Contact

Services

Engineering for systems that have to work.

Three practices for organisations whose software is not allowed to fail: public institutions, banks, marketplaces and the companies that run on them. Every engagement is led by a senior engineer, ends with documentation you can hand to an auditor, and leaves your team able to run the result.

AI

AI Engineering

From pilot to production. Most AI pilots never ship. We build the parts that make them production systems: retrieval that is correct, agents that are bounded, evaluation that catches regressions, and privacy that survives an audit.

Read the practice ›

Problems we solve

  • A pilot that impressed the board but cannot be trusted with real customers.
  • Answers that are fluent and wrong, with no way to measure how often.
  • Data that cannot leave the country, the building or the device.

What you receive

  • AI readiness review
  • LLM feature build
  • On-device and private AI
Cloud

Cloud & Scaling

Systems that stay up at 10× load. Citizen portals, payment systems and marketplaces fail on their best day. We design for the traffic spike, the failed region and the 3 a.m. page, and we leave you with the dashboards and runbooks to operate without us.

Read the practice ›

Problems we solve

  • The portal falls over every time a deadline or an election drives traffic.
  • Outages are discovered by users before the team knows.
  • The cloud bill grows every month and nobody can say why.

What you receive

  • Architecture and scale review
  • Migration to AWS or Azure
  • Observability and on-call readiness
Security

Security & Identity

Identity done right. Most breaches start with identity: a home-grown login, a shared password, a token that never expires. We design access the way the platforms do it, and we review the rest of the system with the same care.

Read the practice ›

Problems we solve

  • A login system someone wrote years ago and nobody dares to change.
  • Ten internal tools, ten passwords, no single sign-on.
  • No passkeys, no multi-factor, no way to revoke access quickly.

What you receive

  • Identity and access design
  • .NET identity and platform hardening
  • Zero-trust and security review

How an engagement runs.

Four steps, each with a deliverable you keep. You can stop after any of them.

  1. Discover

    Two weeks inside your systems and your constraints. You receive a written assessment and the risks ranked.

  2. Design

    Architecture, identity and operations designed on paper first, reviewed with your team, costed before a line is written.

  3. Build

    Senior-led delivery in weekly demos. Tests, infrastructure as code and documentation ship with the features, not after.

  4. Operate

    Dashboards, alerts and runbooks handed to your team, with a defined support window and a clean exit.

Three ways to engage.

Advisory

Review and roadmap

Architecture, scale or security review in 2 to 4 weeks. You receive written findings ranked by risk and a sequenced plan your team can act on.

Talk to us ›
Build

Fixed-scope delivery

A senior-led team ships a defined scope with weekly demos, then hands over with runbooks, dashboards and training for the people who will run it.

Talk to us ›
Embedded

Fractional principal

A principal engineer or CTO inside your team, monthly, for the decisions that are expensive to get wrong: architecture, hiring, security, vendors.

Talk to us ›

Procurement questions.

The answers a procurement officer or CIO usually needs before the first call.

How do you contract?

Fixed-scope work is contracted per deliverable with milestone invoicing. Advisory and embedded work is a monthly retainer with a one-month notice. Public bodies can use their standard services agreement; we work through Albanian or Irish entities as the tender requires.

Do you sign NDAs?

Yes, before any system access or document exchange. We can start from your template or ours.

Where does our data live?

Where you decide. We design for EU regions by default and can work fully on-premise. Nothing is copied to a third-party AI service without a written decision from you.

Can you work on-premise or with our existing vendors?

Yes. Hybrid and on-premise designs are part of the practice, and we integrate with the vendors you already have rather than replacing them for the sake of it.

What documentation do we receive?

Architecture decision records, a security summary, operations runbooks and a handover document. Written so they can be attached to a tender file or an audit response as they are.

How do you hand over?

Every engagement ends with training sessions for your team, a support window agreed in advance, and a clean exit with no proprietary tooling left behind.

Let's build it properly.

Meet us at TIF32, Tirana, November 2026, or start the conversation now.

Contact ZoneTech