Skip to content
GenGraphic

Web applications

Web applications that hold up once real users depend on them.

We build browser-based products for companies that have outgrown spreadsheets, generic tools, or a first version that cannot scale — with the architecture, permissions, and data handling a growing business actually needs.

Problems this solves

Signals a custom web application is the right investment

  • A spreadsheet or generic tool has become the unofficial system of record for a core process.

  • Different teams or customer types need different permissions, views, and workflows in the same system.

  • An existing internal tool has become slow, unmaintainable, or too risky to change.

  • Customers or partners need a self-service interface instead of manual handling by staff.

  • The business needs a single, connected view of data that currently lives in separate tools.

What we deliver

  • Product and technical discovery

    A clear definition of users, roles, workflows, and data model before code is written.

  • A maintainable architecture

    Server-rendered where it matters for speed and SEO, with clear boundaries between frontend, backend, and data layers.

  • Role-based access control

    Permissions enforced on the server, not just hidden in the interface.

  • Testing and documentation

    Automated tests for critical paths, and documentation the team can hand over.

How the engagement works

From discovery to a maintained production system

  1. 01

    Discovery

    Define users, workflows, data model, integrations, and success criteria.

  2. 02

    Architecture

    Choose the technical approach: rendering strategy, data layer, hosting, and security model.

  3. 03

    Build in iterations

    Ship visible, testable increments rather than one large release at the end.

  4. 04

    Launch and support

    Monitor, fix, and extend the application as real usage reveals new requirements.

Relevant technologies

Selected for the problem, not by default

Frontend

  • Next.js
  • React
  • TypeScript

Backend

  • Node.js
  • PostgreSQL
  • Appwrite
  • REST and GraphQL APIs

Infrastructure

  • Docker
  • Vercel
  • Hetzner
  • CI/CD

Security and operational considerations

What we account for by default

  • Server-side validation and sanitisation of all user input.

  • Least-privilege access for every role, checked on every request.

  • Security headers and a content security policy appropriate to the integrations used.

  • Rate limiting on public forms and endpoints.

  • Structured logging for failures, without recording sensitive data.

FAQ

Common questions

Both, when the project needs it. We work across frontend, backend, data, and infrastructure so the application is designed as one coherent system rather than disconnected pieces.

Have a web application that needs to be built or rescued?

We use privacy-friendly analytics to understand how the site is used. No non-essential tracking runs before you accept. Read our cookie policy.