Engineering

Built by the same people who keep it running.

We are a small team running three products in production, which shapes every engineering decision we make. Our software is designed, built and operated in-house, and it runs on AWS.

Cloud

Everything we run, runs on AWS.

Every product we operate, and every environment behind it, is hosted on Amazon Web Services. We chose AWS because it lets a team our size run production infrastructure properly, and it gives us somewhere to grow into as our products scale.

Hosted end to end on AWS

Our applications, their data and their supporting services all sit inside AWS, rather than being spread across providers we would then have to reason about separately.

Room to scale

As each product grows we move further onto managed AWS services, so capacity, backups and resilience become configuration rather than work we do by hand.

We hold the pager

There is no outsourced operations layer. The people who build each product configure its infrastructure and respond when something needs attention.

How we work

Four habits that let a small team ship safely.

None of this is exotic. It is the set of disciplines that have kept three products stable without a large team behind them.

Nothing reaches customers untested

Work is proven in isolated internal environments before it reaches anyone's live account. Live data and test data never share a home.

Releases are deliberate

Going live is an explicit, human decision rather than an automatic side effect of a code change. It means a routine fix can never carry an unfinished change into production with it.

Least access, by default

Each environment can only reach its own resources and its own credentials. Access to anything sensitive is granted narrowly and separately.

Repeatable, not remembered

Deployment is automated and reproducible, so recovering or rebuilding an environment is a known procedure rather than an afternoon of guesswork.

Security & privacy

Our products ask for a lot. We treat that seriously.

Between workplace attendance, continuous location and account access, our products handle genuinely sensitive information. These are the commitments that apply across all of them.

Sensitive data is encrypted

Where a product must store something confidential on a customer's behalf, it is encrypted at rest and used only for the purpose the customer agreed to.

Permissions are opt-in and reversible

Nothing sensitive is collected until someone actively enables it, and it can be turned off or revoked by the person who granted it.

We describe what we actually do

Our products state their real limits rather than implying capabilities they do not have. An accurate expectation is worth more to us than an extra signup.

Want to know more?

We are happy to talk in more depth about how we build and operate our products, including under NDA where that is the right setting.