Zone2

AI systems, web platforms, product development, identity and access. Engineering for startups and scale-ups across the DACH region and the EU.


What we do.

An engagement usually turns out to be more than one of these. If you can’t tell which one you need, that’s worth a call on its own.

  • AI systems

    • Claude
    • Gemini
    • Mistral
    • Node.js

    Most business processes have a step in the middle where somebody reads something, works out what it means, and decides what happens next: an order email that has to become an ERP record, for instance. A language model can do that step now, so the whole process can run without a person in it. We build those systems. The work is mostly in making them dependable enough to leave running.

  • Web platforms

    • Next.js
    • PayloadCMS
    • PostgreSQL
    • Stripe

    A web platform is the product your customers use and everything it needs to keep working: the application, content somebody has to be able to change without a deployment, the payments, and the place it all runs. Those four usually get built at different times by different people, so most of the job is getting them to work together.

  • Product development

    • TypeScript
    • React
    • Supabase
    • Kubernetes

    Sometimes a team is building well and needs more senior hands. Sometimes there’s nobody whose job it is to decide what gets built, because the CTO left and the replacement is months away. We do both, and they’re different jobs. Engineers who join your team work to your plan; an interim technical lead owns the plan and hands it back when the permanent hire arrives.

  • Identity and access

    • Keycloak
    • Auth0
    • OIDC
    • Terraform

    Identity means who’s logging in, and most companies get that from a provider like Keycloak or Auth0. Access means what they’re allowed to do once they’re in, and most companies build that themselves. Both stop fitting as a company grows: you change providers, a big customer arrives expecting to sign in with its own accounts, and a short list of roles stops describing who should see what.


What we’ve built.

  • Orders arrive as free text written by people, in no fixed format. What leaves is a record the ERP accepts, or nothing at all.

    • Unstructured order email to ERP-compliant records
    • Claude, Gemini and Mistral, routed per task
    • Node.js, SigNoz
  • A Rails application, moved to Next.js on Supabase.

    Logistics and transportation SaaS, Germany

    Moving the framework was the visible part of the job. Access control went out of the application and into the database at the same time, and the platform issues ZUGFeRD invoices, the German e-invoicing standard.

    • Ruby on Rails to Next.js on Supabase
    • Row Level Security, enforced in the database
    • ZUGFeRD e-invoicing
  • users
    3M+
    microservices
    30+

    Keycloak to Auth0.

    Optical retail and omnichannel commerce, Germany

    We worked on the migration alongside the client’s own engineers. Keycloak crossed nine major versions along the way.

    • Keycloak on Kubernetes, v15 to v24
    • Auth0 to AWS EventBridge, via Lambda
    • Datadog, Pulumi, Terraform

When to bring us in.

Most of a project’s cost gets decided during scoping, so the best time to call is before the scope is set.

AI systems

  • When you know the feature works and need to know what it costs at volume.
  • When the input is documents rather than a clean API.
  • When a wrong answer has a consequence and something has to catch it.

Web platforms

  • When a framework version is far enough behind that upgrading is a project.
  • When the product has to start billing and nothing bills yet.
  • When the marketing site and the application have drifted into two codebases.

Product development

  • When you’re choosing between hiring, promoting and bringing someone in.
  • When the roadmap has decisions on it that nobody currently owns.
  • When a team has grown past the way it was organised.

Identity and access

  • While the migration is still a plan.
  • When an upgrade crosses several major versions at once.
  • When an agreement requires single sign-on you haven’t built yet.

How we work.

The people who scope your project are the people who build it.

  • The first call.

    You tell us about the system and the deadline. We say what we’d do first and where we think the risk sits.

  • Who works on it.

    Every engagement is led by someone who’s spent a career building production systems and keeping them running. The engineers on it are senior, and chosen for that project. We tell you who they are before the work starts, and you work with them directly.

  • Once we start.

    We work in your repository and your pipeline, not a parallel one. What we bring goes on top of whatever your stack already runs.

  • After launch.

    We stay on and run what we built, when that’s what you want. Version upgrades, dependency and security updates, whatever the product needs next. The contract covers that period too.

Tell us what you’re building.

Send a note or book a call, whichever suits you better. We answer in one or two business days.

Or call +359 877 277 640.

A message commits you to nothing. By sending it you confirm you’ve read the privacy policy.