We build AI, and we govern it.
Most consultancies do one or the other: they build AI without governing it, or they govern it without ever having built it. Nalgo exists because the two should not be separated, and because our founder has spent his career doing both.
John Bagnall
Founder · ISO/IEC 42001 Lead Implementer
John founded Nalgo after fifteen years building and shipping software and data products, the most recent leading AI product delivery at enterprise data platforms. The through-line is a hands-on technical background, SQL, Python and cloud data architecture, applied to products that had to work in production, not just in a demo.
He has built real AI. He led the delivery of an AI-powered data-quality product on AWS Bedrock and Anthropic Claude, using a retrieval-augmented architecture with persistent memory; built agentic workflows in LangChain against live enterprise data; and defined the Model Context Protocol strategy for a database platform, including the guardrails for letting agents reach real systems safely.
He has also spent years on the other half of the problem. He shipped data lineage and observability tooling on OpenLineage, built governance integrations with Collibra, Alation and Atlan, and stood up the audit trails, compliance reporting and SOC 2 controls that regulated enterprises depend on, after earlier modernising mission-critical public-safety software used by 25 UK police forces.
That combination, someone who has built AI in production and governed data at enterprise scale, is the whole idea behind Nalgo. It is now backed formally: John is a certified ISO/IEC 42001 Lead Implementer, the international standard for governing AI responsibly.
Built in production. Governed at scale.
You cannot write a real control for a system you have never built, and you should not ship AI you cannot defend. We have done both sides of that job, which is why we can do them together for you.
Built
- Production AI, not demos: a data-quality product on AWS Bedrock and Anthropic Claude, built on a retrieval-augmented (RAG) architecture with persistent memory.
- Agentic workflows in LangChain, running against real enterprise data.
- Model Context Protocol (MCP) strategy for a database platform, defining the guardrails for agent-to-database access.
- AI-led product onboarding that measurably improved activation and time-to-value.
Governed
- Data lineage and observability built on OpenLineage, with end-to-end audit trails.
- Governance integrations with Collibra, Alation and Atlan across enterprise data estates.
- Compliance reporting and SOC 2 controls for infrastructure holding regulated customer data.
- Mission-critical public-safety software used by 25 UK police forces, where oversight is not optional.
How we operate
The whole system, or nothing
A model in a notebook is not a product. We deliver the agent and the software it lives in as one shipped, owned system, because the gaps between those pieces are where production breaks.
Governance is architecture
Tracing, evaluation and guardrails are decisions you make on day one, not paperwork you add at the end. Build it in and you can answer hard questions later. Bolt it on and you cannot.
Measured, not vibed
Nothing ships against a gut feeling. An evaluation harness turns “we think it is better” into a number that moves, and keeps moving in the right direction.
You own what we build
Systems run on infrastructure you control, with no lock-in. We would rather you stay because the work is good than because leaving is painful.
Let’s talk about what you’re shipping.
Whether you are building AI, governing it, or both, the fastest way to find out if there is a fit is a conversation.