Technology

How we build

The technical page, for those who want it: what we measure ourselves on, and what the work looks like from the inside.

Measured, not claimed

We hold our own site to the standard we sell

Every number below is independently measurable today: security headers, performance, and a no-tracking promise you can verify in your browser's dev tools. The same discipline goes into client platforms: infrastructure as code, policy mapped to ISO 27001, CIS and NIST, and audit trails on by default.

A+ security headers

Strict CSP, HSTS and frame protection on every page, verifiable at securityheaders.com.

100 / 100 PageSpeed

Mobile and desktop, measured on the live site, no tricks: just a site with nothing wasteful in it.

No cookies, no trackers

This site collects nothing about you. Client systems follow the same principle: your data is yours.

Under the hood

Four disciplines, one standard

Not a logo wall: this is what the work actually looks like. The same four disciplines run through every system we ship, whether it is a line-of-business platform or a multi-tenant cloud product.

01

Build and ship

Every build is gated by its own tests and type checks; nothing reaches production on a promise. Releases are versioned, changelogged and reversible with one command.

  • Tests gate the build, every time
  • Offline-first clients that sync when service returns
  • Rollback is a command, not a crisis
A release pipeline run: tests passing, build reproducible, deploy healthy, rollback ready
02

Cloud and infrastructure

Whole environments are written as code: network, firewall, compute, logging, policy. Every deployment is identical, auditable, and private by default.

  • A new environment in under an hour, not a quarter
  • Controls mapped to ISO 27001, CIS and NIST
  • Change is a reviewed plan, never a mystery
An infrastructure-as-code plan and apply: network, firewall, compute, logging, backups and policy created from code
03

Security and access

Passkeys instead of passwords, roles that decide who sees what, and an audit line for every change: who, what, when, before and after.

  • Personal data locked to roles, per session
  • Append-only audit trails on money and people
  • Unknown devices are challenged, then logged
A passkey sign-in card next to an audit trail listing approvals, role changes, corrections and a blocked sign-in
04

Operate and observe

Every system we run tells the truth about itself: a status page anyone can read, heartbeats from every install, and backups proven by live restores rather than promises.

  • Uptime history in the open, bad days included
  • On-premises installs phone home daily
  • Restore drills, done in front of you
A live service status page with uptime bars for internet, sync, platform, backups and recovery point
Principles

How we choose what to build on

No per-seat fees

Where possible we choose software you can self-host and keep using even if we stop working together, instead of tools that charge for every user.

Proven technology

Everything we build on is well documented and widely understood. Your business runs on it, so it should not be an experiment.

No lock-in

Standard formats and open protocols throughout, so you can move to something else later without a painful migration. That includes moving away from us.

Not sure what fits your setup?

Tell us what you're running today and what it costs. We'll tell you honestly what we'd keep, what we'd replace, and what we'd simply switch off.