What we do

What We Do

Four areas of work. Each follows the same approach: a short assessment, then consulting, engineering, products or ongoing operation to match the need; always with a named project lead and a record of what was verified. This page describes each field, how our team works in it and how to begin.

Software Engineering

consultancy · engineering · operation

Where our work began: systems built around a specific business, integrations between systems that do not talk to each other, and staged modernization of what already exists. We document the architecture before writing code, and each delivery comes with evidence that the system does what the documentation describes.

How we engage

Architecture review in two weeks; fixed-scope project or time and materials; monthly operation or handover to the client's team with the knowledge they need documented.

Python · TypeScript · Node.js · React · Flutter · PostgreSQL

What we practice

  • Architecture and system design
  • APIs, queues, events and integrations
  • Legacy systems and data migration
  • Web and mobile applications
  • Data modeling and reporting
  • Testing, continuous integration and observability

Software Engineering in Detail

Applied Artificial Intelligence

engineering · platform · operation

We develop high-end AI solutions, led by specialists: applications that carry out real work, agents that work within defined permissions, infrastructure to run models wherever the client decides, and active defense against breach attempts. All of it is built on Arquipélago, our agentic operating system.

How we engage

AI inventory and governance in three weeks; one agent or application per fixed-scope engagement; AI infrastructure design and operation; Arquipélago components built to measure.

Commercial and open models · MCP · APIs · runs in the client's environment or ours

What we practice

  • Applications and agents for real processes
  • Internal search and knowledge with citations
  • AI infrastructure and open models
  • Active defense and adversary emulation
  • AI inventory, policy and governance
  • Arquipélago and specialized components

Artificial Intelligence in Detail · Arquipélago

Infrastructure and Data Centers

design · construction with partners · operation

We design servers, cloud solutions and hybrid environments around each client’s requirements, with secure connectivity and tested recovery. For server rooms, data centers and AI infrastructure, we deliver complete facilities with partners in civil construction and energy.

How we engage

Infrastructure review in two to three weeks; design and construction; operation under a monthly agreement with written obligations; construction and power coordinated by us and carried out by partners.

High availability · secure access · automation · scalability · disaster recovery

What we practice

  • Purpose-built, hardened servers
  • Cloud Solutions and Hybrid Environments
  • Encrypted networks and remote access
  • Identity management, observability and automation
  • Storage and backup
  • Server rooms and data centers

Infrastructure in Detail

Security and Compliance

consultancy · engineering · retainer

The discipline that runs through the other fields. It begins with a written threat model, applies security and governance from the design stage, carries LGPD and GDPR compliance through to implementation, prepares companies for certifications and maintains that protection under a retainer. We defend the operation against intrusion attempts and rehearse the response in case one succeeds.

How we engage

Threat model assessment in two to three weeks; LGPD and GDPR readiness; certification readiness; fixes built by us; monthly retainer with control reviews and handling of questionnaires and data-subject requests.

LGPD · GDPR · ISO/IEC 27001 and 27701 · SOC 2 Type II · TISAX · PCI DSS · NIS2 · DORA · HIPAA · CCPA

What we practice

  • Threat modeling
  • Security and governance by design
  • LGPD, GDPR and international transfers
  • Certification and regulatory readiness
  • Security assessment and hardening
  • Rehearsed incident response

Security and Compliance in Detail

Partners and vendors

Our partners and suppliers are leaders in their markets.

Some of our work depends on products and services from other companies. We assess each supplier’s security, availability, integration, support and technical evidence. We then examine the evidence the vendor has made available for independent verification.

Certifications and attestations we look for: ISO/IEC 27001 and 27701, SOC 2 Type II, TISAX, PCI DSS, ISO/IEC 27017 and 27018. Regulatory requirements vendors must be equipped to meet when they apply to the client: LGPD and GDPR, HIPAA, NIS2, DORA, CCPA and CPRA, FINRA and SEC rules. None of these attestations is enough to secure our choice; they guide the questions we ask, but choosing a partner requires more than credentials and certifications—it requires confidence in their excellence.