Regulated and assurance-grade software

Some records have to be defensible years after they were written, to someone who was not there and has no reason to trust the system that produced them. That is a different engineering problem from storing data correctly.

We build for it directly: cryptographic integrity over each record, an amendment history that adds rather than overwrites, and a verification endpoint a third party can call without an account, so a document can be checked against the system that issued it. Access and change are logged as evidence, not as debug output.

Where an external standard governs the work, digitising it correctly is most of the job — the rules, the exceptions and the wording, read as written rather than as assumed. Data stays in the UK, under GDPR, in a region the client can name.