Picking projects
We look at maturity, repository activity, the number of maintainers, the licence it ships under and how large the Polish talent pool for it is.
Free to download is not the same as free to run. Some of the licence savings must be reinvested in patching and security monitoring, otherwise the cost resurfaces later, with interest.
We look at maturity, repository activity, the number of maintainers, the licence it ships under and how large the Polish talent pool for it is.
We work with PostgreSQL, Linux, PHP with Laravel and Symfony, and Python with Django, using Keycloak for sign-in and SSO. Off-the-shelf modules are used only when they suit the job without contortions.
Docker, automated builds and deployments, separate test and production environments. New versions reach the server predictably, with no manual file copying.
Automated dependency scans plus an SBOM listing every component. Clients subject to NIS2 increasingly request this document when assessing their suppliers.
We list the licence of every component, such as GPL, AGPL, MIT or Apache 2.0, and flag those that need attention given how you use the system. The legal assessment is for your lawyer.
When we fix a bug in a library, we submit the patch to the original project. That way you are not stuck maintaining a private patched fork that breaks at the next update.
Delivery takes about as long as with commercial platforms. The payoff comes over the years: headcount rises while licence spending stays flat.
We study the requirement and list possible projects. If the open option falls short of a commercial one in quality, we tell you plainly.
A small, well-bounded piece of the work serves as a trial run before you tie yourself to the stack for years.
We develop on components with active maintainers and a steady cadence of security releases.
Code, architecture notes, the SBOM, a licence list and notes on how to install and upgrade.
Hobby projects maintained by a single volunteer eventually go quiet. Their vulnerabilities then remain unpatched, and ripping such a dependency out of production is rarely pleasant. That is why feature lists are only half of our evaluation; the other half is who funds the project, how many maintainers it has and how quickly fixes are released.
On licences, usually yes, and more so as your user count rises. Build and hosting costs differ very little. Judge the options on total cost across a three-to-five-year horizon, not on the initial quote alone.
Any developer familiar with the technology, and that is the whole idea. You own the repository and its documentation, the stack is widely known, and there is no shortage of firms able to work on it. A closed platform from one vendor gives you no such freedom.
It can be a convenient choice: open data exchange standards help with KRI requirements, and the contracting authority gets the full source and documentation. Procurement requirements are for the authority and its lawyer to settle; we help prepare the technical part of the description.
Plenty of people reading it are hunting for bugs, too. Flaws in popular projects are disclosed and patched quickly, so what counts is patching discipline. We follow security advisories, and for critical vulnerabilities, including those flagged by CERT Polska, we roll out fixes outside the normal release cycle.
Explain what the system should do and what frustrates you about today's licensing. We will suggest a stack and be candid about its weak spots compared with commercial products.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.