About

A specialist practice, not a faceless firm.

When you engage Gratia Group, you deal directly with the person leading your engagement. Every relationship is founder-led, backed by a small team of specialist contractors, not a call centre or a rotating support queue.

Claude Truter, Founder of Gratia Group
Claude Truter
Founder & Managing Director

Fifteen years in IT, preceded by six years in accounting. I built a corporate IT department from scratch, including a data centre with redundant server racks, before moving into cloud-native Microsoft 365 work. I spent years as the translator between users and developers, which is still how I approach a client's environment today.

Gratia Group is a specialist Microsoft 365 security and compliance practice, delivered remotely from Georgia to clients in South Africa, the UK, the EU and the US. I lead every client relationship personally, including attending meetings myself, and I'm supported by a small team of specialist contractors engaged under signed agreements, not a rotating support queue and not a large impersonal firm.

Microsoft 365 Security Compliance & Risk Former Microsoft Partner
The team

Founder-led, contractor-supported.

RELATIONSHIP

You always know who you're dealing with

I lead every client relationship and attend meetings personally, especially early in an engagement.

DELIVERY

Specialist contractors, not employees

Documentation, evidence handling and quality assurance are supported by contractors engaged under signed agreements, not staff on payroll.

SCALE

Deliberately small

Small enough that you're never handed off to someone you've never met, large enough that delivery doesn't depend on one person's calendar.

How we work

Secure, Support, Improve.

SECURE

Find and fix the risk

The Microsoft 365 Security & Compliance Assessment: where every engagement starts.

SUPPORT

Keep it running

Managed IT and Managed Compliance, once the exposure is understood and closed.

IMPROVE

Make it work better

Documentation, automation and tidy-up, once the foundation is solid.

Working boundaries

What we are, and what we're not.

ASSESSMENT

Not an audit or certification

Our reports are a management tool, prepared for your internal use. They are not an independent audit or a certification.

INDEPENDENCE

Disclosed, not assumed

Where we implemented a control ourselves, we say so in writing when we re-check it.

SCOPE

Security of processing, not legal advice

We assess your Microsoft 365 environment against POPIA and GDPR security requirements. We don't give legal opinions on your overall compliance.

INSURANCE

Evidence, not coverage promises

We produce the evidence insurers ask for. We're not insurance advisers and can't tell you how your policy will respond.

Want to talk before you book anything?

Get in touch