Services

What we do, in detail.

Every engagement starts with a 20-minute discovery call. You leave with a clear build or no-build recommendation before any money moves.

01

AI Integration

We wire AI into products, workflows, and customer systems where it makes a measurable difference. RAG over your data, agents for recurring decisions, evaluations before anything ships. The result is a feature your team can run, not a demo that ends up in a Figma folder. And because we do security research ourselves, every AI surface is also tested for prompt injection and data leakage.

What's included

  • RAG pipelines over your data sources
  • Agents for recurring decisions
  • Evaluations and guardrails before go-live
  • Prompt-injection and leakage tests for every AI surface
  • Handoff your team can run without us
02

Ops Automation

We build the connections between your systems: imports, syncs, schedules, event-driven jobs. The rules run in code, not in an inbox. When something breaks, you see it before your customer does. Every pipeline ships with retry logic, alerting, and docs your team can run without us.

What's included

  • CSV, API, and webhook pipelines
  • Scheduled and event-driven jobs
  • Retry logic and alerting from day one
  • Monitoring that alarms before it hurts
  • Monthly capacity for new bottlenecks
03

Supplier Data & Catalogs

Excel in, clean data out: we detect suppliers, products, and price lists automatically and load them into Shopware, Shopify, or your ERP. New suppliers in the same format join without code changes. At SØR, supplier onboarding went from hours to minutes. The same engine runs in production there today.

What's included

  • Automatic detection of supplier, format, and season
  • Normalization into a canonical data model
  • Per-supplier price and season logic
  • Import into Shopware, Shopify, or ERP
  • New suppliers without code changes
04

E-Invoicing Compliance

The German B2B e-invoice mandate is in force. We implement the generation and import of structured invoices, verify conformance, and deliver the evidence your auditor asks for. No manual formatting, no risk at audit time. Also relevant if you are an international company invoicing German B2B customers.

What's included

  • Generation and import of ZUGFeRD and XRechnung
  • Conformance checks against EN 16931
  • Integration with your ERP or billing
  • Evidence export for audits
06

AI Content Pipelines

We build pipelines that produce content: LinkedIn carousels from a brief, sourced scripts, rendered videos. Format rules and sourcing run in code, not in discipline. Three posts a week without a designer in the loop.

What's included

  • The brief as single source of truth
  • Validated output: PDF, PNG, paste-ready text
  • Every claim with a quote and a source
  • Scheduling hookup into your vault or CMS
07

Web & Product Builds

From support portal to comparison platform: we build web apps end to end, with auth, billing, CI/CD, and a deploy path your team can take over. Own products like Ticketeil and MoveKlar show what happens when one person ships the whole stack. Security review included: authz, secrets, egress.

What's included

  • Next.js + TypeScript, production-ready
  • Auth, Stripe, API integrations
  • CI/CD and deploy path included
  • Security review: authz, secrets, egress
08

Cybersecurity & Offensive Security

We test your APIs and infrastructure the way an attacker would: authz and IDOR testing, SSRF and egress audits, configuration reviews across every domain. Our own bug-bounty work produced acknowledged findings at Vercel and Exness: an SSRF that bypassed egress controls and leaked cloud-signed OIDC tokens (High), an account-enumeration oracle in a trading platform, and an infrastructure configuration exposure across 57 domains. That mindset goes into every review.

What's included

  • Security review of APIs, auth, and infrastructure
  • IDOR, SSRF, and egress audits
  • Configuration review across all domains and subdomains
  • Threat model and prioritized remediation plan
  • Bug-bounty-proven methodology, responsible disclosure

How we work

01

Discovery call

20 minutes. We look at your process together, and you leave with a clear recommendation: build or no build, and what it costs.

02

Fixed scope

Written scope, fixed price, defined outcome. No open-ended invoices.

03

Build & ship

Production delivery in your stack, with docs and a deploy path.

04

Handoff

Your team takes over. Optionally we stay on as a retainer for the next bottleneck.

Start with a discovery call

20 minutes, no deck, no commitment. You leave with a clear recommendation.