The stack, the standards and the practice
Named technologies and named standards. If something is on this page you can ask us to talk through a decision we made with it.
- React 18
- TypeScript
- Vite
- Tailwind CSS
- React Native
Component architectures with a real accessibility budget, not a checklist at the end.
- PHP 8.3
- Laravel
- Node.js
- Go
- Python
Service boundaries drawn around data ownership, not around team structure.
- MySQL 8
- PostgreSQL 16
- Redis
- ClickHouse
- Elasticsearch
Schema and migration strategy agreed before the first table exists.
- Docker
- Terraform
- AWS
- Azure
- GitHub Actions
Infrastructure in version control, with the same review process as application code.
Named standards, with the limits stated
Two of these are targets we design to and one is a control model we follow without holding the certificate. We say which is which, because a vague compliance claim is worth less than an accurate one.
- OWASP ASVS
- Application Security Verification Standard — the checklist our code audits are run against.
- Regulation (EU) 2016/679 (GDPR)
- Data protection by design in every system that touches personal data: minimisation, retention limits, and a documented lawful basis.
- ISO/IEC 27001 Annex A
- Our internal controls are modelled on Annex A. 25dbr OÜ is not certified to ISO/IEC 27001 and does not claim certification.
- WCAG 2.2 AA
- The accessibility target for interfaces we build, including this website: keyboard operation, contrast, and a visible focus state.
Engineering practice
Architecture before implementation
Every engagement starts with a written technical brief: the domain model, the integration map and the decisions we are making, with their trade-offs recorded.
Your repositories, your accounts
Code is written into infrastructure you own from day one. There is no vendor lock-in step at the end of a project because there is nothing to hand over that you did not already hold.
Security controls modelled on ISO/IEC 27001 Annex A
25dbr OÜ is not certified to ISO/IEC 27001. Our internal controls — access management, change control, logging and supplier review — are modelled on Annex A, and we say so precisely rather than implying a certificate we do not have.
Estimates that can be traced
Scope figures come from a published model with documented weights. When a number changes, we can show which input moved it.