— PROCESS
From assessment to operation, one repeatable model.
New builds, renovations of existing sites, and ongoing operation — we run all of them through the same four steps. Deciding upfront "what we receive, what we produce, and what we verify" at each step means quality doesn't drift when the person in charge changes.
-
STEP 1
Assessment
Assessment
2–4 weeks
-
STEP 2
Design
Design
4–8 weeks
-
STEP 3
Build
Build
4–12 weeks
-
STEP 4
Operate
Operate
Monthly retainer (ongoing)
Assessment
We record the current structure, metrics, operations and risks as fact. Countermeasures come in the next step.
What we receive (Input)
- Site / system URLs and access
- Current operating rules or documentation (if any)
- Stakeholder hearings (30–60 min × several people)
What we deliver (Output)
- Assessment report (scored, prioritized)
- Draft improvement list (response log)
- Scope and assumptions for the next step
What we verify
- Distortions in information structure (URLs, headings, nav)
- Gaps and misrouting in measurement
- Holes in monitoring, notification, evidence retention
- Current state of vulnerabilities, backups and recovery
Design
Based on risk and priority, we define information structure, monitoring ledgers and operating conventions as documentation.
What we receive (Input)
- The assessment report
- Business goals and constraints
- Specs of existing systems and data
What we deliver (Output)
- IA / URL conventions / content model
- Monitoring ledger and notification workflow
- Draft AWS architecture diagram and recovery runbook
- Measurement design document and KPI definitions
What we verify
- Is it repeatable (can someone else operate it)?
- Is it verifiable (can it be confirmed with numbers and evidence)?
- Is it sustainable (does it keep running when the person in charge changes)?
Build
We build something that works, on the assumption of testing and evidence. Review, verification and migration are completed at this stage.
What we receive (Input)
- The full set of design documents
- Access to production and staging environments
- Content and assets
What we deliver (Output)
- A working system / site
- Logging, monitoring and backups up and running
- Migration record and verification report
- Runbook for the operating team
What we verify
- Zero drift between the design docs and the implementation
- Tests left behind that can reproduce failures
- A rollback procedure, always in place
Operate
We keep the four conditions — update, evaluate, improve, protect — turning. Monthly reviews of the improvement list, quarterly structural reviews.
What we receive (Input)
- The live system / site
- Monthly metrics and logs
- A standing meeting with the operating team
What we deliver (Output)
- Monthly report (metrics, improvement proposals)
- An ongoing, continuously updated improvement list
- Incident records and retrospectives
- Quarterly structural-review report
What we verify
- Are the numbers moving (evaluate)?
- Is each initiative feeding the next one (improve)?
- Are detection, notification and evidence retention actually working (protect)?
— Next step
Why not start with an assessment?
Our six resources cover our design thinking, verification model, and a sense of pricing. After you've had a look, we'll follow up as needed.
- 01 An assessment report recording your current state as fact, delivered in as little as 2 weeks
- 02 Sample deliverables and a sense of pricing are included in our resources
- 03 Initial hearing is free, online available