We are an engineering consultancy. We build AI systems, web platforms and the identity infrastructure underneath, and we work inside the engineering teams that run them.
Our clients are startups and scale-ups across the DACH region and the EU. Most of what we work on is already in production, with real users on it. If that sounds like your system, we would be glad to hear about it.
What we do.
AI systems
- Claude
- Gemini
- Mistral
- Node.js
We take the documents and email your business already receives and turn them into records your other systems can accept.
The model is the part you can change in an afternoon. Everything that decides whether the system works sits around it, and that is where the engineering goes.
- Evaluation against records where you already know the answer
- Retrieval over PDFs and scans, chunked the way the document is actually laid out
- Cost per document and per model, instrumented beside latency and error rate
- Agents, and the tools each one is allowed to call
Web platforms
- Next.js
- PayloadCMS
- PostgreSQL
- Stripe
We build the application your customers use, along with the content system, the payments and the hosting that stand behind it.
Those four have to agree with each other, and most of the trouble lives in the seams between them: content that needs a deployment to change, a payment that succeeded but never reached the ledger, a framework upgrade nobody can afford to start.
- Content models in PayloadCMS, versioned with the application
- Payments and billing: Stripe, PayPal, Alipay, and the webhooks behind them
- Access enforced in the database with Row Level Security
- Version and security updates for as long as you want them
Product development
- TypeScript
- React
- Supabase
- Kubernetes
We add senior engineers to a team that is already building, or take the technical lead’s seat when there is nobody in it.
- Interim lead for an engineering or product team, through growth or a crisis
- Mentoring engineers, and building teams that run themselves
- Sparring for a CTO, CIO or founder who already holds the seat
- Assessing a system landscape, its teams and processes, and the target architecture that follows
- Make-or-buy and vendor decisions, and standing between the business, its IT and its suppliers
- Advisory work, where the code stays with your own team
Identity and access
- Keycloak
- Auth0
- OIDC
- Terraform
We move user bases between Keycloak and Auth0, and rebuild the access model underneath when roles alone have stopped being enough.
Most identity work is not a greenfield build. There is a live user base, a deadline that belongs to someone else, and a team that already owns the system. We work inside that, with them.
- Custom extensions: authenticators, required actions, token mappers, storage providers
- Single sign-on for enterprise customers: SAML, OIDC, account linking
- Keycloak upgrades that cross several major versions at once
- Whether access belongs to the user, the resource, or the relationship between them
What we have built.
Order emails, turned into records an ERP will accept.
Dental industry, Germany
For a client in the dental industry in Germany, we built a retrieval-augmented platform in Node.js. Orders arrive as free text written by people, in no fixed format. What leaves is a record the ERP accepts, or nothing at all.
- Unstructured order email to ERP-compliant records
- Claude, Gemini and Mistral, routed per task
- Node.js, SigNoz
A Rails application, moved to Next.js on Supabase.
Logistics and transportation SaaS, Germany
For a logistics and transportation SaaS in Germany, we modernised a Ruby on Rails application to Next.js on Supabase. Access is enforced in the database with Row Level Security, and the platform issues ZUGFeRD invoices, the German e-invoicing standard.
- Ruby on Rails to Next.js on Supabase
- Row Level Security, enforced in the database
- ZUGFeRD e-invoicing
Three million accounts, thirty microservices.
Optical retail and omnichannel commerce, Germany
For an optical retail and omnichannel commerce group in Germany, we played a key role in migrating identity from Keycloak to Auth0. The Keycloak estate ran on Kubernetes and went from version 15 to version 24 along the way.
- Keycloak to Auth0, 3M+ users, 30+ microservices
- Keycloak on Kubernetes, v15 to v24
- Datadog, Pulumi, Terraform
When to bring us in.
AI systems
- When you know the feature works and need to know what it costs at volume.
- When the input is documents rather than a clean API.
- When a wrong answer has a consequence and something has to catch it.
Web platforms
- When a framework version is far enough behind that upgrading is a project.
- When the product has to start billing and nothing bills yet.
- When the marketing site and the application have drifted into two codebases.
Identity and access
- While the migration is still a plan, before the scope is fixed.
- When an upgrade crosses several major versions at once.
- When an agreement requires single sign-on you have not built yet.
How we work.
The first call.
You tell us about the system and the deadline. We say what we would do first, where we think the risk sits, and whether this is work for us. If it is a better fit somewhere else, we will say so then.
Who works on it.
Every engagement is led from the front by someone who has spent a career building production systems and keeping them running. Specialists join from a network we have delivered with before, when a project needs a skill the team does not have on hand. You are told who they are before the work starts, and you work with them directly.
Once we start.
We work in your repository and your pipeline rather than a parallel one, on top of whatever your stack already runs: Next.js applications, PayloadCMS content platforms and the language-model providers.
After launch.
We stay on and run what we built when that is what you want: version upgrades, dependency and security updates, and whatever the product needs next. The engagement is written to cover that period too.
Tell us what you are building.
Send a note or book a call, whichever suits you better. We answer in one or two business days.
Or call +359 877 277 640.