Custom Web Applications
The system your business runs on, built for the rules you answer to.
Some work will never fit on a workflow canvas. When what you need is a real application, with its own data model, its own permission rules and its own audit trail, that is what we build. Next.js and Supabase, deployed on infrastructure you own. The regulatory questions get answered while the data model is being drawn, which is far cheaper than answering them after a security review sends the whole thing back.
- Internal platforms that replace the spreadsheet the whole company quietly depends on
- Client portals with access rules per organisation, per role and per record
- Dashboards reading live from the ERP instead of last month's export
- An audit trail on every write, because somebody eventually asks who changed it
- Microsoft or Google SSO, so access ends the day an employee does
- Deployed in your own cloud account, in the region your regulator expects
When an application is the right answer
Automation moves data between systems that already exist. An application is what you need when the system itself does not exist yet: when several people work the same records at once, when who may see what is a real question, when the state of the work has to be visible to someone who was not in the room. If your problem is really six spreadsheets and an inbox, an application is the honest answer and a workflow is not. If it is one process handing data between tools you already pay for, we will tell you to automate it instead and charge you less.
Regulation belongs in the data model, not in a later phase
Personal data, retention, who may read which row, what gets written to an audit log: these are schema decisions, and retrofitting them means rewriting the middle of an application. We settle them in the first week. Recent builds have run under GDPR, ISO 27001 and SOC 2 expectations, on client-owned servers, with access limited to approved addresses and key-based login only. For a client whose IT provider ran the review, we worked to their requirements rather than asking them to accept ours.
Complex, and still usable in weeks
A large application does not have to start large. We build the narrowest version that a real person can use on real data, put it in front of them, and grow it from there. One recent platform started at a single screen and reached 27 tables, and every step of that was in front of the client while it happened. You see the thing working long before it is finished, which is the only way to catch a wrong assumption while it is still cheap.
Questions we get asked
What do you build on?
Next.js and Supabase for most of it, Postgres underneath, Python where the work is data-heavy. All of it is ordinary, well-documented technology that another developer can pick up. We avoid anything that would leave you dependent on us for a reason other than the fact that we built it.
Our data cannot leave Israel. Is that a problem?
No. Deployment goes to your own cloud account in the region you need, and we have run builds on client-owned servers where nothing touches our infrastructure at all. Where a model is involved, it runs through accounts you own, so the usage and the data trail are yours.
Our security team will review this. What do they get?
The architecture, the data model, where personal data sits, the access rules, the audit logging and the deployment setup, written down rather than described in a call. That review has happened on our builds before and the finding list is the normal one, not a rebuild.
Can our own developers take it over?
Yes, and some clients plan for that from the start. You own 100% of the code and the IP. Handover is the repository, the environment variables, the migrations and a working session with whoever will own it, on the actual system rather than on a slide.
Tell us what's slowing your business down.
30 minutes. No pitch, no deck. Just listening to your needs and seeing how we can help.
Schedule a discovery call