Services

Four ways in, all fixed-scope

COXSWAIN does not sell development hours. It sells outcomes on the systems you already run, with a written scope, listed deliverables and a price you know before we start. You get the price in writing after a 20-minute conversation.

01

Technical audit

Duration
2 weeks
Who for
Product teams with a PHP, Symfony, Node.js, JavaScript or Angular system that slows delivery, and a CTO who wants numbers before decisions.
How it starts
Read-only access to code and infrastructure, two interviews with the team, NDA if you want one.

Tech-debt score, architectural risks, cloud costs, security gaps, AI quick wins and a 90-day roadmap you can execute with or without us.

What changes for youYou know what state the system is in, what it risks and what is worth doing first, before you spend on anything else.

Scope and deliverables

02

AI-assisted delivery pilot

Duration
4-6 weeks
Who for
Teams that have a plan, ours or theirs, and want proof it works before a long commitment.
How it starts
After the audit, or directly, if you already know what hurts.

One to three concrete wins: generated and verified tests, AI-assisted PR review, a module upgraded or migrated in production, a stabilized front end or a smaller AWS/Azure bill.

What changes for youA result you can see in a few weeks, not a promise for next year.

The written scope picks one to three of these; the rest can follow on the retainer.

Scope and deliverables

03

Monthly retainer

Duration
monthly
Who for
Product teams that want ongoing ownership of their system, and agencies that need a white-label delivery partner.
How it starts
After the audit or the pilot. Sized to the work, no long minimum term.

Senior ownership of your codebase: roadmap execution, incident prevention, architecture improvements and cost discipline, month after month.

What changes for youFewer incidents, more frequent releases, and a clear owner who answers when the phone rings.

Scope and deliverables

04

Security assessment and hardening

Duration
1-3 weeks
Who for
Teams with a security questionnaire from a large customer on the desk, a due diligence ahead or NIS2 obligations to document.
How it starts
Access to code and infrastructure, written agreement, then one to three weeks of work.

Code review for authorization, injection and secrets, infrastructure and CI/CD hardening, preparation for enterprise security questionnaires and NIS2 requirements. A report with findings, severity and a remediation plan. Behind it: hundreds of security findings found and fixed in production code, not just reported.

What changes for youAn honest answer to "how exposed are we" and a document you can show a customer or an investor.

This is not a cybersecurity audit under Romanian OUG 155/2024 and not a penetration test. We find, recommend and fix; for pentests we work with specialized partners.

Scope and deliverables

The stack we live in

  • PHP 7 and 8
  • Symfony
  • Laravel
  • Node.js
  • JavaScript and TypeScript
  • Angular
  • MySQL and PostgreSQL
  • Redis and Kafka
  • AWS, Azure and Google Cloud
  • Docker and Kubernetes
  • GitHub Actions
  • Microsoft Graph and Azure AD
  • Claude Code and AI agents
How we work
  • 20-minute conversation
  • Scope and price in writing
  • NDA on request
  • EU and UK hours, US-East overlap
  • Your code and data never go to an AI provider without written agreement

Contact

Let's talk

Tell us what you have, in your own words. You do not need to know which technology the system runs on; we will work that out. You get back questions and a written proposal.

Write to usor directly at [email protected]