Technologies
Open source, vendor-neutral, production-proven
We work with technologies that have real communities behind them and a credible operating story at scale. Below is where we spend most of our time — the list moves as the ecosystem does.
Streaming and messaging
Apache Kafka
The default event backbone. Most of our platforms have one.
Apache Pulsar
When multi-tenancy and geo-replication are first-order requirements.
Apache Flink
Stateful stream processing, exactly-once, at real volume.
Redpanda
Kafka protocol without the JVM, where operational simplicity wins.
Debezium
Change data capture from existing databases, without touching the application.
Distributed data stores
Apache Cassandra
Write-heavy workloads that must survive a datacentre going dark.
ScyllaDB
Same data model, fewer nodes, when latency budgets are tight.
OpenSearch
Search and log analytics, and the base of our managed SIEM.
PostgreSQL
Still the right answer more often than the architecture diagram suggests.
ClickHouse
Analytical queries over very large tables, at interactive speed.
Cloud and orchestration
Kubernetes
Any distribution, any cloud, and on bare metal when the economics say so.
Terraform
Infrastructure as code, in modules your team owns and reuses.
Helm
Packaging and release management for what runs in the cluster.
Argo CD
Git as the single source of truth for cluster state.
AWS · GCP · Azure
All three, plus European and on-premise hosting when sovereignty requires it.
Observability
Prometheus
Metrics and alerting, with rules tuned to your failure modes.
Grafana
Dashboards built to answer incident questions, not to look full.
OpenTelemetry
Vendor-neutral instrumentation, so changing backend is not a rewrite.
Loki
Log aggregation whose cost tracks volume rather than a licence.
Thanos
Long-term metric retention and global query across clusters.
AI and machine learning
Kubeflow
Training and pipeline orchestration on the cluster you already run.
MLflow
Experiment tracking and a model registry that outlives the data scientist.
Ray
Distributed training and batch inference without bespoke plumbing.
vLLM
Self-hosted LLM serving, with throughput that makes the GPU bill defensible.
Feast
A feature store when several models start needing the same data.
Security
HashiCorp Vault
Secrets, certificates and dynamic credentials — no passwords in Git.
Wazuh
Host-level detection and file integrity, feeding the SIEM.
Falco
Runtime detection inside the cluster, at the syscall level.
Trivy
Image and dependency scanning, wired into the delivery pipeline.
Keycloak
Single sign-on and access control across the platform.
Not seeing yours? Ask. This is what we run most often, not the limit of what we work with.
Let’s talk about what your platform needs
Tell us what you are building, or what is keeping you up at night. We will tell you plainly whether we are the right team for it.