What we do · 02 · Technology & Intelligence

Software, AI agents and cloud, built securely and supported.

Websites, apps, custom software, AI agents and cloud, built securely and supported after launch.

Capabilities
10
Scope
Strategy to support
Delivery
AI-assisted

An illustrative diagram of your platform in four layers: Experience (Websites & Apps, Search & AI Visibility); Intelligence (AI Strategy & Agents, AI Product & Automation); Platform & data (Custom Software & Data Platforms, AI Infrastructure & Cloud, Integration & Support); Trust & operations (Cybersecurity & AI Trust, Audits & Assessments, Tech Workforce). Requests move between the capabilities while a status bar shows 95th-percentile latency of 212 milliseconds, 148 of 148 evaluation cases passing, 71 percent of the error budget left and 0.18 grams of CO2e per request.

Why now

Software, data and AI now have to stay fast, secure and affordable every day.

Four changes drive this: AI inside products, models that change every month, AI answers in search and stricter security and privacy law. Each card names a public source you can check.

These figures describe the market; none is a claim about our own results.

A data-centre aisle lined with rack servers Where your software runsYour cloud account and region, monitored at every layer
  1. Then: A pilot. Now: In the product.

    LLM01

    Prompt injection, first on the list

    AI inside the product

    AI features and agents now sit in customer journeys, where they fail in ways ordinary testing does not catch.

    What we do about it

    We test AI features on your own examples, add automatic checks and have a named person approve each release.

    04AI Product

    Source · OWASP Top 10 for LLM Applications, 2025

  2. Then: ~4k tokens. Now: 1M+ tokens.

    1M+

    Tokens of context, up from about 4k

    Models change every month

    Context limits, prices and rankings move faster than release plans, so testing must run on every change.

    What we do about it

    We call every model through one gateway, so switching model needs no rebuild.

    03AI Strategy

    Source · Provider model documentation, 2023–2025

  3. Then: 10 blue links. Now: 1 cited answer.

    10 → 1

    Ten blue links became one answer, citing a few sources

    AI answers in search

    AI Overviews, ChatGPT search and Perplexity answer directly and cite a few sources; being cited takes technical work.

    What we do about it

    We make pages easy to quote and report AI citations beside rankings and revenue each month.

    08Search

    Source · Google, OpenAI and Perplexity product pages

  4. Then: Annual audit. Now: Hours to report.

    6 h

    To report a cyber incident in India

    Security and privacy law

    The DPDP Act 2023, the EU AI Act and CERT-In's six-hour incident rule make security, privacy and AI governance part of delivery.

    What we do about it

    We build consent checks, AI labels, security testing and audit logs into the work, so evidence exists at release.

    06Security

    Source · CERT-In Directions, 28 April 2022

How it works

Your platform in four layers we build and run.

Each of the ten capabilities builds one or more layers. Pick a layer to see which, or follow one customer question through all four.

An architecture diagram in four layers. Experience: website and web app, mobile app, support chat, search and AI answers. Intelligence: support agent, retrieval, workflow automation, evals. Platform and data: custom apps and CRM, customer data, integration bus, AI gateway, GPU and serverless compute. Trust and operations runs alongside every layer: security and guardrails, observability, audits and the on-call squad. The steps below trace one request through it.

Builds the whole platform

Ten capability pages, four layers

Our default core technologies

  • Kubernetes
  • Terraform
  • PostgreSQL
  • Apache Kafka
  • OpenTelemetry

AI models · behind the gateway, swappable

  • OpenAI
  • Anthropic
  • Google Gemini
  • Meta Llama
  • Mistral AI

L1 · built by 2 capabilities

Experience

What customers see: websites, mobile apps, chat, search and AI answers.

L2 · built by 2 capabilities

Intelligence

AI agents, answers from your documents and automated workflows inside the product.

L3 · built by 3 capabilities

Platform & data

Custom apps and CRM, customer data, integrations, the AI gateway and cloud computing.

L4 · built by 3 capabilities

Trust & operations

Security, audits, monitoring and the on-call team, across every layer.

One request, step by step Illustrative

  1. 01 A customer asks the support assistant on the website. 0 ms
  2. 02 The AI gateway routes the question to a small model first. 38 ms
  3. 03 Retrieval reads the customer profile from the CDP through the integration bus. 96 ms
  4. 04 Guardrails check the draft answer before it leaves. 131 ms
  5. 05 The answer streams back and the trace lands in observability. 212 ms
  6. 06 Audits sample traces like this one every month. sampled
  7. 07 The squad on call owns it when anything drifts. owned

Sample plans

Five common goals, each with a typical plan.

Choose a goal to see the capabilities, build order, phases, team and quality checks we would typically plan, and what we would measure in the first 90 days.

Platform Composer · Your company · draft plan Plan ready Typical ranges

Plan: Launch an AI support assistant · 6 phases · 12 weeks · 6 capabilities

Architecture · capabilities involved6 of 10

The capabilities involved in the selected plan are highlighted on the platform map and numbered in build order.

Plan 1 of 5 · typical

Launch an AI support assistant

Answers customer questions from your own knowledge and records, hands off to people when unsure.

Weeks
12
Phases
6
Capabilities
6
  1. 03 Use-case & risk assessmentAI Strategy Wk 1–2
  2. 02 Knowledge & CRM data readyPlatforms Wk 2–4
  3. 04 RAG assistant with evalsAI Product Wk 3–8
  4. 05 Gateway, caching & cost capsAI Infrastructure Wk 6–9
  5. 06 Red-team & OWASP LLM Top 10 reviewSecurity Wk 7–8
  6. 07 Human handoff & ongoing supportIntegration Wk 9–12 →

Team

  • AI lead
  • Product designer
  • 2 × AI engineers
  • Data engineer
  • Security engineer
  • Your support-operations lead

Quality gates · must pass

  • Faithfulness ≥ 0.90 on the golden set
  • Zero critical red-team findings
  • p95 < 2.5 s, first token < 800 ms
  • Handoff to a person on low confidence

First 90 days · we measure

  1. 01Containment rate
  2. 02Cost per resolved conversation
  3. 03CSAT on assisted conversations

Frameworks this plan aligns with

  • OWASP Top 10 for LLM Applications — Security risks in generative AI applications
  • NIST AI RMF 1.0 — AI Risk Management Framework
  • ISO/IEC 42001:2023 — Artificial intelligence management systems
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023

Plan 2 of 5 · typical

Replace a legacy CRM

One customer record your sales and service teams trust, migrated without losing a quarter.

Weeks
18
Phases
6
Capabilities
6
  1. 09 Data & process auditAudits Wk 1–3
  2. 02 Data model & CRM buildPlatforms Wk 3–14
  3. 01 Sales & service interfaceWeb & Apps Wk 5–14
  4. 07 ERP, email & telephony integrationsIntegration Wk 6–14
  5. 06 SSO, access model & audit loggingSecurity Wk 8–12
  6. 10 Cutover squad & hypercareWorkforce Wk 14–18

Team

  • Solution architect
  • 3 × full-stack engineers
  • Data engineer
  • Integration engineer
  • QA engineer
  • Your sales-operations owner

Quality gates · must pass

  • 100% row-level reconciliation of migrated records
  • Two parallel-run cycles, zero P1 defects
  • Role-based access reviewed and signed off
  • Rollback rehearsed before cutover

First 90 days · we measure

  1. 01Time from lead to quote
  2. 02Duplicate record rate
  3. 03Weekly active users

Frameworks this plan aligns with

  • ISO/IEC 27001:2022 — Information security management systems
  • SOC 2 — Trust Services Criteria
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • OWASP ASVS — Application Security Verification Standard

Plan 3 of 5 · typical

Make the product fast on real phones

Good Core Web Vitals in the field, on the mid-range Android phones most customers actually carry.

Weeks
10
Phases
6
Capabilities
5
  1. 09 Field-data performance auditAudits Wk 1–2
  2. 01 Image, font & JavaScript budgetsWeb & Apps Wk 2–6
  3. 05 Edge caching & CDN rulesAI Infrastructure Wk 3–6
  4. 01 Render path & hydration fixesWeb & Apps Wk 4–9
  5. 08 Template-level search checksSearch Wk 6–9
  6. 07 Budgets in CI & real-user monitoringIntegration Wk 8–10 →

Team

  • Performance lead
  • 2 × frontend engineers
  • Platform engineer
  • Search specialist

Quality gates · must pass

  • LCP ≤ 2.5 s at p75, field data
  • INP ≤ 200 ms at p75
  • CLS ≤ 0.1 at p75
  • JavaScript budget enforced on every merge

First 90 days · we measure

  1. 01p75 LCP on low-end Android
  2. 02Mobile conversion rate
  3. 03Organic sessions on mobile

Frameworks this plan aligns with

  • Core Web Vitals — Loading, interactivity and visual stability
  • WCAG 2.2 AA — Web Content Accessibility Guidelines
  • SCI · ISO/IEC 21031:2024 — Software Carbon Intensity

Plan 4 of 5 · typical

Get cited in AI answers

Your pages ranked on Google and quoted by AI Overviews, ChatGPT and Perplexity for the questions buyers ask.

Weeks
12
Phases
6
Capabilities
5
  1. 09 Search & answer visibility auditAudits Wk 1–2
  2. 08 Entity & prompt mapSearch Wk 2–4
  3. 01 Technical SEO & structured dataWeb & Apps Wk 3–7
  4. 08 Answer-ready content systemSearch Wk 4–12
  5. 02 Product & knowledge data feedsPlatforms Wk 5–9
  6. 07 Prompt-panel tracking & reportingIntegration Wk 8–12 →

Team

  • Search lead
  • Content strategist
  • Technical SEO engineer
  • Data engineer
  • Analyst

Quality gates · must pass

  • Valid structured data on every key template
  • Core Web Vitals good at p75
  • Facts consistent across site, feeds and profiles
  • Prompt-panel baseline recorded before changes

First 90 days · we measure

  1. 01Share of answer across a fixed prompt panel
  2. 02Citations per engine
  3. 03Organic and AI-referred conversions

Frameworks this plan aligns with

  • Core Web Vitals — Loading, interactivity and visual stability
  • WCAG 2.2 AA — Web Content Accessibility Guidelines
  • GDPR — General Data Protection Regulation (EU) 2016/679

Plan 5 of 5 · typical

Stand up an embedded AI squad

Vetted AI engineers inside your sprints, shipping a first feature to production with evals from day one.

Weeks
12
Phases
6
Capabilities
5
  1. 10 Role profiles & squad matchWorkforce Wk 1–2
  2. 03 Use-case backlog & prioritiesAI Strategy Wk 1–3
  3. 06 Access, data handling & AI policySecurity Wk 2–3
  4. 10 Onboarding into your sprintsWorkforce Wk 3–4
  5. 04 First AI feature in productionAI Product Wk 4–10
  6. 09 Quarterly delivery & AI-readiness reviewAudits Wk 12 →

Team

  • Squad lead
  • 2 × AI engineers
  • ML & data engineer
  • QA engineer, eval focus
  • Your product owner

Quality gates · must pass

  • Background checks and NDAs complete
  • Least-privilege access in your tools
  • Eval suite in CI before the first release
  • DORA metrics reported from sprint 1

First 90 days · we measure

  1. 01Lead time for changes
  2. 02Change failure rate
  3. 03AI features shipped per quarter

Frameworks this plan aligns with

  • ISO/IEC 27001:2022 — Information security management systems
  • ISO/IEC 42001:2023 — Artificial intelligence management systems
  • DORA metrics — Software delivery performance

Plans show typical phases and lengths and are not a quote. We scope every engagement with your team before work starts.

Tech stack

The technology we work with, by layer.

174 technologies across 18 layers, from languages to collaboration tools. We are tied to no single model or cloud: each choice is made per task on evidence and revisited when the evidence changes.

Technologies we work with. No partner, reseller or certification tier is implied by any mark on this page.

Layer

174 technologies · 18 layers

In all eighteen layers, each choice is made per engagement on evidence, written up in an architecture decision record and kept reversible.

Use the arrow keys to move between technologies; the selected technology is described in the panel beside the wall.

TypeScript Typed front ends and Node services JavaScript The browser and everything that runs in it Python AI, data pipelines and fast back ends Go High-throughput services and CLIs Rust Performance-critical components and WebAssembly Kotlin Android apps and JVM services Swift iOS and iPadOS apps PHP Content sites and mature web platforms Java Enterprise back ends on the JVM .NET Enterprise back ends on Windows and Linux Node.js API servers, workers and tooling
React Interactive product interfaces Next.js Server-rendered React sites and apps Vue.js Progressive interfaces on existing sites Angular Large internal applications with strict structure Svelte Lightweight embedded widgets and dashboards Astro Content-heavy sites with minimal JavaScript Tailwind CSS Token-driven styling at speed Three.js 3D views and product configurators in the browser WebAssembly Near-native compute in the browser
Flutter One codebase for iOS and Android React Native Mobile apps that share logic with React web Expo Faster React Native builds, updates and releases iOS Native Apple platform features Android Native Android platform features Jetpack Compose Modern native Android interfaces
NestJS Structured TypeScript APIs FastAPI Python APIs that serve models and data Django Admin-heavy platforms with a mature ORM Laravel PHP platforms with a rich ecosystem Spring Boot JVM services in enterprise environments GraphQL One typed API over many back ends OpenAPI Initiative API contracts that generate clients and tests Redis Caching, rate limits and queues RabbitMQ Reliable work queues between services Temporal Durable workflows that survive failures Supabase Postgres, auth and storage for fast starts Firebase Mobile back ends, push and analytics
PostgreSQL The default system of record MongoDB Document stores for flexible schemas Snowflake Cloud warehouse for analytics at scale Databricks Lakehouse for data engineering and ML Apache Spark Distributed batch and stream processing Apache Kafka The event backbone between systems Apache Airflow Scheduled data pipelines with lineage dbt Tested, versioned transformations in the warehouse ClickHouse Sub-second analytics on event data Elasticsearch Full-text search and log analytics Google BigQuery Serverless warehouse on Google Cloud DuckDB Fast local analytics inside pipelines Airbyte Connectors that move data into the warehouse Looker Governed metrics and dashboards Power BI Reporting inside Microsoft estates
PyTorch Training and fine-tuning models TensorFlow Production ML in Google-centred stacks Hugging Face Open models, datasets and tokenisers scikit-learn Classical ML: forecasting, scoring, clustering NVIDIA GPU compute for training and inference MLflow Experiment tracking and model registry vLLM High-throughput serving for open models Ray Distributed training and batch inference ONNX Portable models across runtimes Jupyter Exploration and reproducible analysis
OpenAI Frontier models behind the gateway Anthropic Frontier models for long-context and agent work Google Gemini Multimodal models and Google Cloud integration Mistral AI Efficient open-weight and hosted models Meta Llama Open-weight Llama models run in your cloud DeepSeek Open-weight reasoning models, self-hosted Ollama Local models for development and offline use Perplexity Search-grounded answers and citation tracking
LangChain Chains, tools and integrations for LLM apps LangGraph Stateful agents with checkpoints and approvals LlamaIndex Document ingestion and retrieval pipelines Pinecone Managed vector search at scale Weaviate Hybrid vector and keyword search Qdrant Self-hosted vector search with filtering Milvus Vector search for very large collections pgvector Vectors inside Postgres, no new database Replicate Hosted open models by API Modal Serverless GPUs for batch and bursty inference GitHub Copilot AI pair programming in the IDE Cursor AI-native code editing with review
AWS Primary cloud for most regulated workloads Microsoft Azure Cloud for Microsoft-centred estates Google Cloud Cloud for data- and AI-heavy platforms Cloudflare Edge, DNS, WAF and bot management Vercel Hosting for Next.js front ends Netlify Hosting for static and Jamstack sites DigitalOcean Simple cloud for smaller workloads Fastly Edge caching and compute Akamai Global delivery and edge security
Docker Reproducible builds and local environments Kubernetes Orchestration for services and model serving Helm Packaged Kubernetes deployments Terraform Infrastructure as code across clouds Pulumi Infrastructure as code in TypeScript or Python Ansible Configuration for hosts and appliances Argo GitOps delivery and workflow pipelines GitHub Actions CI pipelines with evals and scans GitHub Source, reviews and the audit trail GitLab Source and CI in self-hosted estates Jenkins CI in established enterprise pipelines Istio Service mesh for mTLS and traffic policy
OpenTelemetry Traces, metrics and logs on an open standard Prometheus Metrics and alerting for services Grafana SLO dashboards for engineering and leadership Datadog Managed observability across cloud estates Sentry Error tracking in front ends and apps New Relic APM in established enterprise stacks Elastic Log analytics and security events PagerDuty On-call rotation and incident response
Playwright End-to-end tests in real browsers Cypress Component and end-to-end tests Selenium Cross-browser tests in legacy suites Jest Unit tests for JavaScript and TypeScript k6 Load tests before every launch Postman API contract tests and collections SonarQube Code quality and security gates in CI
Okta Enterprise SSO and identity Auth0 Customer identity and access OpenID Standard sign-in across systems JWT Signed tokens between services Vault Secrets management and dynamic credentials Snyk Dependency and container vulnerability scanning Trivy Image, IaC and SBOM scanning in CI Falco Runtime threat detection on Kubernetes OWASP ASVS, Top 10 and LLM Top 10 as the test bar Burp Suite Manual penetration testing 1Password Shared secrets for teams, never in chat
Zapier Quick automations between SaaS tools Make Visual automations with branching logic n8n Self-hosted workflow automation with AI steps MuleSoft Enterprise integration platform Kong API gateway, auth and rate limiting Twilio SMS, voice and verification WhatsApp Customer conversations on WhatsApp Business Slack Alerts, approvals and copilots where teams work Microsoft Teams Approvals and bots inside Microsoft 365
Salesforce CRM integrations and custom objects HubSpot CRM and marketing automation Zoho CRM and operations suites for the mid-market SAP ERP integration for orders, stock and finance Shopify Commerce storefronts and headless builds WooCommerce Commerce on WordPress Stripe Payments, billing and subscriptions Razorpay Payments and UPI for India PayPal Global checkout and payouts Intercom Customer messaging and support inbox Zendesk Support desk integration and AI handoff
Google Search, Ads and Maps platform APIs Google Search Console Index coverage and query data Google Analytics Traffic, conversion and attribution Google Tag Manager Consent-aware tag management PageSpeed Insights Field and lab Core Web Vitals Lighthouse Performance and accessibility audits in CI Semrush Keyword and competitor research Ahrefs Backlinks and content gaps Algolia Site and product search PostHog Product analytics, flags and session replay Mixpanel Product analytics and funnels Schema.org Structured data machines can cite
WordPress Content sites and editorial teams Contentful Headless content across many surfaces Sanity Structured content with live preview Strapi Self-hosted headless CMS Webflow Marketing sites teams edit themselves
Figma Design source of truth and tokens Storybook Component library and visual tests Jira Delivery tracking in enterprise teams Confluence Runbooks and decision records Linear Fast issue tracking for product squads Notion Docs and lightweight planning Miro Architecture and workshop whiteboards

Standards & frameworks

Frameworks we build to.

We build to these frameworks, so the work itself produces the evidence an auditor asks for. The badges are our own drawings; none is an official seal.

A hand ticking items on a handwritten checklist in a notebook
Evidence for auditorsEach control is ticked off against what an auditor will ask to see.Photo: Jakub Żerdzicki / Unsplash

Choose a framework to see what it governs, how it shows up in delivery and which capability pages apply it. The details appear in the panel after the list.

01Security & privacy14 frameworks

02AI governance5 frameworks

03Quality & accessibility3 frameworks

04Sustainability & operations4 frameworks

We also use these without a badge: ISO/IEC 25010 quality characteristics in our definitions of done; the NIST AI 600-1 generative-AI profile alongside the AI RMF; and the FinOps Framework for cloud cost reviews. The OWASP Top 10 for LLM Applications entry follows the 2025 list.

Alignment describes how we work. It does not mean Xterra Edze holds a certification. ISO 9001 and ISO 14001 are management systems for whole organisations; we follow their practices in delivery. Certifications held by Xterra Edze itself: to be confirmed before launch.

Framework1 / 26

Security & privacy · Standard

ISO/IEC 27001:2022

Information security management systems · ISO / IEC

What it governs

Requirements for an information security management system: risk assessment and treatment, with 93 Annex A controls across organisational, people, physical and technological themes.

How it shows up in delivery

Access reviews, change control, supplier risk and logging are built into delivery, so the evidence exists as the work is delivered.

Security & privacy · Attestation framework

SOC 2

Trust Services Criteria · AICPA

What it governs

Controls for security, availability, processing integrity, confidentiality and privacy. Type I tests design at a point in time; Type II tests operation over a period.

How it shows up in delivery

Change approvals, access logs and incident records captured automatically, ready for your auditor.

Security & privacy · Framework

NIST CSF 2.0

Cybersecurity Framework · NIST

What it governs

Six functions for managing cybersecurity risk: Govern, Identify, Protect, Detect, Respond and Recover.

How it shows up in delivery

Current and target profiles that turn security posture into a prioritised, costed roadmap.

Security & privacy · Framework

CIS Controls v8.1

Critical Security Controls and Benchmarks · Center for Internet Security

What it governs

Prioritised safeguards grouped into implementation groups, plus hardening benchmarks for cloud, container and operating-system configurations.

How it shows up in delivery

Cloud accounts, clusters and images hardened to CIS Benchmarks and scanned continuously for unapproved changes.

Security & privacy · Standard

OWASP ASVS

Application Security Verification Standard · OWASP

What it governs

Testable security requirements for web applications and APIs, organised in three verification levels by risk.

How it shows up in delivery

Security requirements written as acceptance criteria at the level your risk profile needs, and verified in CI.

Security & privacy · Awareness standard

OWASP Top 10

Web application security risks · OWASP

What it governs

The most critical web application risks, from broken access control and injection to security misconfiguration.

How it shows up in delivery

Threat-modelled at design, scanned on every merge and tested manually before release.

Security & privacy · Framework

SLSA

Supply-chain Levels for Software Artifacts · OpenSSF

What it governs

Levels of assurance for how software artifacts are built, with verifiable build provenance.

How it shows up in delivery

Signed builds, provenance attestations and an SBOM in SPDX or CycloneDX for every release.

Security & privacy · Standard

PCI DSS v4.0.1

Payment Card Industry Data Security Standard · PCI Security Standards Council

What it governs

Twelve requirements for protecting cardholder data wherever it is stored, processed or transmitted.

How it shows up in delivery

Scope reduced first, with tokenised payments and segmented networks, then controls built for what remains.

Security & privacy · Regulation

HIPAA Security Rule

Safeguards for electronic protected health information · US HHS

What it governs

Administrative, physical and technical safeguards for electronic protected health information (ePHI).

How it shows up in delivery

Access control, audit trails and encryption for ePHI, with business associate agreements for every processor.

Security & privacy · Regulation

GDPR

General Data Protection Regulation (EU) 2016/679 · European Union

What it governs

Lawful basis, data-subject rights, data protection by design and by default, breach notification and DPIAs for high-risk processing.

How it shows up in delivery

Consent, retention and data-subject request flows designed into the product, with DPIAs where the risk calls for one.

Security & privacy · Law

DPDP Act 2023

Digital Personal Data Protection Act, 2023 · Government of India

What it governs

Notice and consent, duties of data fiduciaries, rights of data principals, breach intimation and added duties for significant data fiduciaries, with the DPDP Rules.

How it shows up in delivery

Consent records, notices and data-principal request handling built for India-based users from the first release.

Security & privacy · Standard

ISO/IEC 27701

Privacy information management systems · ISO / IEC

What it governs

Requirements and guidance for managing personally identifiable information as a controller or processor.

How it shows up in delivery

Data maps, retention rules and processor records kept alongside the systems that hold personal data.

Security & privacy · Regulation

CERT-In Directions 2022

Cyber incident reporting directions · CERT-In, Government of India

What it governs

Reporting of specified cyber incidents within six hours, log retention for 180 days within India and clock synchronisation.

How it shows up in delivery

Incident runbooks, log retention and time synchronisation configured so reporting deadlines can be met.

Security & privacy · Directive

NIS2

Network and Information Security Directive (EU) 2022/2555 · European Union

What it governs

Cybersecurity risk-management measures, supply-chain security and staged incident reporting for essential and important entities.

How it shows up in delivery

Risk measures and incident reporting stages mapped to the services we build and run for in-scope clients.

AI governance · Standard

ISO/IEC 42001:2023

Artificial intelligence management systems · ISO / IEC

What it governs

Requirements for establishing, running and improving an AI management system: AI policy, impact assessment, data and lifecycle controls.

How it shows up in delivery

An AI inventory, impact assessments and lifecycle controls are part of how every model and agent is released.

AI governance · Framework

NIST AI RMF 1.0

AI Risk Management Framework · NIST

What it governs

Four functions for trustworthy AI: Govern, Map, Measure and Manage, with a companion profile for generative AI (NIST AI 600-1).

How it shows up in delivery

Risks mapped per use case, measured with evaluation sets and managed with named owners and release thresholds.

AI governance · Regulation

EU AI Act

Artificial Intelligence Act (EU) 2024/1689 · European Union

What it governs

A risk-based regime: prohibited practices, obligations for high-risk systems, transparency duties and rules for general-purpose AI models.

How it shows up in delivery

Each use case classified by risk tier early, with transparency notices, logging and human oversight designed in.

AI governance · Awareness standard

OWASP Top 10 for LLM Applications

Security risks in generative AI applications · OWASP GenAI Security Project

What it governs

Risks specific to applications built on AI models, including prompt injection (LLM01), sensitive information disclosure (LLM02), excessive agency (LLM06) and vector and embedding weaknesses (LLM08).

How it shows up in delivery

Red-team suites for prompt injection, data leakage and tool misuse run in CI before any model or agent release.

AI governance · Knowledge base

MITRE ATLAS

Adversarial Threat Landscape for AI Systems · MITRE

What it governs

Adversary tactics and techniques against machine-learning and AI systems, drawn from real attacks and red-team research.

How it shows up in delivery

Threat models for AI systems mapped to ATLAS techniques, then exercised in red-team tests.

Quality & accessibility · Standard

WCAG 2.2 AA

Web Content Accessibility Guidelines · W3C

What it governs

Perceivable, operable, understandable and robust content, including 2.2 criteria such as focus not obscured, target size and accessible authentication.

How it shows up in delivery

Automated checks in CI plus manual keyboard and screen-reader passes on every key journey.

Quality & accessibility · Metric set

Core Web Vitals

Loading, interactivity and visual stability · Google

What it governs

Good at the 75th percentile of page loads: LCP ≤ 2.5 s, INP ≤ 200 ms, CLS ≤ 0.1.

How it shows up in delivery

Performance budgets enforced in CI, with field data tracked at the 75th percentile for every template.

Quality & accessibility · Standard

ISO 9001:2015

Quality management systems · ISO

What it governs

Requirements for a quality management system built on process control, risk-based thinking and continual improvement.

How it shows up in delivery

Definitions of done, peer review and release checklists that make quality repeatable.

Sustainability & operations · Specification

SCI · ISO/IEC 21031:2024

Software Carbon Intensity · Green Software Foundation

What it governs

A rate of carbon emissions per functional unit: SCI = ((E × I) + M) per R, where E is energy, I is grid carbon intensity, M is embodied emissions and R the unit.

How it shows up in delivery

Carbon measured per request, user or inference, so efficiency work has a baseline.

Sustainability & operations · Metric set

DORA metrics

Software delivery performance · DORA (DevOps Research and Assessment)

What it governs

Deployment frequency, change lead time, change failure rate and failed deployment recovery time.

How it shows up in delivery

Measured from your pipeline from week one, so delivery speed and stability are reported with numbers.

Sustainability & operations · Standard

ISO 14001:2015

Environmental management systems · ISO

What it governs

Requirements for managing environmental aspects, compliance obligations and performance improvement.

How it shows up in delivery

Hosting, device and data-transfer impact recorded beside cost, with reviewed reduction targets.

Sustainability & operations · Standard

ISO 22301:2019

Business continuity management systems · ISO

What it governs

Requirements for planning, testing and improving the ability to keep operating through disruption.

How it shows up in delivery

Recovery time and recovery point objectives set per service, then tested with restore and failover drills.

Where it applies · 6 of 10 capability pages

Control mapping

Audit logging mapped to six frameworks.

We build access and audit logging once, in the gateway and every service. The same logs meet clauses in six frameworks, which keeps alignment affordable.

  • ISO/IEC 27001:2022Annex A 8.15 · Logging
  • SOC 2CC7.2 · Monitoring of system components
  • PCI DSS v4.0.1Requirement 10 · Log and monitor all access
  • HIPAA Security Rule§164.312(b) · Audit controls
  • CERT-In 2022ICT logs kept 180 days, in India
  • DPDP Act 2023§8(5) · Reasonable security safeguards

An audit log tail showing access events with the actor, action, resource, authentication method, result and trace identifier, including an agent's tool call with its model route and prompt version, a denied export and a person approving a deployment.

How we use AI

AI-assisted software delivery, under four rules.

Agents draft the spec, the tests and the deployment. Every change then goes through automated tests, AI evaluations and security scans. The console below follows one ticket through eight stages.

Two engineers at their desks, one reading code in an editor on a large monitor
Reviewed by peopleAI drafts the code; an engineer reads every line before it merges.Photo: Compagnons / Unsplash

An interactive delivery console. One ticket, adding refund status to a support assistant, runs through eight stages: an agent drafts the spec and the tech lead approves it; an engineer codes with an AI pair and opens pull request 1482; a test agent adds 14 tests; the eval suite passes 148 of 148 cases with faithfulness 0.94; security scans find nothing critical; a named engineer reviews and approves the merge; an agent canaries the release from 5 to 100 percent; and production is observed against its SLO. Other tabs show the code diff, the eval report against its gates and the audit log.

delivery / your-platform / XE-1482 · Refund status in the support assistant In production · 3 h 32 min

Stage 01 of 8Agent + person

Spec

An agent drafts acceptance criteria and edge cases from the ticket. The tech lead edits them and approves.

Output6 criteria · 3 edge cases · approved

Stage 02 of 8Agent + person

Code

An engineer builds the change with an AI pair in the IDE and opens a pull request with a written summary.

OutputPR #1482 · +212 −38 · 7 files

Stage 03 of 8Agent

Tests

A test agent writes unit and contract tests for the change. The engineer keeps the ones that earn their place.

Output+14 tests · coverage 81.2% → 84.6%

Stage 04 of 8Agent

Evals

The golden set runs against the AI feature: faithfulness, refusals, latency and cost, compared with main.

Output148 / 148 pass · faithfulness 0.94

Stage 05 of 8Agent

Security

SAST, dependency, container and secret scans run on the branch, with prompt-injection cases (OWASP LLM01) in the suite.

Output0 critical · 0 high · 0 secrets

Stage 06 of 8Person

Review

A named engineer reads the diff, the eval report and the scan results, then approves or asks for changes. Agents cannot merge.

Waiting for a named engineer. Agents cannot merge.

Approved by the tech lead · 17:12 · logged

Stage 07 of 8Agent

Deploy

Canary to 5% of traffic, then 25% and 100% while error rate and latency hold. It rolls back on its own if they do not.

Outputcanary 5% → 25% → 100% · 0 rollbacks

Stage 08 of 8Agent + person

Observe

Traces, SLO burn and eval drift are watched in production. The on-call engineer owns anything that moves.

OutputSLO 99.96% · burn 0.4× · no drift

#1482Answer refund status from the order system, hand off on low confidence

services/support/answer.py+14−1Drafted with an AI pair · reviewed by the tech lead

@@ -41,9 +41,24 @@ def answer(question: str, customer: Customer) -> Answer:
    context = retrieve(question, customer_id=customer.id, k=8)
    return llm.complete(PROMPT.format(q=question, ctx=context))
    if intent(question) == "refund_status":
        order = tools.orders.lookup(customer.id, scope="read")
        context.append(order.as_citation())
    draft = gateway.complete(
        route="support.answer",        # small model first, escalates on low confidence
        prompt=PROMPTS["answer@v14"], question=question, context=context,
    )
    checked = guardrails.check(draft, policy="support@v6")   # PII, claims, injection
    if checked.confidence < 0.62:
        return handoff.to_human(question, draft, reason="low_confidence")
    return checked.answer

Review noteTool call is read-scoped. Handoff threshold matches the value calibrated on the golden set. Approved.

golden-set@v14 · 148 cases · judge calibrated against expert labelsAll gates pass

MetricThis branchAgainst the gateGateMain
Faithfulness 0.94 ≥ 0.90 0.93
Answer relevance 0.91 ≥ 0.85 0.90
Citation accuracy 0.97 ≥ 0.95 0.96
Correct refusals 1.00 = 1.00 1.00
Injection cases blocked 24 / 24 = 24 22 / 22
p95 latency 1.9 s < 2.5 s 2.1 s
Cost per answer $0.004 ≤ $0.006 $0.005

Why it mattersModels and prompts change. The same 148 cases run on every change, so a regression blocks the merge instead of reaching a customer.

TimeActorActionModel · promptReviewerResult
14:02 spec.agent Drafted acceptance criteria route:large · spec@v7 Tech lead Approved
14:31 ide.pair Suggested 38 lines in 3 files route:code Tech lead 31 kept
16:40 test.agent Generated 14 tests route:code · tests@v3 Tech lead 12 kept
16:46 eval.runner Ran golden set v14 judge@v5 — Pass
17:12 Tech lead Approved merge of PR #1482 — — Merged
17:34 deploy.agent Canary 5% → 100% — On-call Live

RetentionKept with the pull request and the release, exportable to your SIEM, and sampled in the monthly audit.

  • Agents propose, people approve

    Agents draft, test and deploy. A named engineer approves every merge and every production change.

  • Every AI action is logged

    Model, prompt version, inputs, output and reviewer, kept with the pull request and the release.

  • No client data in public training

    Enterprise model endpoints with training turned off, in your region where required.

  • Secrets never enter a prompt

    Credentials stay in the vault. Agents call tools with scoped, short-lived tokens.

What we track on every programme · DORA metrics Illustrative

Lead time for changes
Measured in hoursTicket to production for the run above: 3 h 32 min
Deployment frequency
Daily when neededSmall, reversible changes, released in stages
Change failure rate
Tracked per releaseEvery rollback reviewed in writing
Recovery time
Tracked per incidentRunbooks and on-call from day one

Model updates

New models, tested within days of release.

Each new model is tested on your own cases and adopted only when it scores better or costs less. Changes reach production in a weekly release that must pass four checks.

Model changelog · last 12 months

Nine model releases, each tested on your cases

Eval score
0.81 → 0.93
Cost per 1k requests
$2.40 → $1.02
Adopted
6 of 9
Median time to decision
2 days

A chart of the last twelve months. Nine model releases are marked along the top. The eval score on the golden set rises in steps from 0.81 to 0.93 as six of them are adopted, while the cost per thousand requests falls from 2.40 to 1.02 dollars. Each release can be chosen to see how it was evaluated and what changed.

0.80 0.85 0.90 0.95

Weekly releases · 12 weeks Illustrative

Every Thursday, whatever passed the checks goes live

Twelve weekly releases. Eleven went live, with 9 to 23 changes each. Week 7 was held because a refund-intent test score dropped from 0.92 to 0.86; the fix went live in week 8.

  • Testsunit · contract · e2e
  • AI testsyour examples · every AI feature
  • Scanscode · dependencies · secrets
  • Rollout5% → 100% while targets hold

W7 held. The refund-intent test score dropped from 0.92 to 0.86. Nothing went live; the fix went out with W8.

11 of 12 releases went live1 held by AI tests0 rollbacks

Idea to agent · typical Typical ranges

From a defined problem to production in about six weeks

  1. Day 0 Problem framed One task, one owner, one measure, and the baseline of how it is done today. Owner signs the measure
  2. Day 2 Prototype on real data A working agent on masked copies of your data, traced end to end. The team who does the work reviews outputs
  3. Day 5 Eval baseline A golden set from real cases, scored for quality, cost and latency. Go or stop, decided on the numbers
  4. Week 3 Pilot with users Named users, human approval on every action, guardrails and spend limits live. Security and legal sign the guardrail policy
  5. Week 6 Production with guardrails Rolled out behind the gateway with monitoring, runbooks and an audit log. Sponsor signs the release

How we work with you

From first call to a platform your teams run.

Product, engineering, AI and security teams share the same sprints from week one, and four gates decide when work moves on. Choose a phase to see its decision, team and agent tasks.

A programme plan in five phases, Discover in weeks 1 to 2, Design in weeks 2 to 4, Build in weeks 4 to 16, Launch in weeks 16 to 18 and Run from week 18, across four lanes: product and design, engineering, AI and data, security and quality. Gates: architecture approved after Design, security sign-off after Build, go-live after Launch, and a 90-day review in Run.

LanePhase · typical
Product & design
Engineering
AI & data
Security & quality

Phase 01 · Wk 1–2

Discover

Ends in a decisionWhat to build first, what it must achieve and whether the data can support it.

Deliverables

  • Problem statement and success measures
  • Current-state architecture map
  • Data and AI-readiness assessment
  • Risk register and DPIA screening

Who takes part

Your sponsorYour product ownerDomain expertsProgramme leadSolution architectAI lead

Where agents assist

  • Turns interview notes and tickets into themes, with sources attached
  • Maps systems and data flows from your documents and repositories
  • Drafts the first risk register for people to review

Phase 02 · Wk 2–4

Design

Ends in a decisionThe architecture, the build order and the quality gates the build has to pass.

Gate · Architecture approved

Deliverables

  • Reference architecture and decision records
  • Prototype tested with users
  • Evaluation set and test plan
  • Threat model and security architecture
  • Sprint plan with goals

Who takes part

Solution architectTech leadProduct designerSecurity engineerYour IT and security leads

Where agents assist

  • Drafts architecture options with trade-offs for the architect to decide
  • Generates prototype variants from the design system
  • Proposes evaluation cases from past tickets

Phase 03 · Wk 4–16

Build

Ends in a decisionEvery two weeks: what this sprint delivers, shown working in the demo.

Gate · Security sign-off

Deliverables

  • Working software every sprint
  • Tests, AI evaluations and scans on every change
  • Runbooks written as features land
  • A decision log kept current

Who takes part

Tech leadEngineersProduct designerQA and evaluation engineerYour product owner, weekly

Where agents assist

  • Pairs with engineers in the IDE; people review every line
  • Writes tests and pull-request summaries
  • Runs the AI tests on every change and flags anything that got worse

Phase 04 · Wk 16–18

Launch

Ends in a decisionGo live, with the rollback rehearsed and the on-call rota staffed.

Gate · Go-live

Deliverables

  • Load-test report at expected peak
  • Independent penetration-test report
  • Cutover plan and rollback rehearsal
  • On-call rota, runbooks and training

Who takes part

Release managerSite reliability engineerSecurity engineerYour support leadYour sponsor

Where agents assist

  • Compares AI outputs with your team's decisions in a parallel trial before go-live
  • Watches the staged rollout and triggers a rollback if error rates rise
  • Drafts release notes and training material

Phase 05 · Wk 18 →

Run

Ends in a decisionEvery month: what to improve next, decided on service targets, test results and cost.

Gate · 90-day review

Deliverables

  • Monthly report: service targets, AI test results, cost and carbon
  • Incident reviews without blame
  • A ranked improvement backlog
  • The 90-day review

Who takes part

Service ownerOn-call squadYour product ownerYour finance partner, for cloud cost

Where agents assist

  • Triages alerts and drafts incident timelines
  • Watches AI test scores after model or data changes
  • Flags cost anomalies with a proposed fix for approval
Two colleagues working through a diagram on a whiteboard Design · week 3Architecture options on the wall before any are built
  • Two-week sprints

    A goal per sprint, agreed with your product owner.

  • A demo every sprint

    Working software you can click through on a preview environment.

  • A decision log

    Architecture decision records, so choices outlive the people who made them.

  • Runbooks before go-live

    Written as features land and rehearsed before launch.

Sustainability

Lower-carbon software, measured per request.

AI adds energy to every request. We measure carbon per request with the Green Software Foundation's Software Carbon Intensity (SCI) standard, ISO/IEC 21031, and cut it with the same changes that cut cost.

Wind turbines on the horizon at dusk Measured and reportedCarbon reduced by design, then measured
  1. 01

    Reported per unit of use

    SCI per request, per active user or per 1,000 tokens, with what is counted written down.

  2. 02

    No offsets in the figure

    The SCI specification excludes certificates and offsets, so the figure counts reductions only.

  3. 03

    Choosing the cloud region

    We weigh speed, data residency under the DPDP Act and grid carbon together, and record the choice.

sci-report / your-platform / support.answer Illustrative

Region · grid intensity and round trip from Delhi users

India West is the default because it carries the widest service coverage of the Indian regions, which usually decides it. India North is cleaner and closer to Delhi users, so it wins wherever its services cover the workload. The choice is made per engagement; both keep data in India.

Practices

Where the carbon went · gCO₂e per request

0.18gCO₂e per request

62% below baseline · 179 g per 1,000 requests

  • Right-sized models

    A small model answers first; the large model is used only when the small one is unsure.

    Energy per request down 30–60% on routed traffic

  • Caching and batching

    A cache answers repeated questions; offline jobs run in batches instead of one call at a time.

    Model calls down 20–40%

  • Carbon-aware scheduling

    Embeddings, reports and fine-tuning run at hours or in regions with a cleaner grid, using live grid data.

    Batch emissions down 10–30%

  • Lighter pages

    Image, font and JavaScript size limits are checked on every build, so each visit sends less data to the phone.

    Page weight down 30–50%

  • Idle infrastructure retired

    Services scale to zero overnight, clusters are right-sized and unused resources are deleted in a monthly sweep.

    Idle spend and hardware carbon down

Typical effects are ranges from published practice and are not client results. Grid intensities are illustrative annual averages; live figures come from your cloud provider and grid data when measured.

Industries

Sector rules built into the software.

Regulation, data residency, latency and human review differ by sector, and we settle each before any code is written. Choose yours to see what applies.

Sector01 / 08

Trading screens and a tablet showing market charts on a desk

01 · PCI DSS · RBI · SEBI

Financial services

Payments must be fast, and every decision needs an audit trail.

Regulation
PCI DSS v4.0.1 for card data, RBI directions on IT outsourcing and SEBI's cybersecurity and cyber-resilience framework for market entities.
Data residency
Payment-system data stored only in India under RBI's 2018 direction; customer data processed under the DPDP Act.
Latency & scale
Payment and trading APIs answering 99% of requests within a few hundred milliseconds, with peaks on salary days and at market open.
AI oversight
Every AI-assisted decision logged with inputs, model version and reviewer, with explanations for credit outcomes.

Frameworks that apply

  • PCI DSS v4.0.1 — Payment Card Industry Data Security Standard
  • ISO/IEC 27001:2022 — Information security management systems
  • SOC 2 — Trust Services Criteria
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023

Typical first projectA security and AI-readiness audit, then a fraud-triage assistant with human approval.

A doctor reviewing scans on a tablet with a patient

02 · HIPAA · DPDP · clinical safety

Healthcare & life sciences

Clinical safety comes first, and health data needs the strictest care.

Regulation
DPDP Act consent and purpose limits in India, ABDM health-data standards where they apply and the HIPAA Security Rule for US patient data.
Data residency
Health records kept in region; models trained or tuned only on de-identified data.
Latency & scale
Clinician tools answer within a consultation and tolerate weak connectivity at remote sites.
AI oversight
A clinician reviews every AI suggestion that touches care and makes every clinical decision.

Frameworks that apply

  • HIPAA Security Rule — Safeguards for electronic protected health information
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • ISO/IEC 27001:2022 — Information security management systems
  • ISO/IEC 42001:2023 — Artificial intelligence management systems

Typical first projectVisit summaries drafted by AI, signed off by the clinician on every note.

A shopper and a store assistant looking at products on a tablet

03 · Core Web Vitals · sale days

Retail & D2C

Sale-day traffic, mid-range phones and AI search answers shape revenue.

Regulation
PCI DSS through the payment provider, DPDP consent for marketing and consumer-protection rules on prices and claims.
Data residency
Customer profiles in region; card data never leaves the payment gateway.
Latency & scale
Good Core Web Vitals at the 75th percentile of visits on mid-range Android; 10 to 20 times normal traffic on sale days.
AI oversight
Assistants answer product questions from the live catalogue, so prices and stock levels match what is on sale.

Frameworks that apply

  • Core Web Vitals — Loading, interactivity and visual stability
  • PCI DSS v4.0.1 — Payment Card Industry Data Security Standard
  • WCAG 2.2 AA — Web Content Accessibility Guidelines
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023

Typical first projectFaster product and checkout pages, measured on live visits and conversion.

A robotic arm on an automated production line

04 · OT security · edge

Manufacturing

Plants run on control systems that cannot stop for an upgrade.

Regulation
IEC 62443 for industrial control-system security, ISO/IEC 27001 for IT and export controls on some designs.
Data residency
Plant data stays at the edge; only summaries and models travel to the cloud.
Latency & scale
Vision inspection at line speed, with models on site that keep working when the network drops.
AI oversight
An engineer reviews quality decisions until precision is confirmed on your own line.

Frameworks that apply

  • ISO/IEC 27001:2022 — Information security management systems
  • NIST CSF 2.0 — Cybersecurity Framework
  • ISO 22301:2019 — Business continuity management systems
  • ISO 9001:2015 — Quality management systems

Typical first projectConnect MES and ERP data, then a vision-inspection pilot on one line.

Students gathered around a laptop in a lecture hall

05 · Children's data · accessibility

Education

Results days bring the peaks, and children's data needs the most care.

Regulation
The DPDP Act requires verifiable parental consent for under-18s and bars tracking or targeted ads aimed at them; WCAG 2.2 AA for accessibility.
Data residency
Student records in region, with retention tied to the purpose they were collected for.
Latency & scale
Results-day spikes of 50 times normal traffic, and pages that work on low bandwidth.
AI oversight
Tutoring agents with automatic checks, age-appropriate content and full visibility for teachers.

Frameworks that apply

  • WCAG 2.2 AA — Web Content Accessibility Guidelines
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • GDPR — General Data Protection Regulation (EU) 2016/679
  • OWASP Top 10 for LLM Applications — Security risks in generative AI applications

Typical first projectAn accessible student portal, load-tested for results day.

Shipping containers stacked in a port, seen from above

06 · Events · integrations · offline

Logistics

Every shipment is an event, and every event has to reach the right system.

Regulation
E-way bill and GST e-invoicing integrations, and data-sharing agreements with carriers and partners.
Data residency
Operational data in region; partner APIs bound by contract and scoped per partner.
Latency & scale
Tracking events streamed in seconds, and driver apps that keep working offline.
AI oversight
Route and arrival-time models monitored for falling accuracy, with exceptions sent to a dispatcher.

Frameworks that apply

  • ISO/IEC 27001:2022 — Information security management systems
  • SOC 2 — Trust Services Criteria
  • ISO 22301:2019 — Business continuity management systems

Typical first projectOne event stream across carriers, warehouse and ERP, with WhatsApp updates to customers.

Government buildings in New Delhi under a cloudy sky

07 · Residency · audit · languages

Public sector

Data residency, accessibility and audit trails are required from the start.

Regulation
CERT-In six-hour incident reporting and 180-day log retention, the DPDP Act and the GIGW guidelines for government websites.
Data residency
Data held in India, on government-empanelled cloud where the department requires it.
Latency & scale
Citizen services in many Indian languages, with spikes as scheme deadlines approach.
AI oversight
A person reviews any decision about a citizen, and the explanation can be published.

Frameworks that apply

  • CERT-In Directions 2022 — Cyber incident reporting directions
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • WCAG 2.2 AA — Web Content Accessibility Guidelines
  • ISO/IEC 27001:2022 — Information security management systems

Typical first projectA security and accessibility audit, then a multilingual citizen-service assistant.

Two engineers working side by side at monitors of code

08 · SOC 2 · tenancy · AI features

SaaS

Enterprise buyers ask for evidence before they sign.

Regulation
SOC 2 reports and ISO/IEC 27001 expected by enterprise buyers; GDPR and the EU AI Act for customers in the EU.
Data residency
Per-tenant data boundaries, with EU or India hosting on request.
Latency & scale
Response-time targets per plan, and isolation so one busy tenant cannot slow the rest.
AI oversight
AI features that keep each tenant's data separate, with evaluation tests on every release.

Frameworks that apply

  • SOC 2 — Trust Services Criteria
  • ISO/IEC 27001:2022 — Information security management systems
  • GDPR — General Data Protection Regulation (EU) 2016/679
  • EU AI Act — Artificial Intelligence Act (EU) 2024/1689

Typical first projectSecurity-questionnaire readiness, then an AI feature built with tenant isolation.

Measures

Monthly service reports in numbers engineering leaders use.

Speed, reliability, AI quality, security, cost and carbon, reported monthly. Each number has a written definition and a target agreed before launch, so your CTO, CFO and auditor read it the same way.

Service report · Xterra Edze

Your platform

Six concerns · targets agreed before launch · definitions printed beside every number Illustrative

01Speed On target

p75 LCP · mobile, field data

2.1s ▼ 1.7 s · 12 months

p95 API latency212 ms

Definition · Speed

Largest Contentful Paint at the 75th percentile of real page loads on mobile. Core Web Vitals rate it good at 2.5 s or less, alongside INP ≤ 200 ms and CLS ≤ 0.1. p95 API latency: 95% of requests finish faster than this.

02Reliability On target

SLO attainment · rolling 30 days

99.97% ▲ 0.25 pts · 12 months

Error budget left71% · 12.5 of 43.2 min used

Definition · Reliability

The share of requests served well over the window. A 99.9% monthly SLO allows 43.2 minutes of failure in 30 days: the error budget. When it runs out, releases pause and reliability work goes first.

03AI quality On target

Faithfulness · golden set

0.94 ▲ 0.10 · 12 months

Eval pass rate148 / 148 cases

Definition · AI quality

The share of claims in an answer that the retrieved sources support — faithfulness, also called groundedness — scored by a judge calibrated against expert labels. The same golden set of real cases runs on every change to a model, prompt or data source. One term, one number, one gate: the hero readout, the run log and the composer all report this figure.

04Security On target

Critical vulnerabilities open

0 ▼ 6 · 12 months

MTTR · high severity3.2 days

Definition · Security

Confirmed critical findings from scans, penetration tests and reports, counted until the fix is verified in production. MTTR is the mean time from a finding being confirmed to its fix going live.

05Cost On target

Cost per 1,000 requests

$1.02 ▼ $1.38 · 12 months

Spend vs monthly budget94%

Definition · Cost

Compute, model tokens, storage and egress divided by requests served, per 1,000. Reviewed with finance every month using the FinOps Framework, because unit cost says more than the total bill.

06Carbon On target

SCI per request

0.18gCO₂e ▼ 0.29 g · 12 months

Batch jobs run carbon-aware86%

Definition · Carbon

Software Carbon Intensity, ((E × I) + M) per R, from the Green Software Foundation (ISO/IEC 21031:2024), with R as one request. Offsets are excluded by design, so it only falls when the software uses less.

  1. Weekly

    Operations review

    Error-budget burn, incidents, AI test scores and anything that paged someone, in fifteen minutes with the on-call engineer.

  2. Monthly

    Service report

    All six measures against target, including cost and carbon per unit, and what we will change next month.

  3. Quarterly

    Business review

    The measures agreed before launch, the roadmap and DORA metrics on how delivery is running.

Core Web Vitals · good
LCP ≤ 2.5 s · INP ≤ 200 ms · CLS ≤ 0.1, at the 75th percentile of visits
Error budget
99.9% over 30 days = 43.2 min of allowed failure
Burn-rate alert
14.4× over one hour spends 2% of the month’s budget: page on-call
p95 / p99
The response time that 95% or 99% of requests beat; averages hide the slowest requests

Where we work

Offices in India and Canada, overlapping your hours.

Offices in New Delhi and Ludhiana on India Standard Time (UTC+5:30), and in Saint John, Canada, on Atlantic Time. Between them, our office hours overlap most of the working day in Europe, the Gulf, South-East Asia and North America.

Time zones
2India Standard Time (UTC+5:30) and Atlantic Time in Saint John (UTC−4, UTC−3 in summer)
Office hours
10:00–19:00Nine hours in India, Monday to Friday
Extended shift
+ 3.5 hTo 22:30 IST, by agreement
On call
24 / 7Rota and escalation path, by agreement

Office 01 · India

New Delhi

03:55 IST · UTC+5:30

6 Worldmark, AerocityNew Delhi 110037, India

Work led here

  • Client and programme leadership
  • Architecture and AI engineering
  • Security, audit and assessment work

Office 02 · India

Ludhiana

03:55 IST · UTC+5:30

SCO-2, LGFSCO-1, 3rd Floor Noble Enclave, Opp. Hotel Park PlazaFerozepur Road, Ludhiana, Punjab 141001, India

Work led here

  • Platform, product and web engineering
  • Data, QA and AI testing
  • Managed service, support and the on-call rota

Office 03 · Canada

Saint John

19:25 ADT · UTC−3

120 University AvenueSaint John, NB E2K 1Z3, Canada

Overlap

Your working day against ours, hour by hour

Offices · IndiaIST · UTC+5:30

9 hoffice hours

Office · CanadaSaint John · ADT · UTC−3Saint John · AST · UTC−4

Saint John office, Northern summer: open 09:00–17:00 ADT, which is 17:30–01:30 India time.Saint John office, Northern winter: open 09:00–17:00 AST, which is 18:30–02:30 India time.

United KingdomLondon · BST · UTC+1London · GMT · UTC+0

United Kingdom, Northern summer: a 09:00–17:30 local working day shares 8.5 h with our office hours. United Kingdom, Northern winter: a 09:00–17:30 local working day shares 8.5 h with our office hours.

EuropeFrankfurt · CEST · UTC+2Frankfurt · CET · UTC+1

Europe, Northern summer: a 09:00–17:30 local working day shares 8.5 h with our office hours. Europe, Northern winter: a 09:00–17:30 local working day shares 8.5 h with our office hours.

GulfDubai · GST · UTC+4Dubai · GST · UTC+4

Gulf, Northern summer: a 09:00–18:00 local working day shares 9 h with our office hours. Gulf, Northern winter: a 09:00–18:00 local working day shares 9 h with our office hours.

SingaporeSingapore · SGT · UTC+8Singapore · SGT · UTC+8

Singapore, Northern summer: a 09:00–18:00 local working day shares 5.5 h with our office hours. Singapore, Northern winter: a 09:00–18:00 local working day shares 5.5 h with our office hours.

US EastNew York · EDT · UTC−4New York · EST · UTC−5

US East, Northern summer: a 09:00–17:30 local working day shares 7 h with our office hours. US East, Northern winter: a 09:00–17:30 local working day shares 7 h with our office hours.

Local working days shown as 09:00–17:30 (09:00–18:00 in the Gulf and Singapore). Shared hours count the office days in India and in Saint John. Handovers are written down: open incidents, releases in progress and anything waiting for approval.

Services & packages

Technology services, bought alone or as one programme.

Services you can start with, from our ten technology capabilities. Pick one and your enquiry reaches the right team with it attached. Each comes as a short sprint, a fixed-scope project or an ongoing team.

Categories
05
Services
21
Packages
06
Not sure what you need? Describe the problem

How to buy

  1. 01Pick services. Enquire about one, or add several to a brief.
  2. 02Choose a package. A sprint, a fixed project or an ongoing team.
  3. 03Send the brief. We reply within one working day.

Browse by category

Timelines are typical. Every quote follows a written scope.

01Build

4 services
Typical timeline: 6–12 weeks

Website

A corporate, marketing or e-commerce website that loads fast, works for everyone and is easy for your team to update.

What’s included

  • Content model, page templates and an editor-friendly CMS
  • SEO foundations and Schema.org markup
  • Core Web Vitals and WCAG 2.2 AA checks before launch
  • Analytics and consent set-up
  • Corporate
  • E-commerce
  • Headless CMS

Best forCompanies launching a new brand or replacing a site that holds them back.

Explore Websites & Apps
Typical timeline: 10–18 weeks

Web or mobile app

A web application, iPhone app or Android app, built native or cross-platform depending on what your product needs to do.

What’s included

  • Product discovery and a clickable prototype
  • Accounts, roles and the core workflows
  • Native, Flutter or React Native, chosen on evidence
  • Store submission, crash reporting and analytics
  • SaaS
  • iOS · Android
  • Cross-platform
  • React Native

Best forFounders and product teams putting a new product in front of customers.

Explore Websites & Apps
Typical timeline: 12–24 weeks

Custom CRM or operations platform

A CRM, operations system or approval tool built around how your business runs, rather than reshaping your process to fit a package.

What’s included

  • Process mapping and a build, buy or extend decision per module
  • Data model and role-based access
  • Integrations with the systems you keep
  • Data migration with reconciliation reports
  • CRM
  • ERP
  • Internal tools
  • Salesforce

Best forBusinesses that have outgrown spreadsheets or off-the-shelf software.

Explore Custom Software & Data Platforms
Typical timeline: 8–16 weeks

Data platform & BI dashboards

One place for your business data and the dashboards built on it, so every team works from the same numbers.

What’s included

  • Warehouse or lakehouse set-up
  • Automated pipelines from your tools
  • Tested data models and metric definitions
  • Dashboards in Power BI, Looker or your BI tool
  • Warehouse
  • ELT
  • BI
  • dbt
  • Power BI

Best forLeadership teams reporting from spreadsheets that disagree.

Explore Custom Software & Data Platforms

02Intelligence

5 services
Typical timeline: 4–6 weeks

AI strategy & roadmap

A plan showing where AI can save time, cost or risk in your business, which use cases to build first and how to measure them.

What’s included

  • Interviews and process walk-throughs
  • Opportunity map scored on value, feasibility and risk
  • Sequenced roadmap with business cases
  • Pilot charter for the first use case
  • Readiness
  • Use cases
  • Roadmap

Best forLeadership teams that want an AI plan grounded in their own processes.

Explore AI Strategy & Agents
Typical timeline: 8–12 weeks

Custom AI agent or copilot

An AI agent or assistant that answers, drafts, checks and updates records in your systems, with a named person approving anything consequential.

What’s included

  • Task design with scoped permissions
  • Integration with your tools and APIs
  • Evaluation set and red-team tests before go-live
  • Action log and human approval steps
  • Agents
  • Copilots
  • Human approval
  • OpenAI

Best forTeams with repetitive, rules-heavy work spread across several systems.

Explore AI Strategy & Agents
Typical timeline: 6–10 weeks

AI knowledge assistant

Ask questions of your own documents and data, and get answers with the sources shown so people can check them.

What’s included

  • Document ingestion and hybrid search
  • Citations and permission-aware access
  • Faithfulness and relevance evaluations
  • Deployment on the web, Slack or Teams
  • Document Q&A
  • Citations
  • Permission-aware
  • LlamaIndex
  • pgvector
  • OpenAI

Best forSupport, sales, HR and legal teams searching long documents every day.

Explore AI Product & Automation
Typical timeline: 2–8 weeks

Workflow automation

Data entry, document handling and hand-offs between tools done automatically, with exceptions sent to the right person.

What’s included

  • Process mapping and an automation shortlist
  • Workflows with AI steps for reading, sorting and drafting
  • Error handling, alerts and an audit trail
  • Documentation and team handover
  • n8n
  • Make
  • Temporal

Best forOperations teams losing hours to copy-and-paste work.

Explore AI Product & Automation
Typical timeline: 4–10 weeks

AI inference platform

Run AI models fast and affordably, through managed endpoints or on your own GPUs, with latency and cost per request tracked.

What’s included

  • Serving with vLLM or managed endpoints
  • Batching, caching and routing between models
  • Load tests against response-time targets
  • Cost-per-request dashboard
  • Model serving
  • Response time
  • Cost per request

Best forProducts with growing AI traffic, data-residency rules or rising model bills.

Explore AI Infrastructure & Cloud

03Run & protect

5 services
Typical timeline: 8–20 weeks

Cloud migration & foundations

Move to AWS, Azure or Google Cloud, or tidy what you already run there, with secure foundations set up as code.

What’s included

  • Discovery and a migration plan per application
  • Landing zone with identity, networking and policy controls
  • Infrastructure as code
  • Cutover with a rollback plan
  • AWS
  • Azure
  • Google Cloud
  • AWS
  • Microsoft Azure

Best forOrganisations leaving a data centre or reorganising a cloud estate.

Explore AI Infrastructure & Cloud
Typical timeline: 1–3 weeks

Penetration test (VAPT)

Security specialists test your website, app, API or cloud the way an attacker would, under an agreed scope, and show you what to fix.

What’s included

  • Scope and rules of engagement
  • Manual testing against OWASP guidance
  • Severity-rated findings with evidence
  • Fix guidance and a retest of fixed findings
  • Web · mobile
  • API · cloud
  • OWASP

Best forBusinesses before launch, after major changes or when a customer asks for a report.

Explore Cybersecurity & AI Trust
Typical timeline: 8–24 weeks

Compliance readiness

Get ready for ISO/IEC 27001:2022, SOC 2 or India’s DPDP Act 2023: we find gaps, help implement controls and prepare evidence for your auditor.

What’s included

  • Gap assessment against the framework
  • Risk assessment and policies
  • Control implementation support
  • Evidence collection and audit support
  • ISO/IEC 27001:2022
  • SOC 2
  • DPDP Act 2023

Best forCompanies whose customers or regulators ask for proof of security.

Explore Cybersecurity & AI Trust
Typical timeline: 4–10 weeks

System integration

Connect your CRM, ERP, payments and other tools so data moves between them automatically, once and correctly.

What’s included

  • Integration map and data contracts
  • APIs, events or iPaaS flows with retries
  • Contract tests and monitoring
  • Runbooks for support
  • APIs
  • iPaaS
  • Events
  • Salesforce
  • MuleSoft

Best forTeams re-keying the same data into several systems.

Explore Integration & Support
Typical timeline: Onboarding 2–4 weeks, then monthly

Managed support with SLAs

Engineers who monitor your systems, respond to incidents within agreed times, keep everything patched and report to you every month.

What’s included

  • Response and resolution targets by severity
  • Monitoring and alerting
  • Security patches and upgrades
  • Monthly service review
  • SLA
  • Monitoring
  • Monthly report

Best forBusinesses whose systems matter too much to run without cover.

Explore Integration & Support

04Grow & assess

4 services
Typical timeline: 90-day cycles, ongoing

SEO programme

Technical fixes, useful content and clear structure that help your site rank in Google and Bing.

What’s included

  • Technical SEO audit and fixes
  • Topic and content plan
  • Structured data in JSON-LD
  • Monthly reporting against a baseline
  • Technical SEO
  • Content
  • Reporting
  • Schema.org

Best forBusinesses where search is a main source of customers.

Explore Search & AI Visibility
Typical timeline: 8–12 weeks, then ongoing

AI search visibility (AEO & GEO)

Make your pages easier for ChatGPT, Perplexity, Gemini and Google’s AI Overviews to quote, and track how often they cite you.

What’s included

  • Baseline across the main answer engines
  • Answer-first content and clear entity facts
  • Outreach to trusted sources
  • Monthly share-of-answer tracking
  • AEO
  • GEO
  • AI Overviews
  • OpenAI
  • Schema.org

Best forBrands whose customers now research by asking an AI assistant.

Explore Search & AI Visibility
Typical timeline: 2–4 weeks

Technical & code audit

An independent review of your code, architecture and delivery process, with a ranked list of fixes and what each problem costs you.

What’s included

  • Code quality and architecture review
  • Security and dependency checks
  • Delivery review with DORA metrics
  • Ranked backlog and a 30-60-90-day plan
  • Code
  • Architecture
  • Tech debt

Best forBefore a funding round, replatform, acquisition or vendor change.

Explore Audits & Assessments
Typical timeline: 2–4 weeks

AI readiness assessment

A scored review of how ready your data, systems, skills and governance are for AI, and what to fix before the first build.

What’s included

  • Readiness score across data, infrastructure, skills and governance
  • Use-case readiness review
  • Risk and compliance check
  • Prerequisite roadmap
  • Readiness score
  • Prerequisites

Best forOrganisations planning an AI programme or a first AI build.

Explore Audits & Assessments

05Talent

3 services
Typical timeline: Start in 2–4 weeks

Dedicated squad

Engineers, QA and design under one delivery lead, working in your stack and sprints and accountable for an agreed outcome.

What’s included

  • Squad shaped to the outcome
  • Delivery lead and agreed goals
  • Work in your tools and meetings
  • Monthly delivery review
  • Squad
  • Agreed outcome
  • Your cadence

Best forCompanies with a clear product goal and no team free to deliver it.

Explore Tech Workforce
Typical timeline: Start in 2–4 weeks

Engineers by role

Add vetted frontend, backend, mobile, DevOps, data or AI engineers to your existing team, for as long as you need them.

What’s included

  • Engineers vetted in your stack
  • You interview and choose
  • Onboarding with a first merged change in week one
  • Monthly quality and fit review
  • Staff augmentation
  • Vetted
  • Flexible

Best forTeams with more roadmap than people.

Explore Tech Workforce
Typical timeline: Ongoing, set days each month

Fractional CTO or tech lead

Senior technical leadership for part of the week: direction, architecture decisions, hiring and a clear voice for technology at board level.

What’s included

  • Technology strategy and roadmap
  • Architecture and vendor decisions
  • Hiring plan and interviews
  • Board and investor updates
  • Leadership
  • Part-time

Best forStart-ups and growing companies not yet ready for a full-time CTO.

Explore Tech Workforce

Your brief

Tick “Add to brief” on any service, choose a package, then continue. Or enquire about one service directly.

How we work with you

Ways to engage, from a question to an RFQ.

Ask a quick question, send a project brief or issue a formal RFQ. The lead for the work reads each one in full, and any services already in your brief go with it.

Or book a thirty-minute call

What are you sending?

  1. 01

    About 2 minutes4 required answers

    For a first conversation, a press request or anything that does not need a scope yet.

    You get A reply from a named lead

  2. 02Recommended

    About 8 minutes5 short steps

    Goals, audiences, a budget band and timing, so our first reply can outline the work.

    You get Options and a first scope after one call

  3. 03

    About 15 minutesYour documents attached

    Your documents, deadlines and the procurement and security rules the work must meet.

    You get Receipt confirmed and a named bid lead

How it is priced

Each package shows its pricing model. Work starts once a written scope and quote are agreed.

  • Typical length
    1–3 weeks
    Pricing
    Fixed fee
  • Typical length
    4–12 weeks
    Pricing
    Fixed price
  • Typical length
    3–9 months
    Pricing
    Fixed price per milestone
  • Typical length
    Ongoing · 6-month minimum
    Pricing
    Monthly fee
  • Typical length
    6–18 months
    Pricing
    Programme fee · by statement of work
  • Typical length
    Ongoing · 3-month minimum
    Pricing
    Time & materials
Compare what each package includes
What each package includes and who it suits
PackageEvery engagement includesBest for
SprintA short, fixed-scope engagement that answers one defined question.
  • Scope and outcome agreed before day one
  • A senior lead plus the specialists needed
  • A working review every week
  • A decision-ready answer or prototype
Discovery, a diagnostic, a prototype or a decision you need to make soon
ProjectA defined scope, delivered for a fixed price.
  • Statement of work with deliverables and acceptance criteria
  • A named project lead and a fixed team
  • A shared plan with dated checkpoints
  • Source files, yours once paid for
Work you can describe up front: an identity, a platform or a set of tools
MilestoneA larger build in phases you approve and pay for one at a time.
  • Phases with their own scope, output and sign-off
  • A go or no-go review at every gate
  • Re-planning between phases as you learn
  • Payment tied to accepted milestones
Programmes too large for one contract, where you want control at each step
RetainerReserved monthly capacity to run, improve and extend what we built.
  • A reserved block of team time every month
  • Agreed response times for requests and fixes
  • A monthly review and a rolling backlog
  • Planned improvements as well as upkeep
Live brands and products that need a steady team without hiring one
EnterpriseA multi-workstream programme with a dedicated team, governance and agreed service levels.
  • An engagement director and a steering group
  • A dedicated team across several workstreams
  • Service levels, reporting and a risk register
  • Security, legal and procurement reviews in the plan
Large organisations running change across markets, portfolios or business units
SquadA dedicated team that works inside your stack and sprint schedule.
  • Named specialists matched to your roadmap
  • Works in your tools, meetings and backlog
  • Scale the team up or down each month
  • Knowledge transfer built in from week one
Teams with a clear roadmap that need more senior people quickly

How we work with you

Six terms we enforce in the build.

Answers to what procurement, legal, IT and security teams ask, each shown with the setting or rule that enforces it.

Two engineers reviewing code together on a laptop Reviewed togetherDecisions written down as they are made
terms.md · Your company × Xterra Edze 6 clauses
  1. §1Usually asked by Legal · Procurement

    You own the code and the model configuration

    Source code, infrastructure code, prompts, evaluation sets and model and gateway configuration live in your repositories from the first commit, and are yours once paid for.

    Enforced asrepository

    repo.owner    = "your-org"
    ip.assignment = "on payment"
    includes      = [code, iac, prompts, evals, model_config]
    
  2. §2Usually asked by CTO · Procurement

    Model-agnostic and reversible

    Every model sits behind a gateway and an eval suite. Changing provider, or bringing a model in-house, is a configuration change we can demonstrate, not a rebuild.

    Enforced asgateway config

    route "support.answer" { model = var.model }
    switch.requires = "golden set ≥ gate"
    exit            = open formats, your keys
    
  3. §3Usually asked by Security · IT

    Security from the first commit

    Least-privilege access, your single sign-on where you have it, secrets in a vault, scans on every build, and your security questionnaire answered during scoping, not after.

    Enforced asCI policy

    ci.required = [sast, deps, secrets, iac, image]
    access      = sso + mfa, least privilege
    secrets     = vault only · never in prompts
    
  4. §4Usually asked by Security · Risk

    People approve, agents assist

    Agents draft, test and propose. A named person approves every merge, every production change and any action that reaches your customers, and every AI action is logged.

    Enforced asbranch protection

    main.required_reviews = 1   # a named person
    agents.can_merge      = false
    ai_actions.log        = [model, prompt, reviewer]
    
  5. §5Usually asked by CTO · Finance

    Measured, not asserted

    Targets for speed, reliability, AI quality, security, cost and carbon are agreed before launch and reported every month with their definitions, good months and bad.

    Enforced asservice report

    report.monthly = [cwv_p75, slo_30d, evals, vulns,
                      cost_per_1k, sci_per_request]
    targets        = "agreed before launch"
    
  6. §6Usually asked by IT · Operations

    Documentation and handover are deliverables

    Architecture decisions, runbooks, dashboards and onboarding guides are written as the work lands and accepted like any other deliverable, so your team can run it without us.

    Enforced asdefinition of done

    done    += [adr, runbook, dashboard, alert, owner]
    handover = "rehearsed, not emailed"
    

Our work is aligned with ISO/IEC 27001, SOC 2 and ISO/IEC 42001. That is not a certification claim; certificates come from independent auditors.

Questions

What technology buyers ask before they start.

Anything else? Ask the engineers who would run the work, or sketch a plan first.

First reply
One working day, from an engineer
First call
45 minutes, no slide deck
Under NDA
Signed before anything technical is shared
Outline plan
Scope, shape and a price range within a week

Yes. You can start with one: an audit, a single AI feature, a website or a squad. Each is scoped and priced on its own and built to connect with the rest when you are ready.

Related09Audits01Web & Apps04AI Product

Whichever scores best on your own examples. We work with models from OpenAI, Anthropic, Google, Meta and Mistral and with open-weight models in your cloud. All are called through one gateway and chosen per task on quality, speed and cost. When a new model arrives, we test it on the same examples and switch only if it does better.

Related03AI Strategy05AI Infrastructure

Yes. We deploy into your AWS, Azure or Google Cloud account, including India regions, and use enterprise model endpoints with training on your data switched off. Where data may not leave your network at all, open-weight models run inside it.

Related05AI Infrastructure06Security

You do. What we make for you is yours once it is paid for, including code, prompts, evaluation sets and model settings. Tools we already had stay ours, and you get a free, permanent licence to use them.

Related02Platforms10Workforce

Early and in writing. We answer your questionnaire during scoping, work under your policies and produce the evidence your auditors ask for as part of delivery. If you are working towards ISO/IEC 27001 or SOC 2, we prepare you for the independent auditor who issues the certificate or report.

Related06Security09Audits

Typically four to eight weeks from a defined problem to production. A prototype runs on your data within days and test baselines are set in week one. A pilot with named users starts by week three, with automatic checks in place. Regulated or high-risk uses take longer because review does.

Related03AI Strategy04AI Product06Security

Yes, in whichever shape helps. Engineers can join your sprints, a squad can own a stream of work or we can review and pair while your team builds. Knowledge transfer is planned from the first week.

Related10Workforce07Integration

You choose: a managed service with agreed service levels, or a handover to your team with runbooks, dashboards and training. Either way, we review the first 90 days against the measures agreed before launch.

Related07Integration10Workforce

Tell us what you need built.

You will speak to a lead who would run the work, and get a straight answer on fit.

Book a call

Three ways to start

Every engagement starts with a written scope and a quote agreed before work begins.

Choose one of the three ways above