Web apps
We build and maintain custom web applications
CRMs, customer portals, ERP modules, dashboards and integrations between systems. Every code change is checked and scanned for vulnerabilities before it reaches your users.
Our stack
- Frontend
- React, Next.js, TypeScript, Tailwind CSS
- Backend & API
- Node.js (NestJS, Next.js), PHP (Laravel), Python (FastAPI, Django)
- Database
- PostgreSQL as the main database, Redis for caching and queues
- Infrastructure
- Docker, reverse proxy with automatic SSL/TLS, Cloudflare, S3-compatible storage
The service in detail
Every application starts with a specific job: organising your sales, giving your customers their own login, seeing your numbers on a dashboard or connecting programs that don't currently talk to each other. We choose the stack for each project, always on LTS versions that still receive security updates. If you later need a mobile app too, it will work with the same backend and the same database.
The applications we build run in Docker containers on our own platform, in data centres in the EU. Only the ports we need are open on the servers. Access is by SSH key only, and security updates are applied automatically. Cloudflare sits in front of every application, with a firewall (WAF) and protection against malicious bots. The platform's admin panel isn't public and requires 2FA.
We continuously monitor the libraries your application uses. A pull request opens automatically for every new version of a library, framework or Docker image. Small updates (patch and minor) are applied on their own once the tests pass. A developer reviews the major ones. We're alerted to known vulnerabilities (CVEs) in real time and patch them, starting with the most serious.
Why trust us
Checks before every release
Every build runs static analysis, checks for keys or passwords accidentally left in the code and scans the container image. If a critical vulnerability is found, the release doesn't go live.
The database isn't exposed to the internet
Each application's containers are isolated on a separate internal network. The database and internal services can't be reached from outside. API keys are stored encrypted on the platform, never in the code.
Every backup is checked
If a backup fails or doesn't run, we're alerted straight away. We run regular test restores, and once a month we store a copy on the backup server at our offices.
The code is yours
Your code, domain and accounts belong to you. We manage them, and you can have a full copy of the application whenever you ask.
How we work
Written proposal
We discuss what the application needs to do and which systems it will connect to. Before we write any code, you get a written proposal with costs and a timeline.
Code review on every change
The code lives in Git, with branch protection. No change reaches the live application until it has been code-reviewed and has passed the automated checks: lint, tests and build.
Zero-downtime releases
Each new release is deployed without stopping the application and has to pass health checks. If it doesn't respond correctly, the application rolls back to the previous release.
Monitoring
If the application goes down, uptime monitoring alerts us within seconds. Every error is reported to the team, showing where in the code it happened. We also monitor CPU, RAM and disk usage, plus SSL and domain expiry dates.
Frequently asked questions
How much does a custom web application cost?
There's no list price. The cost depends on what the application needs to do and how many systems it connects to. You'll see it in the written proposal, before any work starts.
Can the application have AI features?
Yes. We can add AI to your workflows, build a chatbot of your own or create tools that process your data automatically. We write these parts in Python, with FastAPI or Django, and connect them to the rest of the application.
How often do you take backups?
Every day for the database and every 6 hours for critical applications. Backups are encrypted and kept in S3-compatible storage, with version history and deletion protection. We back up files as well. For critical PostgreSQL databases, we can restore the data to a specific moment in time (point-in-time recovery).
Who maintains the application after handover?
Our technical team, on an annual support package. For web applications we recommend Ultimate, with a 24-hour response time and 20 hours of work a year. Only Ultimate includes phone and WhatsApp support, as well as 24/7 cover for critical incidents. On the other packages, you contact us by email.
What do you want your app to do?
Tell us in a few words what your business does and which software you use today. We'll explain how we'd build the application and what we'd need from you.
Get a free quote