What we build with
and what we run.
A deliberately compact stack of established open source technologies. Nothing you won't find developers for in three years — and nothing that ties you to one provider.
- Open source first
- Managed services only with open standards (e.g. PostgreSQL)
- Portable between providers
- Skills available long-term

Development
The application layer: backend, frontend, data and interfaces. Lime marks what we use by default — the rest comes in depending on the project or in existing systems.
backend
- Kotlin
- Spring Boot
- Java
- Node.js
- NestJS
- Go
Kotlin and Spring Boot are our standard for business-critical services — type-safe, mature and backed by the entire JVM ecosystem. Java in existing systems, Node and Go where they fit the job.
frontend
- React
- TypeScript
- Next.js
- Tailwind CSS
- Ant Design
- Electron
React with TypeScript for web interfaces, Next.js where server rendering or SEO matters, Tailwind CSS for styling. Ant Design as the component base in data-heavy applications, Electron for desktop clients.
data
- PostgreSQL
- Redis
- REST
- GraphQL
- OpenAPI
PostgreSQL as a reliable foundation for relational data, Redis for caching and queues. We deliver interfaces as REST or GraphQL — matched to what the connecting system needs. Every API is documented as an OpenAPI specification so your team or a third party can integrate it without asking.
integration
- REST & APIs
- ERP & inventory
- CRM
- Payment providers
- Government interfaces
- Legacy systems
The work is rarely in the technology; it's in understanding the other system. We work our way into existing interfaces — including ones without usable documentation.
workflows
- Temporal
- Saga pattern
- Retry & timeout
- Event-driven
Long-running business processes across several systems — approvals, billing runs, synchronisation with third-party systems. Temporal records the state, retries failed steps automatically and makes every run traceable instead of hiding it in cron jobs and status columns.
identity & access
- Keycloak
- OIDC & SAML
- 2FA
- ID Austria
- Entra ID
- ADFS
Login, single sign-on and permissions centralised in Keycloak — with custom extensions where the standard isn't enough, and sign-in with existing accounts.
Operations & sovereign cloud
The infrastructure layer: platform, delivery, monitoring and security. All on European infrastructure with data stored in Austria or the EU.
infrastructure
- Kubernetes
- Exoscale
- Pulumi
Containerised workloads on Kubernetes, run on Exoscale with data centres in Vienna. The entire infrastructure is described as code — reproducible, versioned, traceable.
delivery
- ArgoCD
- GitOps
- CI/CD pipelines
- Infrastructure as code
Git is the source of truth: changes go through pull requests, ArgoCD pulls them into the cluster automatically. Every deployment is traceable and can be rolled back.
observability
- Grafana
- OpenTelemetry
- Prometheus
- Loki
- Tempo
Metrics, logs and traces in one interface — including alerting. That's not just a convenience for operations: it's what makes it possible to detect incidents within reporting deadlines at all.
security & data
- Automatic backups
- Encryption
- Access control
- Restore tests
- Security audits
Backup and restore procedures are tested, not just set up; how often is agreed with you. Security audits and penetration tests are done by Certitude Consulting if needed.
How the layers work together
For us, development and operations aren't two offerings but one continuous stack. That's why there are no gaps in responsibility between application and infrastructure.
- One team responsible from application to infrastructure
- Every layer containerised and therefore portable
- No proprietary managed services as the foundation
- Moving to another provider possible without a rewrite
- The same tools across all projects — no knowledge silos
Why this matters to you
When application and operations come from a single team, there's no discussion about whether a problem lies in the code or the infrastructure. There's one contact — and they fix it.
How we choose technologies
A stack is a bet on the next ten years. That's why we decide conservatively — and justify every exception.
Proven, not trendy
We use what has been running in production for years and has a solid community. Frameworks that change their architecture every eighteen months cost you more later than they save at the start.
Available skills
You'll find developers for Kotlin, Java, TypeScript and Kubernetes — today and in five years. That's crucial if you want to take over or extend a project internally later.
No lock-in as the foundation
Proprietary managed services are convenient and make switching providers expensive. We build on portable open source components so that moving stays a decision and doesn't become a project.
One stack across all projects
We deliberately work with the same tools. That makes maintenance, handovers and covering for each other possible — instead of running a one-off setup for every project.
Built to be run
When we choose a technology, we think about who will have to run it later. If we can't monitor, back up and update it properly, it doesn't go into production.
Open to what's already there
If something is already running at your company, we assess it instead of replacing it by reflex. Modernising in steps is usually cheaper and less risky than rebuilding.
How we work with AI
AI tools are part of our everyday development — as a tool, not as a replacement for understanding. Fixed rules apply:
Every line is reviewed
Whatever a tool suggests is read and understood by a person before it goes into the repository. Code that nobody on the team can explain doesn't get merged.
Tests, not trust
Generated code goes through the same automated tests, reviews and pipelines as any other. Written faster doesn't mean checked less.
Responsibility stays with us
We stand behind quality, security and maintainability — no matter which tool a line was written with.
Your data stays out
We don't give production data or personal data to AI tools. Whether your code may be worked on with AI assistance is something we agree with you up front.
The stack in production
A SaaS platform for the healthcare sector — built and run on exactly this stack, GDPR compliant with data stored in Austria.
- kotlin · spring boot
- react · electron
- kubernetes · exoscale
- argocd · prometheus
Frequently asked questions about the stack
Can we specify technologies?
Yes, as long as we can take responsibility for them. If you already have a framework or database in house, we work with it. Where we see concerns for operations or maintainability, we say so beforehand — not after the launch.
Why Kotlin and not the latest framework?
Because business-critical software runs for ten years, not two. Kotlin is type-safe, has the JVM ecosystem behind it and you'll find developers for it in the long run. We pick technology that lasts, not whatever is newest.
Does the stack fit our existing frontend?
Usually yes. We deliver the API and stick to the interface your frontend or CMS needs — whether React, Vue, a shop system or something custom.
Are we tied to Exoscale?
No. The stack is containerised and described as infrastructure as code so that switching providers remains feasible. We recommend Exoscale for data residency in Vienna and GDPR compliance — not because moving would be technically impossible.
Can we run it ourselves later?
Yes. We hand over architecture, operating processes and documentation completely and support the knowledge transfer. That's exactly why we rely on widely used open source tools instead of home-grown ones.
Does this fit what you're planning?
If you want to know whether our stack fits your project or your existing landscape: we'll go through it in detail in a call — technical, without buzzwords.
For existing systems too: we assess what stays and what should be replaced.