Services
Four practices, one team — end to end.
We don't outsource. Every line of code, every Supabase policy, every App Store submission ships from the same studio.
Custom iOS & macOS Apps
End-to-end native development on Apple platforms. We design, build, and ship apps that feel like Apple wrote them — fast launches, modern SwiftUI, deep system integrations.
- SwiftUI + Swift Concurrency, iOS 17+ targets
- Sign in with Apple, In-App Purchase, Push, Live Activities
- Camera + VIN/barcode scanning, CoreML on-device inference
- App Store submission, TestFlight rollouts, ASO setup
Recent work
Used-car dealer needed a phone-only auction & inspection app for buyers in the field — shipped to TestFlight in 6 weeks, App Store in 9.
Modern Web Platforms
Web platforms engineered for scale and security from day one. Modern React, edge-rendered, with hardened auth and database-level access control.
- Next.js 16 App Router, Server Components, Cache Components
- Supabase Postgres with RLS, row-level audit trails, RPCs
- Vercel deploys, preview URLs, edge middleware
- Stripe billing, OAuth providers, multi-tenant patterns
Recent work
Multi-tenant pet-services platform handling 30k+ service events with row-level isolation and live status streaming to clients.
AI Integrations
Production AI features that actually move the business — not novelty chatbots. We focus on tool-calling agents, structured extraction, and domain-tuned assistants.
- OpenAI + Anthropic SDKs with prompt caching and streaming
- Function/tool calling that touches real systems
- Bilingual (EN/ES) intent classification and NLU
- Custom RAG over your data with Supabase vector search
Recent work
AI inspection assistant that ingests photos and a VIN, returns a structured condition report, and flags red-flag damage in under 6 seconds.
Security & Audits
Independent reviews of your stack focused on the OWASP top 10, RLS coverage, secret hygiene, and platform-level posture. Pragmatic remediation, not theater.
- Row Level Security review across every Supabase table
- Auth flow hardening (OAuth, refresh tokens, session boundaries)
- Secret audit (env files, public bundles, deploy logs)
- Headers, CSP, CORS, rate limits, abuse vectors
Recent work
Audited a marketplace's Supabase project, surfaced 14 missing RLS policies and 3 exposed secrets — fixed in a single sprint.
Not sure where to start?
We do free 30-minute scoping calls. No pitch deck.