How we build_

Governance baked in, not bolted on.

The stack we build production AI on, the governance we ship with it, and why both together are what survives investor diligence, security review, and audit.

Book a readiness call
ONE DECISION, NOT TWO_

Most AI gets built fast and governed later. That order is the problem.

When governance is bolted on after a model already ships, the evidence your reviewers ask for has to be reverse-engineered under deadline — and the architecture often can't produce it without rework. Retrofitting is the costlier path: it shows up as a stalled funding round, a failed security review, or a procurement that quietly dies after the trust was sold on the product.

We make governance and engineering the same decision. The data class, the controls, the documentation and the evidence trail are designed at the start, alongside the code — so the system can answer hard questions because it was built to.

What that means for you

  • Diligence-ready — the evidence file exists before the call, not after it.
  • Reviewer-readable — architecture documented so a fractional CTO, CSO or investor reviewer can verify it.
  • No scramble — audit, retention and access answers are a lookup, not a project.
  • Lower total cost — governance designed in once beats governance retrofitted twice.
THE STACK WE BUILD ON_

A modern, production-grade toolchain — chosen for reliability and observability, not novelty.

Python + FastAPI

Our core for AI services and APIs — fast, typed, and well-suited to data and ML workloads.

Next.js

Modern, accessible frontends and interfaces, server-rendered where it counts.

NestJS

Structured, typed backend services where a robust application framework earns its keep.

Distributed microservices on AWS

Scalable, isolated services with tenant separation and infrastructure as code.

LangGraph + LangFuse

Agentic orchestration with full LLM tracing — every step and prompt is observable.

Production observability

Logging, tracing, and evaluation built in, so behaviour is measured, not assumed.

GOVERNANCE FROM DAY ONE_

The controls and documentation that turn "trust us" into "here's the evidence".

Article 9 from day one

Special-category data handled to the strictest UK GDPR bar — encryption, tenant isolation, access control, retention you set.

arc42 architecture docs

System design documented to a recognised template so reviewers can read and verify it, not just take our word.

DPIA

A Data Protection Impact Assessment that maps the risks of processing personal data, with mitigations recorded.

DCB0129 / DCB0160 clinical safety

Where clinical risk applies: hazard logs, a safety case, and a documented model behaviour envelope.

ISO 27001 control map

Information-security controls mapped to the standard, so security review has a structured answer.

Evidence trail

Audit logs, provenance, and a dossier aligned to the standard your reviewers actually use — ready before the call.

PLAIN ENGLISH_

The acronyms, in plain language — for founders who aren't engineers.

Article 9
The UK GDPR category for the most sensitive personal data — health, biometric, and similar. The strictest rules apply.
DTAC
The NHS Digital Technology Assessment Criteria — the baseline the NHS uses to assess a digital health product before adopting it.
arc42
A widely used template for documenting software architecture so other people can review and understand it.
DPIA
Data Protection Impact Assessment — a structured way to identify and reduce the privacy risks of handling personal data.
DCB0129 / DCB0160
NHS clinical-safety standards — for the manufacturer of a system (0129) and the organisation deploying it (0160).
ISO 27001
The international standard for managing information security in a business.
RAG
Retrieval-Augmented Generation — grounding an AI's answers in your own documents, with sources, rather than its training data alone.
Agentic AI
AI that takes multi-step actions to complete a task, rather than returning a single one-shot answer.

Building AI that has to survive scrutiny?

Tell us your data class and where the pressure is coming from — investors, a security review, or an NHS procurement. We'll map what's in scope and what to build first.