The work
Everything on this page is in production. The first two are client engagements, used by them daily. The rest we built and run ourselves — the workshop's job management, our own accounting ledger, the infrastructure underneath the portfolio.
We show both, labelled, because a buyer should discount our own products and can't do that if we blur the line. Building software you then have to operate for years is a different discipline from building it and handing it over, and it's the one that shapes how we work.
Data platform
One view of a wholesale business scattered across a dozen systems.
Client name withheld pending approval
A multi-tenant consolidation and reporting platform for a wholesale and retail group operating several separate inventory organisations. It pulls orders, stock, purchasing, financials and marketing spend out of the group's inventory, commerce, accounting and advertising systems into one normalised store, then serves it back as dashboards, scheduled reports, extracts, and a query surface their team asks questions of directly.
Analytics runs on DuckDB reading the operational database in place — no ETL, no second copy, no pipeline to fall behind. Some of what the business needed wasn't exposed by the upstream API at all, so that data is captured through a browser-automation sidecar. And the whole thing carries a data-quality layer checking six classes of defect on every sync, which exists because a subtle encoding bug in one upstream system's discount field had been quietly producing phantom negative revenue across thousands of orders — invisible for months because it mostly netted out, until a new year-on-year view isolated a single month. Finding that is the argument for the gates.
Engineering governance
Estate-scale posture and remediation, run across client codebases.
Client name withheld pending approval
Most engineering assurance stops at the project boundary. Watchtower is our engine for the layer above it: pointed at an organisation's whole repository estate, it builds a picture of delivery health across every repo at once — where the risk is, where work has gone quiet, where standards have drifted — and turns that into a remediation programme rather than a report that gets filed. We run it as an engagement, read-only where a client wants the assessment first, and in remediate mode where they want the backlog worked through.
Every signal — audit findings, policy-as-code checks, git delivery patterns, secret scanning, dependency advisories — is an adapter writing into one findings table, de-duplicated by fingerprint, so a new source inherits the whole remediation pipeline without new machinery behind it. From there a finding becomes a plan, gets reviewed by a second and independent model, dispatches to agents, and closes itself when the pull request verifies. Read-only versus remediate is a hard gate per engagement, because pointing autonomous agents at someone else's production repositories is not a thing to get casually right.
Cloud consulting
Monthly consulting reports, generated from fourteen data sources.
Our own product, sold to managed service providers, who use it to produce client-facing monthly reports. It connects to a client's cloud and SaaS estate, pulls the numbers, writes the commentary, and delivers a branded PDF.
Fourteen providers — AWS, Azure, Snowflake, dbt, Fivetran, Xero, GitHub, Terraform, GCP and more — behind one abstraction, with encrypted per-client credentials, period-scoped snapshots so historical reports don't change when the source data does, and 73 report sections that each generate their own commentary.
Manufacturing
The back office that runs a manufacturing workshop.
Quote to invoice for CNC and custom fabrication shops: contacts and deals, quoting, job tracking through configurable pipeline stages, time entries, shop-floor clock-in, costing, scheduling, and a customer portal.
The whole operating surface of a real business in one system, with a shop-floor kiosk, an iOS app for the owner, and accounting integration — and it runs our own workshop, which means every rough edge is one we feel before anyone else does.
Also running
Infrastructure
A self-hosted replacement for Terraform Cloud.
Workspace management, run lifecycle, versioned state storage, policy checks, VCS-triggered runs, a private module registry, and team access control — with a Terraform Cloud-compatible API so the standard CLI workflow just works.
Finance
A double-entry ledger that replaced our accounting software.
Self-hosted multi-tenant accounting: general ledger, bank reconciliation, accounts receivable and payable, GST returns, and depreciation registers. It runs the books for two New Zealand companies.
Data platform
A business context substrate over everything an organisation says and does.
Ingests organisational events — mail, chat, meetings, accounting, documents — into a layered data model, then extracts the entities, commitments and decisions buried in them and exposes the result to applications and AI agents.
Because they haven't said we can yet. Client names, and the numbers that go with them, are theirs to release — not ours to spend on our own marketing. Some engagements aren't on this page at all for the same reason. We're asking, and this page will say more when they say yes. In the meantime we're happy to arrange a reference call, and you'll get the same discretion when it's your project on someone else's portfolio.
It isn't a set of case studies. There are no delivery metrics here — no time-to-ship, no cost against a comparable quote, no rework rate — because publishing those without a named client behind them would be exactly the unfalsifiable marketing this whole site argues against. Ask, and we'll walk you through a real engagement properly.
Tell us what needs building and we'll tell you straight whether it's a fit.
Start a build