Core competencies
Four things, done properly.
We are a small firm and we act like one. These are the areas where we will put our own name on the result. Anything outside them, we will say so on the first call.
01
Custom software development
- NAICS 541511
- NAICS 541512
- PSC DA01
- PSC DA10
Applications built against a written specification, delivered with everything needed to maintain them without us.
Web applications, internal tools, and back office systems in TypeScript, Python, and Swift. Mobile where the work has to happen away from a desk.
Every project ships with the source, the build and deploy pipeline, an architecture document, and a runbook. If a client wants to take the work in house at the end of an engagement, that has to be possible without a transition contract. We have handed systems over that way and we would rather do it than hold a client hostage to our own documentation.
- Requirements capture and written specification before code
- Greenfield builds and recovery of stalled projects
- API design and integration with legacy systems of record
- Data migration from systems nobody has the password to
- Source, pipeline, and documentation transferred at close
02
Systems design and integration
- NAICS 541512
- NAICS 541611
- PSC DF01
- PSC DD01
Architecture for environments where the hard part is the seams between systems that were never meant to meet.
Most of the difficulty in an enterprise or agency system is not any one component. It is the record that has to move from a scheduling system built in 2004 to a reporting requirement written in 2024, without losing its provenance on the way.
We do assessment and current-state documentation first, because in about half the engagements we have taken on, the documented architecture and the running architecture were different systems. Then target design, migration sequencing, and the integration work itself.
- Current state assessment and architecture documentation
- Target architecture with a migration path that can be staged
- Integration across records, scheduling, billing, and reporting
- Vendor and build-versus-buy analysis with the math shown
- Program and technical management through delivery
03
Security engineering
- NAICS 541519
- NAICS 541512
- PSC DJ01
Security designed into the system while it is being built, and evidence an assessor will accept.
Retrofitting security before an assessment is the most expensive way to buy it. Access control that costs an afternoon during design costs a quarter once a system has real users and real data in it.
We do threat modeling during design, build audit logging that produces evidence rather than debugging output, and work the human layer, which is where small organizations actually get breached. Staff training against phishing, pretexting, and impersonation, written against how a specific team really works rather than a generic module.
- Threat modeling and security architecture during design
- Identity, access control, and least-privilege implementation
- Audit logging designed to satisfy an assessor, not just a developer
- Security assessment of existing systems, with findings ranked by exploitability
- Staff security programs: phishing, pretexting, impersonation
- Incident response and postmortem
04
Cloud and infrastructure
- NAICS 518210
- NAICS 541513
- PSC DH01
- PSC DC01
- PSC DB01
Infrastructure a small team can actually operate, defined in code, with the failure modes written down.
We migrate systems off hardware that is past its service life, and off cloud architectures that were designed for a scale the client never reached and are now costing them for the privilege.
The test we apply is whether the client can run it. An architecture that requires a dedicated platform team is the wrong architecture for an organization that does not have one, however good it looks in a diagram.
- Infrastructure as code, versioned alongside the application
- Migration from on-premises and from over-built cloud estates
- Cost analysis and rightsizing with the invoice as the measure
- Backup, restore, and disaster recovery that has been tested
- Monitoring and alerting tuned so alerts still mean something
Working set
What we actually use.
Listed so you can tell quickly whether we fit your environment. We are not going to claim expertise in everything, and a firm that lists forty technologies is telling you it has none.
- Languages
-
- TypeScript
- Python
- Swift
- Go
- SQL
- C#
- Platforms
-
- AWS
- Cloudflare
- Azure
- Linux
- Kubernetes
- Docker
- Data
-
- PostgreSQL
- SQLite
- Redis
- S3
- HL7 and FHIR interfaces
- Practice
-
- Infrastructure as code
- CI/CD
- Threat modeling
- Zero trust access
- Unity and AR/VR
Have a requirement in one of these areas?
Send the scope or the solicitation number. You will get a straight answer on fit within a day.