Skip to content
Reference architecture

This is what we hand over.

A composite of the systems we build: typed at every boundary, observable end to end, and deployable by your team without us in the room.

system.topologylive traffic
EDGEAPPLICATIONDATA & MODELSOPERATIONSClientsWeb · Mobile · Partner APIEdge / CDNCache · WAF · TLSAPI GatewayAuthN/Z · Rate limitServicesNode · FastAPI · typedWorkersAsync jobs · retriesOLTPPostgreSQL · replicasModel layerInference · eval · fallbackVector storepgvector · citationsTelemetryOpenTelemetry · tracesCI / CDIaC · progressive delivery

Scroll to pan the diagram

Typed at every boundary

Schemas are versioned and generated into clients. No untyped JSON crossing a service line, and no silent contract drift between teams.

Grounded, not guessed

Anything a model outputs can be traced to the source that produced it. Where there is no grounding, the system escalates to a person instead of inventing an answer.

Reproducible from zero

Every environment can be rebuilt from a clean cloud account with infrastructure as code. Nothing important exists only in someone's console history.

Reversible by default

Progressive delivery, feature flags, and a rollback path that is tested rather than assumed. A bad release is an inconvenience, not an incident.

In practice

What that looks like in code.

Three things we write on almost every engagement: a release path that can undo itself, an evaluation gate that blocks a quality regression, and a retrieval step that escalates rather than invents.

// Blue/green rollout with automatic rollback
export async function release(svc: Service) {
const next = await svc.provision({ replicas: 12 })
await next.warm()
if (await healthy(next, { p99: 80 })) {
return svc.cutover(next)
}
await svc.rollback()
throw new ReleaseError("p99 regression")
}
typecheck passing
zsh — codeaex
$

Non-negotiables

  • Every deploy is reversible without a database restore.
  • Every job is idempotent and safe to replay.
  • Every alert points at a runbook that has been rehearsed.
Engagements

Tell us what is breaking.

Send the problem, not a polished brief. An engineer reads every enquiry and replies within two working days with a real technical opinion — including when the honest answer is that you do not need us.

  • Reply from an engineer, not a salesperson
  • Fixed scope and price before any build starts
  • Your code, your cloud, your repo — from day one