What We Do
Four areas of work. Each follows the same approach: a short assessment, then consulting, engineering, products or ongoing operation to match the need; always with a named project lead and a record of what was verified. This page describes each field, how our team works in it and how to begin.
Software Engineering
consultancy · engineering · operation
Where our work began: systems built around a specific business, integrations between systems that do not talk to each other, and staged modernization of what already exists. We document the architecture before writing code, and each delivery comes with evidence that the system does what the documentation describes.
How we engage
Architecture review in two weeks; fixed-scope project or time and materials; monthly operation or handover to the client's team with the knowledge they need documented.
Python · TypeScript · Node.js · React · Flutter · PostgreSQL
What we practice
- Architecture and system design
- APIs, queues, events and integrations
- Legacy systems and data migration
- Web and mobile applications
- Data modeling and reporting
- Testing, continuous integration and observability
Applied Artificial Intelligence
engineering · platform · operation
We develop high-end AI solutions, led by specialists: applications that carry out real work, agents that work within defined permissions, infrastructure to run models wherever the client decides, and active defense against breach attempts. All of it is built on Arquipélago, our agentic operating system.
How we engage
AI inventory and governance in three weeks; one agent or application per fixed-scope engagement; AI infrastructure design and operation; Arquipélago components built to measure.
Commercial and open models · MCP · APIs · runs in the client's environment or ours
What we practice
- Applications and agents for real processes
- Internal search and knowledge with citations
- AI infrastructure and open models
- Active defense and adversary emulation
- AI inventory, policy and governance
- Arquipélago and specialized components
Infrastructure and Data Centers
design · construction with partners · operation
We design servers, cloud solutions and hybrid environments around each client’s requirements, with secure connectivity and tested recovery. For server rooms, data centers and AI infrastructure, we deliver complete facilities with partners in civil construction and energy.
How we engage
Infrastructure review in two to three weeks; design and construction; operation under a monthly agreement with written obligations; construction and power coordinated by us and carried out by partners.
High availability · secure access · automation · scalability · disaster recovery
What we practice
- Purpose-built, hardened servers
- Cloud Solutions and Hybrid Environments
- Encrypted networks and remote access
- Identity management, observability and automation
- Storage and backup
- Server rooms and data centers
Security and Compliance
consultancy · engineering · retainer
The discipline that runs through the other fields. It begins with a written threat model, applies security and governance from the design stage, carries LGPD and GDPR compliance through to implementation, prepares companies for certifications and maintains that protection under a retainer. We defend the operation against intrusion attempts and rehearse the response in case one succeeds.
How we engage
Threat model assessment in two to three weeks; LGPD and GDPR readiness; certification readiness; fixes built by us; monthly retainer with control reviews and handling of questionnaires and data-subject requests.
LGPD · GDPR · ISO/IEC 27001 and 27701 · SOC 2 Type II · TISAX · PCI DSS · NIS2 · DORA · HIPAA · CCPA
What we practice
- Threat modeling
- Security and governance by design
- LGPD, GDPR and international transfers
- Certification and regulatory readiness
- Security assessment and hardening
- Rehearsed incident response
Our partners and suppliers are leaders in their markets.
Some of our work depends on products and services from other companies. We assess each supplier’s security, availability, integration, support and technical evidence. We then examine the evidence the vendor has made available for independent verification.
Certifications and attestations we look for: ISO/IEC 27001 and 27701, SOC 2 Type II, TISAX, PCI DSS, ISO/IEC 27017 and 27018. Regulatory requirements vendors must be equipped to meet when they apply to the client: LGPD and GDPR, HIPAA, NIS2, DORA, CCPA and CPRA, FINRA and SEC rules. None of these attestations is enough to secure our choice; they guide the questions we ask, but choosing a partner requires more than credentials and certifications—it requires confidence in their excellence.