Services
Six practices that share one delivery standard: a written scope before we start, work you can review while it happens, and documentation you keep at the end. Engage one of them or all six.
Software built to be maintained.
Anyone can ship a first version. We write the version that still makes sense when someone else opens the repository eighteen months from now, and we hand you that repository.
Typical engagement, 4 to 16 weeks
Web platforms and portals
Customer portals, dashboards and internal tools that stay responsive, accessible and fast on real connections.
APIs and integrations
REST and GraphQL services, third-party integrations, payment and ERP connections, with versioning and clear contracts.
Automation
Scripts, jobs and internal workflows that remove the repetitive work your team is doing by hand today.
Legacy rescue
Inheriting an undocumented system: we map it, stabilise it, and give you the choice between refactor and rebuild, with the cost of each.
Secure code review
Line-level review of authentication, authorisation, input handling and dependency risk, against OWASP guidance.
Handover pack
Source, environment setup, architecture notes and deployment steps: enough for another engineer to take over cleanly.
Find it before someone else does.
Authorised, scoped and agreed in writing before any test begins. You get findings ranked by real business impact, not a raw scanner dump with 400 false positives.
Typical engagement, 1 to 4 weeks
Penetration testing
Web application, internal network and external perimeter testing under a signed authorisation and defined rules of engagement.
Security audit
Configuration, access rights, patch level and exposure review across servers, endpoints and cloud accounts.
Hardening
Baseline hardening for Linux and Windows servers, databases, and network devices, applied and documented rather than merely recommended.
Monitoring and detection
Centralised logging, alert rules that a human can actually respond to, and tuning so the noise does not bury the signal.
Incident response
Containment, forensic triage, clean-up and a written post-incident report with the changes that prevent a repeat.
Awareness training
Short, practical sessions for staff on phishing, passwords and data handling, measured with a follow-up test.
Networks that are designed, not accumulated.
Most office networks grew one switch at a time until nobody knows what is plugged in where. We document what exists, then redesign it into something segmented, resilient and drawable on one page.
Typical engagement, 2 to 8 weeks
Design and documentation
Topology, addressing plan, VLAN segmentation and an up to date diagram your team can actually read.
Routing and switching
Configuration and migration on Cisco, MikroTik and comparable platforms, with rollback planned in advance.
Firewalls and segmentation
Policy design that separates guests, staff, servers and management, so one compromised laptop is not the whole company.
Remote and site-to-site VPN
Encrypted access for branches and remote staff, with multi-factor authentication and per-role access.
Wireless design
Survey-based Wi-Fi planning, controller configuration and separate SSIDs for guest and corporate traffic.
Performance troubleshooting
Packet-level diagnosis of the complaints about slow connections that nobody has been able to close.
Servers you can rebuild from scratch.
If losing a server means losing a week, the setup is wrong. We provision infrastructure as repeatable configuration, monitor it from day one, and test the restore, not just the backup.
Typical engagement, 2 to 10 weeks
Linux server setup
Provisioning, hardening, web and database stacks, TLS, and sane user and permission management.
Containers and orchestration
Docker and Kubernetes environments sized to what you actually run, not to a conference slide.
CI/CD pipelines
Automated build, test and deploy with staged releases and a rollback that works under pressure.
Monitoring and alerting
Uptime, resource and application metrics with dashboards and alerts routed to the right person.
Backup and disaster recovery
Off-site, versioned, encrypted backups, plus a documented recovery drill so you know the real restore time.
Migration
Moving from shared hosting, an ageing server or one cloud to another, with a planned cutover window.
The IT department you do not have to hire.
For teams too small for in-house IT and too dependent on it to keep improvising. A fixed monthly scope, a named contact, and a response time written into the agreement.
Monthly retainer, rolling
Help desk
A single channel for staff issues, with tracked tickets and a response window you can hold us to.
Patch and update management
Scheduled updates for servers, endpoints and network devices, tested before they roll out widely.
Asset and licence tracking
An accurate inventory of what you own, what it runs, and when it needs renewing or replacing.
Account lifecycle
Joiner, mover and leaver processes so access is granted quickly and, more importantly, removed on time.
Vendor coordination
We talk to your ISP, hosting provider and software vendors so your team does not have to.
Quarterly review
A short report on incidents, risks and what should be budgeted next quarter, in plain language.
Policy that survives contact with reality.
A security policy nobody follows is worse than none, because it creates the illusion of control. We write rules that fit how your people actually work, then make them enforceable.
Typical engagement, 2 to 6 weeks
Security policy
Access control, acceptable use, data classification and incident procedure, short enough that people actually read it.
ISO 27001 readiness
Gap analysis against the standard, a prioritised remediation plan, and evidence collection before the auditor arrives.
Risk assessment
A register of what could realistically go wrong, what it would cost, and what reduces it most per unit of spend.
Access reviews
Periodic checks of who can reach what. This is the control that catches the accounts everyone forgot about.
Business continuity
Continuity and recovery planning with defined RTO and RPO targets, tested rather than filed.
Technology due diligence
An independent read on a system, a vendor or an acquisition target before you commit to it.
Three ways to work with us.
Fixed-scope project
A defined outcome, a fixed price and a delivery date. Best when the requirement is clear: a build, an audit, a migration.
Monthly retainer
An agreed block of hours each month across any of our services. Best for ongoing development, support and steady improvement.
Advisory
Senior input without full delivery: architecture review, second opinion, or oversight of another vendor's work.
Not sure which service you need?
Describe the problem in your own words. If it is not something we should take on, we will say so, and point you at who should.