Skip to main content
/stackTechnology

The stack, the standards and the practice

Named technologies and named standards. If something is on this page you can ask us to talk through a decision we made with it.

Frontend
  • React 18
  • TypeScript
  • Vite
  • Tailwind CSS
  • React Native

Component architectures with a real accessibility budget, not a checklist at the end.

Backend
  • PHP 8.3
  • Laravel
  • Node.js
  • Go
  • Python

Service boundaries drawn around data ownership, not around team structure.

Data
  • MySQL 8
  • PostgreSQL 16
  • Redis
  • ClickHouse
  • Elasticsearch

Schema and migration strategy agreed before the first table exists.

Platform
  • Docker
  • Terraform
  • AWS
  • Azure
  • GitHub Actions

Infrastructure in version control, with the same review process as application code.

Standards we work to

Named standards, with the limits stated

Two of these are targets we design to and one is a control model we follow without holding the certificate. We say which is which, because a vague compliance claim is worth less than an accurate one.

OWASP ASVS
Application Security Verification Standard — the checklist our code audits are run against.
Regulation (EU) 2016/679 (GDPR)
Data protection by design in every system that touches personal data: minimisation, retention limits, and a documented lawful basis.
ISO/IEC 27001 Annex A
Our internal controls are modelled on Annex A. 25dbr OÜ is not certified to ISO/IEC 27001 and does not claim certification.
WCAG 2.2 AA
The accessibility target for interfaces we build, including this website: keyboard operation, contrast, and a visible focus state.

Engineering practice

Architecture before implementation

Every engagement starts with a written technical brief: the domain model, the integration map and the decisions we are making, with their trade-offs recorded.

Your repositories, your accounts

Code is written into infrastructure you own from day one. There is no vendor lock-in step at the end of a project because there is nothing to hand over that you did not already hold.

Security controls modelled on ISO/IEC 27001 Annex A

25dbr OÜ is not certified to ISO/IEC 27001. Our internal controls — access management, change control, logging and supplier review — are modelled on Annex A, and we say so precisely rather than implying a certificate we do not have.

Estimates that can be traced

Scope figures come from a published model with documented weights. When a number changes, we can show which input moved it.