//services

Custom backend systems, APIs, cloud platforms and audits

0xProgramming OÜ delivers software engineering and IT consulting for business clients. Each module below is a scope we take on end to end — designed, built, load-tested and handed over with the documentation needed to run it without us.

backend · Backend & systemscloud · Cloud & DevOpsaudit · Security & auditconsulting · Consulting

module_01 · backend

Systems Architecture & Backend Engineering

We design and build the server side of production platforms: domain modelling, service boundaries, transactional integrity, queueing and idempotency, background processing and zero-downtime migration paths. Delivered as a documented codebase your own engineers can own, not a black box.

deliverables

  • Architecture decision records (ADRs) for every structural choice
  • Service and data-model design with migration strategy
  • Production codebase with automated test suite
  • Runbook and on-call handover documentation
PHP 8.3GoNode.jsTypeScriptPostgreSQLMySQL 8RedisRabbitMQKafka
engagement:
Fixed-scope project or dedicated-team retainer
typical:
6–20 weeks

module_02 · backend

Enterprise API & Integration Solutions

Contract-first API programmes: OpenAPI and Protobuf schemas, backward-compatible versioning policy, authentication and rate limiting, webhook delivery with retries and replay, plus adapters for ERP, CRM, payment, logistics and legacy SOAP endpoints. Every integration ships with a conformance test suite so a supplier change surfaces in CI, not in production.

deliverables

  • Versioned API contract (OpenAPI / Protobuf) and reference client
  • Authentication, quota and abuse-control layer
  • Integration adapters with conformance tests
  • Developer documentation and sandbox environment
OpenAPI 3.1gRPCGraphQLProtobufOAuth 2.1OIDCWebhooksJSON Schema
engagement:
Fixed-scope project
typical:
4–14 weeks

module_03 · cloud

Cloud Infrastructure & DevOps Optimisation

Kubernetes and container platform design, Terraform-managed environments, blue/green and canary deployment pipelines, autoscaling and capacity policy, backup and restore drills, plus cost review that usually pays for a meaningful part of the engagement. We optimise for recovery time and unit cost per request, not for the largest possible cluster.

deliverables

  • Infrastructure as code repository with reviewed plan/apply flow
  • CI/CD pipelines with rollback and environment promotion
  • Metrics, tracing, log pipeline and alert policy
  • Disaster-recovery procedure with a tested restore
KubernetesDockerTerraformAnsibleGitHub ActionsGitLab CIPrometheusGrafanaOpenTelemetry
engagement:
Project or ongoing platform retainer
typical:
3–12 weeks

module_04 · audit

IT Security, Code Audits & Architecture Consulting

Structured audit of code, architecture and infrastructure against OWASP ASVS and our own reliability checklist. Covers authentication and session handling, injection and access-control classes, dependency and supply-chain exposure, data-protection posture under GDPR, single points of failure and scaling ceilings. Output is a written report with severity-ranked findings, reproduction steps and a remediation plan costed in engineering days.

deliverables

  • Severity-ranked findings with reproduction steps
  • Threat model and trust-boundary diagram
  • Remediation plan costed in engineering days
  • Executive summary for non-technical stakeholders
OWASP ASVSThreat modellingStatic analysisLoad testingGDPR reviewDependency audit
engagement:
Fixed-fee audit
typical:
2–5 weeks

module_05 · backend

Performance Engineering & Database Optimisation

We start by reproducing your load, then fix what the profile actually shows: N+1 access patterns, missing or wrong indexes, lock contention, connection-pool exhaustion, serialisation overhead and cache-key design. Every engagement ends with a repeatable load-test harness so the next regression is caught in CI.

deliverables

  • Baseline and post-optimisation benchmark report
  • Query, index and schema changes with migrations
  • Caching and connection-pooling strategy
  • Reusable load-test harness wired into CI
k6JMeterEXPLAIN ANALYZEpgBouncerProxySQLRedisBlackfirepprof
engagement:
Fixed-scope project
typical:
2–8 weeks

module_06 · consulting

CTO-as-a-Service & Technical Due Diligence

For companies that need architectural authority without a full-time hire. Technology selection with written trade-offs, build-versus-buy analysis, engineering process and code-review standards, interview design for backend and platform roles, and technical due diligence reports for investors or acquirers.

deliverables

  • Written technology recommendations with trade-offs
  • Roadmap sequenced by risk and dependency
  • Engineering standards and review process
  • Due-diligence report for investors or acquirers
Architecture reviewDue diligenceVendor selectionHiringRoadmap planning
engagement:
Monthly retainer (days per month)
typical:
Ongoing, 3-month minimum

//process

How an engagement runs

Same four stages whether the work is a two-week audit or a five-month platform build. You see working software from the first increment, and nothing is invoiced against a milestone you have not seen.

  1. stage_01 — discovery
    ./discovery --start

    Technical discovery

    duration: 3–5 days

    We read the code, the schema and the incident history, then interview the people who operate the system. Output is a written constraint map: current load, real bottlenecks, coupling, and the changes the business actually needs.

  2. stage_02 — architecture
    ./architecture --start

    Architecture & plan

    duration: 1–2 weeks

    Target architecture with decision records, a migration path that keeps production running, capacity model with headroom, and a delivery plan sequenced by risk rather than by convenience.

  3. stage_03 — build
    ./build --start

    Implementation

    duration: Project-dependent

    Two-week increments, trunk-based, every change behind CI with tests and review. You get a working environment from week one and a demo at the end of each increment — no six-week silences.

  4. stage_04 — harden
    ./harden --start

    Load, hardening & handover

    duration: 1–3 weeks

    Load tests to the agreed target, failure drills including a restore from backup, security review against OWASP ASVS, then runbooks and a working session with your team. We leave when they can run it without us.

//engagement

Commercial terms, stated up front

Fixed scope

A written specification, a fixed price and a delivery date. Best when the problem is already understood — an integration, a migration, a defined feature set.

Retainer

A set number of engineering days per month, billed monthly, cancellable with 30 days’ notice. Best for ongoing platform work and for teams that need senior capacity rather than a project.

Fixed-fee audit

A bounded review with a written report at the end. Costed before it starts, and deliberately independent of whether you then hire us to do the remediation.

Indicative day rate €780. Invoiced in EUR from Estonia with EU VAT reverse charge where applicable. B2B only — we do not contract with consumers.