Public software is judged by its worst day, not its best.
Nobody writes about the portal that worked. They write about the one that fell over on deadline day, the one a screen reader could not complete, the one whose audit log did not exist when the inquiry asked for it. So the question is not whether a service can be built — it is what it does at the surge, on a five-year-old phone, on a bad connection, in Arabic, with no mouse, on the day the law says it must open. We have shipped that, twice, for two national governments on two continents — and we do not build lock-in: you should be able to end the contract and lose nothing but us.
We run it as a Launch Risk Review: bring one service, live or in build. In 30 minutes we map its critical path to the fixed date, its accessibility exposure against WCAG 2.2 AA, and its security and data-residency exposure. You keep a one-page written assessment — usable as an internal briefing or an annex to a risk register. Not a sales demo, not a capability deck, no procurement obligation.
What we take on, and what we do not bid for
SCOPE OF ENGAGEMENT
Ministries and agencies, state and municipal government, public-health and transport authorities, and the systems integrators who have already won the framework and need a delivery team that will not slow their programme down.
The build, a workstream inside your prime’s delivery, or a fixed-scope package under an existing vehicle — from one agency’s internal service up to a national citizen-facing platform. Under your governance, in your repositories, with your reporting cadence.
We are not a prime on multi-year framework megaprojects, and we will not pretend otherwise to win a page view. What you get instead of a bid team is the senior engineers who do the work, with architecture signed off on every project.
Public work is won in rooms like this, then judged on its worst day.
Six situations we are usually called into
FILED SITUATIONS
The date is in the legislation, not the sprint board
The service must be open when the statute commences or the event opens. Scope can move, quality cannot, and the date will not. The team you have can build it in nine months. You have five.
Nobody will touch the back end
A twenty-year-old system the whole agency depends on, a nightly batch window that dictates every design decision, no current documentation, and the two people who understood it have retired. Everyone agrees it must be modernised. Nobody wants to be the one who breaks pension payments.
Accessibility arrives as a blocker two weeks out
The audit comes back with issues that are not CSS tweaks: a custom date picker no screen reader can operate, a status flow with no text equivalent, error messages announced to nobody. The assessment is booked. Remediation is now a re-architecture with no time to do it.
Three agencies, three versions of the same person
Health has one address, revenue has another, the municipality has a third, and the citizen has told all of them. Every attempt to reconcile it becomes a governance argument about who is authoritative — and the service you are building has to work anyway.
The surge lands in one hour
A registration window opens, a crisis puts the service on the front page, a deadline funnels a nation into one form. Load that took a week in testing arrives in ninety minutes, and the failure mode is a queue that loses people’s submissions rather than one that holds them.
The previous supplier is gone
You have a repository that will not build, no runbook, credentials in a leaver’s account, and a change request the department needs before the end of the quarter.
Ministry-grade content, bilingual with full right-to-left layout, and a release path that satisfies a government communications office as well as two app stores.
One application, and the record it leaves behind
CASE 2026-004182
Auditability is not a feature you add at the end; it is what each state writes as it happens. Step through a single citizen application and watch the register fill in beside it — actor, action, reason, retention. This is what we mean when we say the audit trail is a delivery requirement.
Led from Ireland with a senior team across Europe, working EU hours with a full US-morning overlap — and contracting through Fluvius USA Inc on US paper.
The delivery record
FOUR ENGAGEMENTS
Two named national governments on two continents, plus defence-adjacent and security engineering beside them. Very few agencies this size have shipped a live national-scale public service — we say so because it is true, and because it is the whole argument.
Citizen and consular services, live in both public app stores
A Flutter application delivering consular and citizen services to the public. Ministry-grade content, bilingual with full right-to-left layout, and a review-and-release process that has to satisfy a government communications office as well as two app stores. The constraint that shapes everything is that a ministry cannot ship a correction quietly.
National epidemic control — inbound travel and public-health protocols
Traveller submissions, protocol enforcement and the operational reporting behind them, at the scale of everyone entering a country. The hard part was not the feature list: it was standing a national service up against a date set by public-health policy, then operating it while the rules changed underneath it.
A unified cybersecurity platform
Detection, response and remediation in one system, with kernel-level detection and automated remediation. Low-level engineering where a false positive costs an analyst their whole morning and a missed detection costs considerably more. The client, sector and deployment scale stay withheld.
Detection to operator handoff in four seconds
Acoustic, RF, EO/IR and radar reduced to validated tracks an operator can act on. This is the case that answers whether we can do hard real-time and defence-adjacent work: the deadline is not a sprint, it is four seconds.
The Launch Risk Review looks at your service the way we looked at those: critical path, accessibility exposure, residency exposure, and what has to be true to hit the date.
What we deliver, and what you hold at the end of it
SCHEDULE OF SERVICES
Timelines are indicative and depend on scope — said once here rather than hedged on every line. Every engagement ends with artefacts in your possession, not a promise of them.
Citizen-facing mobile and web services
A service a member of the public can complete on the phone they already own, in their language, on a bad connection — including right-to-left layouts and first-generation smartphones.
You get: the apps in the stores or the service behind your domain; WCAG 2.2 AA tested with assistive technology and not only a scanner; source and CI in your repositories. Mobile development → · Qatar MoFA case →
National-scale platforms under a fixed date
When the date is set by policy or an event. Scope negotiated down to what must be live on day one, the rest sequenced behind it — the epidemic-control-platform pattern.
You get: a critical path, a load profile with the surge modelled, a degradation plan for each dependency, and a service that opens on the date. Read the case →
Legacy modernisation and documented handover
Strangler-fig migration around the batch window rather than a cutover weekend that has to go perfectly. One slice at a time, behind the same interface.
You get: each slice in production, an architecture document that matches reality, and a runbook a different supplier could take over from. Legacy modernisation →
Accessibility remediation to a stated conformance level
A dated conformance target and the work to reach it — starting with the custom controls that turn an audit into a re-architecture.
You get: an audit against WCAG 2.2 AA with assistive-technology evidence, fixes shipped in priority order, and documentation your procurement team can put behind a Section 508 or EN 301 549 answer. UI/UX & accessibility →
Security engineering and detection tooling
Detection, response and remediation built as product rather than bought as a dashboard — the engineering behind our EDR, SIEM, IPS and IDS work.
You get: instrumentation, alerting that survives an on-call rotation, and a penetration-test remediation cycle rather than a report that sits in a drawer. Security audit & hardening →
Sensor and data-fusion systems
Multiple sensor streams reduced to something an operator can decide on inside seconds, from the PanoptesAI lineage.
You get: the fusion pipeline, the confidence model and the operator view. PanoptesAI case →
API and interoperability layers
Getting two agencies’ systems to agree without a shared database — including FHIR profiles where health data is in scope.
You get: a published OpenAPI contract, a versioning and deprecation policy, and an audit trail on every exchange. API integrations →
Embedded senior engineers alongside an integrator’s team
We take a workstream inside your delivery, under your governance, at your reporting cadence.
You get: engineers in your standups and a subcontract that does not create a second programme to manage. Engineering team →
Detection, response and remediation built as product rather than bought as a dashboard — where a false positive costs an analyst a morning and a missed detection costs more.
What you are thinking, answered
QUESTIONS ON NOTICE
- A visible skip link, styled as part of the page rather than hidden until it is needed.
- Focus indication is designed in: a 3px amber outline with an offset, on every interactive element.
- The case walkthrough above is fully keyboard-operable — buttons, arrow keys, Home and End — and every state change is announced through a live region.
- Text contrast meets AA on both the ink and paper surfaces; colour never carries meaning alone (states are labelled as well as coloured).
- Motion is limited to two entrance fades, both removed under
prefers-reduced-motion; the walkthrough works without any animation. - Semantic landmarks, one
h1, and headings in order; every form control has a real label.
The Launch Risk Review is run by an engineer who has opened a national service on a date that could not move — not by a bid team.
Not ready to talk? Complete the form instead
FORM LR-24
Launch readiness for a public service: 24 checks before you commit to a date
Accessibility and the assessment, audit and records, data protection and residency, the worst day, and handover. Each check asks for the evidence rather than an opinion — mark it where somebody could produce that evidence today, and leave it blank where nobody knows. The blanks are the plan.
Bring one service. We will tell you what the date depends on.
LAUNCH RISK REVIEW
Thirty minutes with an engineer who has opened a national service on a date that could not move. We map the critical path, the accessibility exposure against WCAG 2.2 AA, and the security and residency exposure — then say plainly what would have to be true to hit the date.
- You keep the one-page written assessment
- An engineer on the call, not a bid team
- No demo, no capability deck, no procurement obligation