Services

Work we already do every week, applied to your product

Every service line below is demonstrated by something running in production under our own name. You can open it, sign up, and judge the engineering before the first conversation — which is a better basis for hiring anybody than a slide.

AI and LLM application engineering

Most assistants are a prompt with a text box in front of it. The ones worth paying for are grounded in something — a user's actual history, a document set, the state of the system they are talking about. That grounding, and the plumbing that keeps it affordable and honest, is the work.

  • Retrieval and grounding: an assistant that opens with what the user actually got wrong, rather than a generic first message
  • Model routing across providers, with key rotation, health-based retirement and automatic failover, so an outage slows a job rather than losing it
  • Credit and quota metering with a ledger that reconciles, prices shown before the action, and automatic refunds on failure
  • Support for hosted and local models through OpenAI-compatible endpoints, including fully air-gapped deployment
  • Robust handling of malformed model output, and checkpointing so a long job resumes rather than restarts
Proved in Examness and Provelex

Automated QA and security testing

A test suite that breaks whenever the interface changes gets switched off within a year. We build browser automation that resolves controls by what they are rather than where they were, so a redesign produces a healed step instead of a red build and a maintenance backlog.

  • Functional coverage driven in a real browser, with test cases derived from the application rather than hand-written and left to rot
  • Security review against the OWASP Top 10 (2021) using bounded, non-destructive probes, plus headers, cookie flags, TLS and exposed files
  • Accessibility against WCAG through axe-core, translated out of developer language, and Core Web Vitals measured from the page itself
  • Reports built to be forwarded: business impact, reproduction steps, evidence, standards mapping and a confidence figure on every finding
  • A build-pipeline gate that fails a release on a critical or high finding, and a documented HTTP interface for your own tooling
Proved in Provelex

Web platform engineering

The unglamorous half of a product: the API, the schema, the sessions, the money, the deployment. It is where most of the risk lives, and it is the part that decides whether the interesting half can be changed safely six months later.

  • API and database design, authentication and session handling, and authorisation scoped so that a new endpoint fails closed by default
  • Billing and ledger systems where every movement is a line with a reason, and the lines sum to the balance
  • Live progress over WebSocket — a timeline you can watch rather than a spinner you have to trust
  • Deployment behind automatic HTTPS with security headers, access logging and rolled retention, on your infrastructure or ours
  • Single-entry-point operations: one command to serve, one to run a job, one to check the environment and name what is missing
Proved in Examness and Provelex

Cross-platform mobile

An app is worth building when it shares an account and a backend with the web product, not when it is a second codebase telling a slightly different story. We build the phone client as another window onto the same data.

  • Android and iOS from one codebase, signing into the same account and sharing the same balance, history and progress
  • Honest handling of what the phone cannot do — stated plainly in the interface rather than hidden behind a broken button
  • Light, dark and a system setting that follows the device, matched to the web product
  • Multilingual interfaces where every user-facing string is translated rather than machine-guessed at run time
Proved in Examness

How an engagement runs

Small, visible steps, in that order

We would rather be judged on something working than on a document describing something that will work.

A conversation about the problem

What is actually costing you time or money, what has already been tried, and what would count as this being finished. Free, and often ends with us saying you do not need us.

A written specification

A single document precise enough to be executed without further clarification: scope, interfaces, data, what is explicitly out of scope, and how each piece will be verified. You own it either way.

A working slice, early

The thinnest end-to-end path that proves the architecture, running where you can open it. Everything after that is widening, not discovering.

Handover that survives us

Source, tests, a deployment path you can run yourself, and documentation written for the person who inherits it. No component that only works because we are still here.

If a piece of the work turns out to be better solved by something that already exists, we will say so. A recommendation that costs us a line item is worth more to you than one that does not.

Tell us what is not working

One email with the problem in your own words is enough to start. If it is outside what we do well, we will tell you that rather than take it on.