Least privilege by default
Access is granted per role and per environment. Credentials are stored in managed secret systems and rotated, never embedded in source or configuration files.
00Software & infrastructure engineering
RIVER KG is an IT company working on custom software, cloud architecture, data platforms, and secure infrastructure. We take responsibility for how systems behave under load, over years, and in the hands of the people who operate them.

01Company overview
We design, build, and operate software and infrastructure for organisations where downtime, incorrect data, or a failed migration has real consequences.
Projects usually begin with a system that already exists: a service that has outgrown its original design, an integration that breaks silently, a reporting process that nobody trusts. Our first task is to describe that situation accurately.
From there we work in defined increments, with architecture written down, decisions justified, and each release observable in production. The result is a system the client owns entirely — code, infrastructure definitions, and documentation.
02Core capabilities
03Featured technology
Before code is written, the system is drawn: services and their responsibilities, data ownership, synchronous and asynchronous paths, failure domains, and the boundaries where information crosses trust levels.
Diagrams are kept current with the implementation. When they diverge, the diagram is corrected rather than abandoned — it remains the shared reference during incidents and onboarding.

04Services overview
Engagements combine several of these areas. The mix depends on the state of the existing system and the constraints around it.
Domain-specific systems built from requirements, not from templates.
Accessible, fast interfaces with server-rendered delivery where it matters.
Environment design, networking, scaling policy, and cost boundaries.
Contract-first connections between internal systems and third-party services.
Threat modelling, access control, secrets management, and hardening.
Pipelines, warehouses, and models that stay consistent over time.
Reproducible environments, delivery pipelines, and infrastructure as code.
Architecture review, technology assessment, and delivery planning.
Incremental replacement of legacy components without freezing the business.
Monitoring, maintenance, and controlled evolution after launch.
05Industries & business challenges
| Context | Typical problem | Engineering response |
|---|---|---|
| Logistics and operations | Scheduling and tracking data spread across spreadsheets and disconnected tools. | Single operational data model, event history, and interfaces built around daily working rhythms. |
| Financial and regulated services | Manual reconciliation and audit trails that cannot be reconstructed reliably. | Append-only records, deterministic calculations, and reporting derived from one source. |
| Industry and manufacturing | Machine and sensor output collected but not usable for decisions. | Ingestion pipelines, normalised measurements, and dashboards tied to defined thresholds. |
| Healthcare and public sector | Sensitive data handled by systems with unclear access boundaries. | Role-based access, encryption in transit and at rest, and documented data flows. |
| Software product companies | Delivery slowing down as the codebase and infrastructure grow. | Modular boundaries, automated pipelines, and measurable release health. |

06Development approach
We start with the existing system, its constraints, and the people who operate it. Documentation of the current state comes before proposals for a future one.
Domain concepts, data ownership, and failure modes are written down and reviewed. Disagreement at this stage is cheaper than disagreement in production.
Each increment is deployable and observable. Progress is demonstrated by working software in a real environment, not by percentage estimates.
Instrumentation, runbooks, and handover material are produced alongside the code, so that the system can be run by the team that owns it.
07Technology expertise
Technology choices follow the problem. We prefer widely supported, well-documented components over novelty, and we avoid dependencies that cannot be operated by the client's own team.

08Security & quality principles
Access is granted per role and per environment. Credentials are stored in managed secret systems and rotated, never embedded in source or configuration files.
Dependencies are pinned and scanned. Builds are reproducible, artefacts are traceable to a commit, and deployments are recorded.
Every change passes review and automated checks. Rollback paths exist before a release, and migrations are written to be reversible where the data model allows.
Validation at boundaries, encryption in transit and at rest, network segmentation, and logging designed for investigation rather than volume.

09Project workflow
Phase 01
Systems review, constraints, risks, and a written scope with open questions listed explicitly.
Phase 02
Data model, interfaces, environments, and non-functional requirements agreed in writing.
Phase 03
Iterative delivery into a staging environment with review at the end of each increment.
Phase 04
Load behaviour, security review, failure testing, and documentation completion.
Phase 05
Staged rollout, monitoring in place, and a defined rollback procedure.
Phase 06
Maintenance, observability review, and planned improvement cycles.
10Key facts
We publish no unverified figures, awards, or client names on this website.
11Working with RIVER KG

We prefer a narrow system that fits the process precisely to a broad platform that fits nothing well. Requirements are reduced to what the organisation actually does.
The people writing the code take part in the discussions. There is no translation layer between technical reality and project reporting.
Monitoring, backups, permissions, and cost behaviour are part of the design phase, not tasks postponed until after launch.
Documentation, infrastructure definitions, and code are structured so another team could continue the work without a rewrite.
12Company statement

13Contact information