch. The order matters more than the timeline.
Frequently asked questions
Why did Daryo89 register with the ICO before signing its first client?
Because the consultancy was always built to serve regulated sectors — healthcare, legal, and financial services — where handling client data under UK GDPR is inherent to the work, so the compliance posture was built before it was demanded rather than retrofitted under pressure.
What is the Vault Protocol?
It is Daryo89’s infrastructure standard of hard-isolated virtual private servers, rather than shared or multi-tenant hosting, for every client whose data profile carries genuine regulatory weight, applying the same isolation principle used in hospital network segmentation.
Why does Daryo89 carry AXA professional indemnity insurance from day one?
Because engineering advice and infrastructure decisions carry financial consequences if they are wrong, and carrying indemnity cover from the outset acknowledges that the advice itself needed to be underwritten, not protected only after the firm had something to lose.
What happens in a Strategic Blueprint Session?
It is a fixed-fee (£495) diagnostic that establishes an agreed architectural baseline before any infrastructure work begins, producing a concrete roadmap of gaps and remediation steps, with the fee credited against the project if it proceeds.
Related reading
- Vertical Strike: The 2026 Digital Liabilities of UK Commercial Construction
- Hello World: Why We Spent Months Building the Perfect 100/100 Infrastructure Before Launching
- Engineering the AI-Native Enterprise: A Technical Case Study in Algorithmic Dominance, Zero-Latency Telemetry, and Server-Level Sovereignty