/// Industries / Public sector

Digital public services built to be audited.

Public systems have to be transparent, resilient, and supportable for years. We build the citizen portals, registries, e-signature, and archive systems behind them — with the auditability and operational discipline that standard demands.

/// The constraint

It has to outlive the contract.

Public infrastructure is judged on transparency and longevity, not launch-day polish. A citizen's request arrives through the portal, by e-mail, or as scanned post; it is registered, routed, and answered with a signed act that must still verify years from now. We build that whole chain so every action leaves an audit trail, every statutory deadline is tracked, the service degrades gracefully under load, and the documentation lets the next team support it long after we've stepped back.

  • [ 01 ]An audit trail on every consequential action
  • [ 02 ]Resilience and observability built in, not bolted on
  • [ 03 ]Open standards and interoperability by default
  • [ 04 ]Documented to be supported for years
/// Accountability

What 'accountable' has to mean here.

The non-negotiables we design in from day one, because a public system has to answer for itself.

Every action attributable, with a full audit trail
Access control and segregation of duties
Accessibility to WCAG 2.1 AA / EN 301 549
GDPR by design, hosted in the EU
Encryption keys held per institution
A documented security incident process
/// Built to be handed over

From the old system to the team that comes next.

Few institutions start from nothing. The registers live in old databases and spreadsheets, and decades of files sit on paper. We write importers for the old systems, produce a reconciliation the institution signs off, and run old and new in parallel before cut-over — with the paper archive scanned and indexed alongside.

The measure of a public system isn't the demo — it's whether it still runs, and can still be changed, in five years. So resilience and observability are how it is built, and the documentation is part of the deliverable: architecture, runbooks, and decisions written down so a team we've never met can operate and extend the system with confidence.

AuditTrail on every action
WCAGAccessible by standard
YearsSupportability
/// Capabilities

What we build.

  • Citizen portals · national eID sign-in
  • Guided forms, pre-filled from the profile
  • Electronic registry & case management
  • Statutory deadline tracking & escalation
  • Qualified e-signatures & seals · eIDAS
  • Electronic archive · PDF/A & timestamps
  • Local taxes & fees · reconciliation
  • Council meetings & official publication
  • Legacy migration & archive scanning
  • Multi-institution tenancy & access
/// In the field
Access requests with two-person approval, segregation-of-duties pairings blocked at grant time, and a live append-only audit trail beside them.
One case queue across six services, statutory clocks on every row, retention classes attached — and the selected case's full attributable trail alongside.
A citizen sees the same record the officer does: permit progress at step 2 of 4, a dated action request, and every update logged and attributable.
A sign-in request that says exactly what it will read — name, address, and nothing else — over a consent list and an activity log the citizen can audit.
/// Proof

How we build for public infrastructure.

The discipline every public-sector build carries.

Audit
Trail on every action
24/7
Observable & resilient
WCAG
Accessible by standard
Years
Supportability
/// Questions

What public bodies ask us.

  • We build on open standards and document everything, so the system can be operated, audited, and extended by another team — including your own — without depending on us.

  • Yes. We build to WCAG 2.1 AA and EN 301 549 as a baseline, not a retrofit, and test for it as part of the delivery.

  • Every consequential action is attributable and logged to an audit trail, with access control and segregation of duties designed in. Where several institutions share a platform, each is its own tenant with its own data, and a subordinate or oversight body sees exactly what its legal relationship allows.

  • The officials do. They sign with their own qualified certificates through remote signing under eIDAS — the platform never holds a signing key. Signed documents are stored as PDF/A with a qualified timestamp, so they still verify years later.

  • To the institution. Payments by card, bank transfer, or at the counter settle directly to the institution's own treasury accounts — the software never holds the money. It keeps the ledger of what is owed and reconciles each payment against the treasury statements.

  • You get architecture docs, runbooks, and the decision record — enough for your team to run and change the system for years. We can also stay on to operate it.

Building for one of these?

Tell us the constraints — uptime, compliance, field conditions. We'll come back with an architecture that fits.

Contact us