Skip to main content

Proof of delivery

Evidence, not adjectives.

One engagement documented in full, and an honest account of the wider portfolio. Client names and commercial terms stay confidential.

Documented engagement

What a completed engagement actually looks like.

This is our own production system. We publish it in full because it is the one engagement where we can show every detail without a client's confidentiality being involved.

Security assurance · internal

Hardening our own production intake system

  • Secure
  • Build
  • Operate

Business challenge

An internal RFP intake system had been running in production for months, collecting prospect contact details, company information and generated proposals. It worked. Its access model had never been independently reviewed, and the security posture was assumed from reading the code rather than tested against the running system.

System delivered

A full assessment followed by remediation of every validated finding, then verification of each fix against production. The work covered the session layer, the database access model, the write surface, response caching, the notification pipeline and failure visibility.

Technical scope

  • Next.js App Router middleware and route handlers
  • PostgreSQL row-level security and role privileges
  • HMAC-signed sessions (Web Crypto, edge-compatible)
  • Server-only service-role data access
  • Transactional email delivery
  • Forward-only database migrations

Operational outcome

  • Anonymous database privileges revoked; prospect data no longer reachable with the public key
  • Cookie-presence authentication replaced with signed, expiring sessions
  • API routes brought inside the protection they appeared to sit behind
  • Draft writes restricted to an explicit field allowlist
  • Repeated submissions no longer produce duplicate notifications
  • Document-generation failures surfaced to operators instead of being discarded

Current status

Deployed to production and verified.

Evidence available

  • Behavioral test suite covering each control
  • Before-and-after verification against the running system
  • Sanitized findings table (published on the Security page)
  • Forward-only migrations with documented rollback

Wider portfolio

The shape of the work behind that.

Delivery engagements across consumer, operational and field-facing software. What follows is the composition of that record — the kinds of systems and the sectors they were built for.

Operational and utility systems

Internal tools and utility products — the systems that carry recurring work rather than the ones customers see.

  • Utility
  • Manufacturing
  • Real Estate

Logistics and field operations

Applications used away from a desk: dispatch, tracking and on-site capture.

  • Transportation
  • Safety

Consumer and community products

Cross-platform products with public user bases, taken through app-store release.

  • Social
  • Leisure
  • Entertainment
  • Sports
  • Gaming

Commerce and hospitality

Customer-facing ordering, discovery and membership experiences.

  • Food & Beverage
  • Fashion

Media and publishing

Content delivery and subscriber-facing platforms.

  • News
  • Publication
Engagements delivered
28

plus 1 currently in development

Sectors
14

consumer through industrial

Delivery shape
29

included both an application and its backend

Individual client engagements are not published. Where a client has agreed, we can walk through the challenge, the architecture and the outcome directly — including reference conversations.

Want to see the detail behind a specific capability?

Tell us what you are evaluating and we will show the closest relevant work, with the client's permission where one is involved.