01Capabilities
What we build, and what we will not bid
Written for evaluators. Every claim here is one we can substantiate on request, and the limits are stated as plainly as the capabilities.
Core competencies
Custom enterprise and web applications
- Responsive web applications for citizen-facing and internal agency use
- Role-based dashboards, administrative consoles, and review queues
- Internal workflow systems, including multi-step approval and verification flows
- Server-rendered and client applications built to work on any device
- Accessibility conformance built in from the first commit, not audited at the end
Backend services, APIs, and systems integration
- Typed backend services with schema-validated inputs at the trust boundary
- REST and callable endpoints, including scheduled and event-driven jobs
- Data modeling, indexing, and query design for application workloads
- Integration with commercial and third-party systems: payments, identity, mapping, data feeds
- Normalization, deduplication, and reconciliation of external data sources
Cloud-ready architecture and deployment
- Managed-platform application architecture on Google Cloud and Firebase
- Serverless functions and container services, with environment separation
- Scripted, repeatable deployments rather than manual release steps
- Secrets held in a managed secret store, never in source control
- Static and edge-delivered front ends with security headers and a content security policy
Modernization, sustainment, and O&M
- Taking over applications from a departing vendor, including undocumented ones
- Dependency, platform-version, and deprecation currency, which is the work that prevents outages
- Incremental modernization of aging codebases, including Objective-C and legacy Swift
- Documented runbooks and transition-out packages, so the next vendor is never held hostage
Secure development and delivery
- Role-based access control enforced server-side, with declarative data access rules
- Input validation at every trust boundary, and privileged operations isolated from clients
- Automated unit and integration tests, including integration tests against emulated services
- Static analysis, type checking, and formatting as standard project tooling
- Data rights tracked and legended during development, so what you receive is unambiguous
Section 508 and WCAG 2.1 AA conformance
- Assessment of web applications against WCAG 2.1 AA
- Assessment of iOS applications against the DHS Section 508 Compliance Test Process
- Remediation of existing applications, with before and after evidence
- Accessibility Conformance Report (VPAT) preparation
- Automated conformance checks wired into the delivery pipeline, so regressions are caught before review
Native Apple applications, as a specialization. Nine years of professional iOS engineering including two years as a software engineer at Apple. Swift, SwiftUI, UIKit, and Objective-C interop on legacy codebases. We bring this depth to field, mobile, and accessibility-intensive systems, including VoiceOver, Dynamic Type, and contrast conformance, and to native macOS applications. It is a capability we are unusually strong in. It is not the category we compete in.
How we deliver
Small teams fail in predictable ways. These are the practices that prevent each one.
Working software on a schedule you can verify
Short increments with demonstrable output. You should never have to take our word for progress between milestones.
Accessibility evidence as you go
Conformance checks run against changes. The artifact a reviewer asks for at the end already exists from week one.
Documentation and source delivered continuously
Code and documentation land in your repository throughout, not at closeout. Transition-out material is written as we go.
Data rights marked during development
Pre-existing components and contract-funded work are tracked and legended separately, so what you receive is unambiguous.
Fixed price where scope is knowable
You get cost certainty. We get the upside of working efficiently. Milestone-billed, never one payment at the end.
Named engineers, start to finish
The people named in the proposal are the people on the contract.
Prime, team, or no bid
Three columns, stated before you ask. The third one is the reason to trust the first two.
We can prime this
- A bounded web application or internal workflow system
- An API or backend service with its data model
- A 508 assessment or remediation engagement
- A native iOS or macOS application
- Sustainment or incremental modernization of an application in service
We team on this
- Programs larger than a principal-led team can staff
- Requirements needing federal past performance we do not yet hold
- Enterprise programs with a large sustainment bench
- Pursuits where our accessibility practice is a scored discriminator
We do not bid this
- Work involving DoD controlled unclassified information
- Classified work of any kind
- Cost-reimbursement contracts requiring a DCAA-adequate accounting system
- 24/7 staffed operations centers
Codes, vehicles, and compliance posture
Classification
- Primary NAICS: 541511 Custom Computer Programming Services
- Secondary NAICS: 541512 Computer Systems Design Services, 541519 Other Computer Related Services
- Relevant PSCs: DA01 Business Application/Application Development Support Services, and DJ01 Security and Compliance Support Services, which covers Section 508
- Business size: Small Business
- Entity type: Arizona limited liability company
- Place of performance: Phoenix, Arizona, and CONUS remote
Compliance posture, stated honestly
- SAM.gov: registration in process. UEI and CAGE published here on issue
- Section 508 / WCAG 2.1 AA: core practice, with evidence provided alongside deliverables
- Cloud: application architecture and deployment on Google Cloud and Firebase. We do not offer a FedRAMP-authorized SaaS product, and we have not led a federal ATO process as prime. Compliance-intensive FedRAMP and ATO work is pursued with an experienced partner, where we contribute architecture, implementation, testing, documentation, and remediation
- CMMC: not currently assessed. We do not bid work involving DoD CUI.
- Clearances: none held. We do not bid classified work.
- Accounting: commercial. Suited to firm-fixed-price and commercial-item T&M. It is not a DCAA-adequate system, so we do not bid cost-reimbursement contracts.
Why we publish the limits. A vendor who says yes to everything costs you a failed award and a re-solicitation. If your requirement involves CUI, a clearance, or cost-type accounting, we are the wrong firm. We would rather tell you now, and point you at someone who fits.