Custom backend systems, APIs, cloud platforms and audits
0xProgramming OÜ delivers software engineering and IT consulting for business clients. Each module below is a scope we take on end to end — designed, built, load-tested and handed over with the documentation needed to run it without us.
We design and build the server side of production platforms: domain modelling, service boundaries, transactional integrity, queueing and idempotency, background processing and zero-downtime migration paths. Delivered as a documented codebase your own engineers can own, not a black box.
deliverables
→Architecture decision records (ADRs) for every structural choice
→Service and data-model design with migration strategy
Contract-first API programmes: OpenAPI and Protobuf schemas, backward-compatible versioning policy, authentication and rate limiting, webhook delivery with retries and replay, plus adapters for ERP, CRM, payment, logistics and legacy SOAP endpoints. Every integration ships with a conformance test suite so a supplier change surfaces in CI, not in production.
deliverables
→Versioned API contract (OpenAPI / Protobuf) and reference client
Kubernetes and container platform design, Terraform-managed environments, blue/green and canary deployment pipelines, autoscaling and capacity policy, backup and restore drills, plus cost review that usually pays for a meaningful part of the engagement. We optimise for recovery time and unit cost per request, not for the largest possible cluster.
deliverables
→Infrastructure as code repository with reviewed plan/apply flow
→CI/CD pipelines with rollback and environment promotion
→Metrics, tracing, log pipeline and alert policy
→Disaster-recovery procedure with a tested restore
IT Security, Code Audits & Architecture Consulting
Structured audit of code, architecture and infrastructure against OWASP ASVS and our own reliability checklist. Covers authentication and session handling, injection and access-control classes, dependency and supply-chain exposure, data-protection posture under GDPR, single points of failure and scaling ceilings. Output is a written report with severity-ranked findings, reproduction steps and a remediation plan costed in engineering days.
We start by reproducing your load, then fix what the profile actually shows: N+1 access patterns, missing or wrong indexes, lock contention, connection-pool exhaustion, serialisation overhead and cache-key design. Every engagement ends with a repeatable load-test harness so the next regression is caught in CI.
For companies that need architectural authority without a full-time hire. Technology selection with written trade-offs, build-versus-buy analysis, engineering process and code-review standards, interview design for backend and platform roles, and technical due diligence reports for investors or acquirers.
deliverables
→Written technology recommendations with trade-offs
Same four stages whether the work is a two-week audit or a five-month platform build. You see working software from the first increment, and nothing is invoiced against a milestone you have not seen.
stage_01 — discovery
~$./discovery --start
Technical discovery
duration: 3–5 days
We read the code, the schema and the incident history, then interview the people who operate the system. Output is a written constraint map: current load, real bottlenecks, coupling, and the changes the business actually needs.
stage_02 — architecture
~$./architecture --start
Architecture & plan
duration: 1–2 weeks
Target architecture with decision records, a migration path that keeps production running, capacity model with headroom, and a delivery plan sequenced by risk rather than by convenience.
stage_03 — build
~$./build --start
Implementation
duration: Project-dependent
Two-week increments, trunk-based, every change behind CI with tests and review. You get a working environment from week one and a demo at the end of each increment — no six-week silences.
stage_04 — harden
~$./harden --start
Load, hardening & handover
duration: 1–3 weeks
Load tests to the agreed target, failure drills including a restore from backup, security review against OWASP ASVS, then runbooks and a working session with your team. We leave when they can run it without us.
//engagement
Commercial terms, stated up front
Fixed scope
A written specification, a fixed price and a delivery date. Best when the problem is already understood — an integration, a migration, a defined feature set.
Retainer
A set number of engineering days per month, billed monthly, cancellable with 30 days’ notice. Best for ongoing platform work and for teams that need senior capacity rather than a project.
Fixed-fee audit
A bounded review with a written report at the end. Costed before it starts, and deliberately independent of whether you then hire us to do the remediation.
Indicative day rate €780. Invoiced in EUR from Estonia with EU VAT reverse charge where applicable. B2B only — we do not contract with consumers.