Skip to main content

Services

Engaged for one stage, or all five.

Every service below sits inside ExpediApp OS. Most clients start with one and extend once there is a reason to, rather than committing to a programme up front.

Discover

Discovery and product strategy

Before anything is built: how work actually flows, where decisions stall, and which opportunities justify software at all. Sometimes the honest answer is a small integration rather than a new product.

Typical outputs

  • Systems and process map
  • Prioritised opportunities
  • Technical feasibility assessment
  • Recommended sequence

Design

Product design and architecture

The experience people will use and the architecture underneath it, planned so that value arrives early rather than at the end of a long programme.

Typical outputs

  • User experience and flows
  • System architecture
  • Working prototype
  • Implementation plan

Build

Application engineering

Production software: web and mobile applications, internal platforms, and the integrations that connect them to what a business already runs.

Typical outputs

  • Web and mobile applications
  • Backend services and APIs
  • Integrations and automation
  • Deployment pipeline

Build

AI integration

AI applied to a specific, bounded task with a defined success condition and a human approval step where the consequence sits — rather than a general assistant attached to everything.

Typical outputs

  • Bounded task definition
  • Model and prompt configuration
  • Human approval workflow
  • Quality measurement

Design · Build

Modernization

A disposition for each capability — preserve, connect, modernise or replace — sequenced so the business keeps running while the estate changes underneath it.

Typical outputs

  • Capability-level dispositions
  • Migration sequence
  • Integration layer
  • Retirement plan

Secure

Security assurance

Independent assessment of what is running now, whoever built it, followed by remediation and verification. Detailed on its own page.

Typical outputs

  • Prioritised findings report
  • Remediation
  • Behavioral verification
  • Re-test on change
Full detail

Operate

Managed operation

Deployment, monitoring, governance and continuous improvement for systems that would otherwise be delivered and then left alone.

Typical outputs

  • Monitoring and alerting
  • Ongoing improvement
  • Governance
  • Portfolio visibility

Security engagement levels

The one service with a defined ladder.

Security assurance is scoped in tiers because the work is repeatable. Everything else is scoped per engagement.

  1. 01

    Security Snapshot

    A time-boxed independent assessment of one application, delivered as a prioritized findings report you own.

  2. 02

    Security Hardening Sprint

    We remediate the validated findings and provide before-and-after evidence for each one.

  3. 03

    Continuous Security Assurance

    Ongoing review as the application changes: dependency monitoring, deployment checks and regression testing.

  4. 04

    Enterprise Application Governance

    Portfolio-wide visibility for teams responsible for many internal, vendor-built or AI-assisted applications.

Commercials

How pricing works.

Engagements are scoped and priced per piece of work rather than published as packages. A single-form marketing site and a multi-tenant operational platform are not the same assessment, and a fixed price for both would only be accurate for one of them.

What we will do is give you a scope and a number before you commit, and tell you when we think the work is not worth doing.

Not sure which of these you need?

Describe the situation rather than the solution. Working out which stage you are actually at is part of the first conversation.