Zone2

AI systems, web platforms, product development, identity and access. Engineering for startups and scale-ups across the DACH region and the EU.


What we do.

Most engagements turn out to be more than one of these. If you cannot tell which one you need, that is worth a call on its own.

  • AI systems

    • Claude
    • Gemini
    • Mistral
    • Node.js

    Most business processes have a step in the middle where somebody has to look at something, work out what it means, and decide what happens next. Software has always been able to do the steps either side of it. Language models can do that middle step now, which means the whole process can run without a person sitting in it. Building those is the work, and making them dependable enough to leave running is the hard part.

  • Web platforms

    • Next.js
    • PayloadCMS
    • PostgreSQL
    • Stripe

    The product your customers use, and everything it needs to keep working. There is more to it than the application: content somebody has to be able to change, money moving through it, and the place it all runs. They are usually built at different times by different people, and getting them to work together is most of the job.

  • Product development

    • TypeScript
    • React
    • Supabase
    • Kubernetes

    Sometimes a team is building well and simply needs more senior hands. Sometimes there is nobody whose job it is to decide what gets built at all. We do both, and they are different jobs: one adds capacity to a plan somebody else owns, the other means owning the plan.

  • Identity and access

    • Keycloak
    • Auth0
    • OIDC
    • Terraform

    Every system has to know who someone is before it can decide what they are allowed to do. The first half is usually bought and the second is usually built, and both stop fitting as a company grows: providers get changed, big customers arrive expecting to sign in with their own, and a short list of roles stops describing who should see what.


What we have built.

  • Orders arrive as free text written by people, in no fixed format. What leaves is a record the ERP accepts, or nothing at all.

    • Unstructured order email to ERP-compliant records
    • Claude, Gemini and Mistral, routed per task
    • Node.js, SigNoz
  • A Rails application, moved to Next.js on Supabase.

    Logistics and transportation SaaS, Germany

    The framework was the visible part. Access also moved into the database rather than the application, and the platform issues ZUGFeRD invoices, the German e-invoicing standard.

    • Ruby on Rails to Next.js on Supabase
    • Row Level Security, enforced in the database
    • ZUGFeRD e-invoicing
  • Three million accounts, thirty microservices.

    Optical retail and omnichannel commerce, Germany

    We played a key role in migrating identity from Keycloak to Auth0. The estate crossed nine major versions of Keycloak along the way.

    • Keycloak to Auth0, 3M+ users, 30+ microservices
    • Keycloak on Kubernetes, v15 to v24
    • Datadog, Pulumi, Terraform

When to bring us in.

Earlier than most people expect: scoping is where the cost of a project gets decided.

AI systems

  • When you know the feature works and need to know what it costs at volume.
  • When the input is documents rather than a clean API.
  • When a wrong answer has a consequence and something has to catch it.

Web platforms

  • When a framework version is far enough behind that upgrading is a project.
  • When the product has to start billing and nothing bills yet.
  • When the marketing site and the application have drifted into two codebases.

Product development

  • When you are choosing between hiring, promoting and bringing someone in.
  • When the roadmap has decisions on it that nobody currently owns.
  • When a team has grown past the way it was organised.

Identity and access

  • While the migration is still a plan.
  • When an upgrade crosses several major versions at once.
  • When an agreement requires single sign-on you have not built yet.

How we work.

The people who scope your project are the people who build it.

  • The first call.

    You tell us about the system and the deadline. We say what we would do first and where we think the risk sits.

  • Who works on it.

    Every engagement is led by someone who has spent a career building production systems and keeping them running. The engineers on it are senior, and chosen for that project. You are told who they are before the work starts, and you work with them directly.

  • Once we start.

    We work in your repository and your pipeline, not a parallel one. Next.js, PayloadCMS and the model providers go on top of whatever your stack already runs.

  • After launch.

    We stay on and run what we built, when that is what you want. Version upgrades, dependency and security updates, whatever the product needs next. The engagement is written to cover that period too.

Tell us what you are building.

Send a note or book a call, whichever suits you better. We answer in one or two business days.

Or call +359 877 277 640.

A message commits you to nothing. By sending it you confirm you have read the privacy policy.