Web applications
Python · Django · PostgreSQL · HTML/CSS · JavaScriptServer-side business logic, relational data, role-based workflows and hosted deployments.
Technical answers for CIO/CTO, CISO, IT operations, procurement and technical reviewers. We publish enough to assess architecture, engineering discipline and security boundaries — without publishing credentials, internal endpoints, data schemas or hardening detail that would materially simplify abuse.
Python · Django · PostgreSQL · HTML/CSS · JavaScriptServer-side business logic, relational data, role-based workflows and hosted deployments.
C# · .NET · WPF · SQLiteWindows x64 desktop product with local evidence storage and current read-only source boundaries.
Python · local-first services · local model routesR&D stack for local cognitive workflows, controlled web intelligence and defensive monitoring.
PHP · WordPress · WooCommerce · JavaScriptProfessional websites, commerce, content and practical web tools when a CMS architecture is appropriate.
Clear domain and module boundaries take priority over microservices for their own sake. Distribution follows only from real scale, integration or isolation requirements.
UI visibility is not a security boundary. Sensitive access is enforced in application logic, queries and service boundaries.
Role, tenant, assignment, context and operational need determine access. Job title alone is insufficient.
Missing secrets, invalid deployment configuration or ambiguous authorisation fail closed where appropriate rather than silently continuing.
Development, controlled demo and production use separate secrets, accounts, datasets and deployment profiles.
Release claims follow relevant tests and target-runtime validation. A static check is not presented as production acceptance.
Public web deployments terminate TLS at a controlled edge/reverse proxy. Application and database services are not directly published without need.
Secrets stay outside source and packages; production configuration is injected and controlled per environment.
Backup, retention, restore testing and responsibilities are defined per deployment.
Health, relevant security events and operational failures should be detectable without unnecessary employee monitoring.
No. The stack follows product type, deployment, maintainability and security requirements.
Not as a generic default. NERVE 1.0 Final has no configured external AI provider. QCE is local-first R&D. Other products may use external services only when explicitly designed and disclosed.
Current NERVE 1.0 Final connectors are read-only and the baseline contains no active action executor.
The demo and every real customer deployment are separate environments. Hosting region, processors, backup, retention and SLA are defined for the actual engagement.
Not yet. ISO/IEC 27001 is the first formal certification target. The site does not claim certification before independent issuance.
Yes, for a concrete evaluation. Publicly we show system level; deployment-specific dataflows, network detail and controls are shared through controlled due diligence.
Use this page as the first technical reference. For customer- or deployment-specific details we provide additional documentation through a controlled process.