Skip to content
§1

Consulting

Engagements scoped against what actually breaks.

Three specialisms sit at the centre: cyber security, SEO, and answer engine optimisation, with ecommerce engineering as a fourth practice in its own right. The rest is built on the same depth. Every recommendation is grounded in having operated the system, not read about it.

§2

Core specialisms

The three the practice is built on.

Cyber Security ConsultingCybersecurity

From WordPress hardening to banking-grade security architecture. AI-assisted penetration testing, threat modelling, incident response frameworks, and security posture reviews that go beyond checkbox compliance.

  • Security audit: AI-powered penetration testing using Claude and Gemini, with scored reports covering configuration, code, infrastructure and DNS
  • Hardening and 2FA: login protection, passkeys, TOTP, brute-force controls, hidden login URLs, session management, mandatory admin enforcement
  • Threat monitoring: file integrity checking, SSH brute-force monitoring, web probe detection, new admin alerts, automated alerting
  • Banking-grade architecture: the security posture expected under regulatory scrutiny, applied at whatever scale you operate
SEO ConsultingSearch visibility

Technical SEO audits, on-page optimisation, and AI-driven content and metadata tooling that earn real organic traffic rather than vanity rankings. The same discipline is applied to our own published plugins.

  • Technical audit: crawl budget, indexation, canonicalisation, structured data validation, and Core Web Vitals against real field data rather than lab estimates
  • On-page optimisation: titles, meta descriptions, heading hierarchy and internal linking rebuilt around the search intent that converts
  • Structured data: Schema.org markup for products, articles, FAQs and organisations, the groundwork both classic search and answer engines depend on
  • Metadata at scale: AI-generated titles, descriptions and ALT text across an entire library
Answer Engine OptimisationAI answer engines

A growing share of discovery happens inside ChatGPT, Google AI Overviews and Perplexity rather than on a results page. AEO structures your content so those systems cite and recommend you, not just rank you.

  • Content structured for direct extraction: clear claims, defined terms, answerable questions
  • llms.txt and machine-readable content maps for AI crawlers
  • FAQ and HowTo schema tuned for citation, not just rich snippets
  • Entity and authorship signals (E-E-A-T) that answer engines weight when choosing a source
  • Comparison and definitional content that AI systems reach for by default
  • Citation monitoring: tracking when and how often you are referenced across major AI assistants
  • Freshness and update signals so crawlers keep re-indexing your best pages
  • Brand mention audits to catch where AI answers get you wrong, and fix the source
§3

Ecommerce Development

Most ecommerce work is a store build. This is the engineering underneath one.

A storefront is the only system where a bug has a running total. An oversell costs you a customer and a refund, a slow product page costs you the sale before anyone sees the price, and a checkout that drops a webhook costs you an order you will never know you lost. We build the commerce layer the way we build banking infrastructure, because the failure modes are the same shape: money moving, inventory that must agree with itself, and integrations that cannot be allowed to silently diverge.

What it costs when it is wrong
  • CostA checkout that fails under load fails at your busiest hour, not your quietest
  • CostOverselling is an inventory integration problem, not a warehouse problem
  • CostPayment reconciliation gaps surface weeks later, in accounting, not in alerts
  • CostPage speed on a product page is a revenue number, not a Lighthouse score
  • Commerce platform: WooCommerce and custom or headless storefronts, with product catalogue and SKU architecture built to stay fast as the range grows
  • Checkout and payments: gateway integration (PayPal, Stripe), subscriptions, refunds, webhooks, reconciliation, fraud controls, PCI-conscious architecture
  • Orders: full lifecycle and status management, cancellations, returns and refunds, integrated across warehouse and shipping carriers
  • Inventory: stock availability and reservations, multi-location inventory, and ERP/WMS integration so the storefront never oversells
  • Fulfilment: courier API integration, shipping rules, tracking, and click-and-collect workflows
  • Customer: accounts, guest checkout, loyalty, vouchers and promotions, transactional email and SMS
  • Integration: ERP, accounting, CRM, warehouse, payment and courier APIs wired into checkout and order events, not bolted on after launch
  • Performance: caching, CDN, database tuning, observability and high availability on the pages that drive revenue
  • Security: authentication hardening, bot protection, vulnerability management, payment isolation, POPIA/GDPR-conscious data handling
§4

Supporting services

Built on the same engineering depth.

AWS & Cloud ArchitectureCloud infrastructure

Architecture designed for workloads that actually break things, not for certifications or slide decks. From EC2 instance sizing to multi-region Aurora replication, VPC design to Lambda cost optimisation.

  • EC2 right-sizing and auto-scaling strategy
  • RDS Aurora multi-region replication design
  • VPC architecture, subnetting and security groups
  • S3 lifecycle policies, intelligent tiering, cost control
  • Lambda architecture and cold-start mitigation
  • CloudFront and WAF configuration for high-traffic sites
  • Infrastructure-as-code review (Terraform / CDK)
  • Cost audits: cut waste without cutting capability
Platform Rearchitecting & RecoveryPlatform engineering

Inherited a broken platform? Scaled past what your architecture can handle? Facing a cloud migration that has already gone wrong? We diagnose and fix large-scale platforms, from modernising legacy monoliths to recovering stalled migrations.

  • Platform health assessment: identify structural failure points before they hit production
  • Legacy monolith decomposition: strategic service extraction, not big-bang rewrites
  • Cloud migration recovery: diagnose and fix migrations that have stalled or degraded
  • Scaling failure analysis: systems that worked at 10k users and collapse at 10M
  • Data architecture remediation: schema rot, query degradation, replication lag under load
  • Dependency map and blast-radius analysis for large distributed systems
  • Technology strategy for the board: costed, credible and deliverable
  • Phased remediation roadmap, prioritised by risk and business impact
Database ArchitectureData

Schema design, query optimisation, replication strategy and migration planning honed across banking-grade transactional workloads. MariaDB, PostgreSQL, Aurora, and the query patterns that cause silent production degradation.

  • Schema review and normalisation for high-write workloads
  • Slow query analysis and index strategy
  • Aurora multi-region failover and replication lag management
  • Migration planning from legacy MySQL/MariaDB to Aurora
  • Read replica architecture for analytics separation
  • Connection pooling and PgBouncer/ProxySQL configuration
AI IntegrationApplied AI

Practical AI integration using frontier models, not wrappers. Anthropic Claude and Google Gemini wired into your actual workflows, with real data privacy: your data goes directly to the provider, never through a middleman.

  • AI-powered security audit and penetration testing pipelines
  • Content generation workflows: SEO, metadata and summaries at scale
  • Update risk scoring: AI reads changelogs so your team does not have to
  • Category and content taxonomy analysis at scale
  • AI debugging assistants for PHP and WordPress production errors
  • Custom Claude or Gemini API integration into existing toolchains
Networking & InfrastructureInfrastructure

The unglamorous work that keeps production running. BGP routing, SD-WAN, Cloudflare Workers, DNS architecture, TLS certificate management, and the networking decisions that look simple until they fail under load.

  • Cloudflare architecture: Workers, Tunnels, Access, R2, D1 and WAF configuration
  • CDN strategy and cache rule design
  • TLS and certificate management
  • DNS architecture and failover design
  • Zero Trust network access: identity-aware access without a VPN
  • BGP and SD-WAN routing decisions
Enterprise Content ManagementContent & document governance

Architecture, governance and workflow for organisations managing thousands of documents and pages at scale, the unglamorous structure that decides whether content stays findable and compliant, or turns into an unmanageable archive.

  • Information architecture: taxonomy, metadata schema and content modelling designed for how people actually search, not how the org chart is drawn
  • Workflow and approval: review, approval and publishing pipelines with clear ownership at every stage, automated where it removes friction and not before
  • Access and audit trails: role-based access control and full change history, built for regulated environments
Web DevelopmentCustom builds

Custom websites and web applications built for performance and maintainability, engineered to survive well past launch day. Framework agnostic, and chosen for the problem rather than the trend.

  • Frontend architecture review: component structure, state management, bundle size discipline
  • Core Web Vitals engineering: real fixes to LCP, INP and CLS, not Lighthouse theatre
  • API design and integration: REST, GraphQL and third-party service wiring done cleanly
  • CMS-agnostic builds: headless or traditional, chosen on merit for the actual content workflow
  • Accessibility review against WCAG, treated as a requirement rather than an afterthought
  • CI/CD pipeline design for reliable, low-drama deployments
  • Security-hardened deployment: the same patterns shipped in our own plugin suite
  • Legacy site modernisation without a risky all-at-once rewrite
WordPress DevelopmentWordPress engineering

Custom themes, plugins and integrations held to the same engineering standard as our own commercial plugin suite: PHPCS clean, security reviewed, and built to pass WordPress.org's own Plugin Check before it ever ships.

  • Custom plugin development to WordPress coding standards, with the nonce checks, sanitisation and escaping most plugins skip
  • Theme development: custom themes and block editor patterns built for the content team that has to use them daily
  • Hardening and performance: object cache configuration, query profiling, and the same hardening shipped in Cyber & Devtools
§5

Action

Tell us what is breaking.

A security posture you are not sure about, search traffic that has stalled, or a platform that has outgrown its architecture. No gatekeeping and no sales process. The reply comes from Andrew.