No AI by default. Available on request.

We develop software with craftsmanship. Every line of code is produced by experienced developers who understand what they write. If you want AI assistance, you can have it within clear guardrails and without compromising quality, security or confidentiality.

Our standard

  • Development without AI tools. Architecture, implementation and decisions remain in human hands.
  • Your code and data do not leave the agreed environment and are not used for training.
  • The same quality stages in every project: static analysis, tests, architecture rules, review and QA acceptance.

If you want AI assistance

Some clients want to use AI selectively, for example for test coverage, boilerplate or migration steps. We do this as a deliberate decision, not in passing. Before work begins, we document the following in the statement of work:

  • Which tools are used and in which environment they run.
  • Which parts of the codebase they may be used for and which are excluded.
  • How your code is handled, including data protection and exclusion from training.
  • Who takes responsibility for the output: always a named developer on our side.

Which models are used

Standard

Models from established providers such as OpenAI and Anthropic through their business interfaces, where inputs are not used for training.

Your own contracts

On request, we work within your enterprise plan and tenant. Your agreements on data residency, retention and region then apply.

Local models

Self-hosted on request, in your environment or ours. Suitable when code must not leave your own infrastructure.

The chosen option is documented in the statement of work before the project starts. This includes the provider, region and retention periods.

What does not change

Every suggestion from an AI tool passes through the same stages as handwritten code: static analysis, automated tests, verification of architecture boundaries, review by an experienced developer and acceptance by quality assurance. Nothing bypasses this process.

Costing with responsibility: AI changes the tools, but not our responsibility. Verification, review and acceptance remain part of the service and may require additional effort. We therefore estimate the actual scope instead of relying on generic promises about a tool.

Our quality chain

Laravel

  • larastan/larastan: static analysis with Laravel awareness, with the level raised step by step.
  • laravel/pint: consistent coding style, enforced automatically in the pipeline.
  • pestphp/pest: tests, including architecture tests for namespaces and dependencies.
  • rector/rector with the Laravel set: automated refactoring and version upgrades.
  • nunomaduro/phpinsights: metrics for code quality and complexity.

Symfony

  • phpstan/phpstan with phpstan-symfony: static analysis with knowledge of the container and services.
  • friendsofphp/php-cs-fixer: consistent coding style based on a defined ruleset.
  • phpunit/phpunit: unit and integration tests.
  • rector/rector with the Symfony set: automated refactoring and version upgrades.
  • qossmic/deptrac: enforcement of architecture boundaries between layers and modules.

Across projects: roave/security-advisories and composer audit against known vulnerabilities, optionally infection/infection for mutation testing when test quality must be demonstrated.

Where we do not use AI, even on request

  • Security-critical core logic: authentication, authorization and cryptography.
  • Migrations that run on production data.
  • Confidential code unless disclosure to third parties has been explicitly approved.
  • Architecture decisions. These are made by a person who takes responsibility for them.

Want to know what is in your existing codebase, including the parts created with AI? We examine that in our code and AI review.