Skip to content

The enterprise practice of Pixirain

Built for the workyou cannotbuy.

Custom platform engineering, AI systems, assurance and data-protection work for organisations whose problem does not have a product. Scoped to one company at a time, delivered on escrowed milestones, with a single name answering for the outcome.

The thesis

Software is now generated faster than it can be reviewed.

Everyone is shipping. Almost nobody is checking.

Assurance is not a side practice here. It is the layer we think the market is missing — the one that answers for whether any of what has been built is actually any good — and it is why a firm that builds systems also audits, certifies and red-teams them.

FIG 01 // THE ASSURANCE APERTURE
INSPECTION RIG // ACTIVE
UNCHECKED INFLUXAUTONOMOUS SYNTHESISVERIFICATION GATECERTIFIED RELEASEESCROW SIGN-OFF
01 // INVARIANT

AST & Symbolic Proof

02 // ADVERSARIAL

Red-Team Fuzzing

03 // ESCROW

Client Release Gate

ARCHITECTURE // AIR-GAPPED VERIFICATION LAYERLATENCY: ZERO-DRIFT

The delivery rail

The part that is already built.

Custom work usually fails on process, not on capability. So the process is not improvised per engagement — it runs on the same infrastructure the catalogue business has been delivering on, and these four properties are structural rather than promised.

pixirain://delivery.raillive

HELDRELEASEDYOUR APPROVALScoping01Definition02Delivery03Handover04
Escrow · milestone fundingFIG. 01
Escrow01

Money moves when you approve, not before

Funds are held against each milestone and released when you accept the work. Not on a schedule, not on an invoice date — on your approval.

Assignment02

You do not shortlist anyone

Work is assigned rather than tendered, and the assignment carries accountability with it. If the wrong person was chosen, that was our decision to make and ours to fix.

Deliverables03

Structured objects, not files in a thread

Every deliverable is a first-class record with a type, a version, a reviewer and a revision history. Nothing important lives in a chat message.

Ownership04

One person owns the outcome

A delivery lead is attached to the engagement and answers for it. Escalation is a name, not a support queue.

Engagement

There is no price list. There is a shape.

Everything here is scoped to one organisation, so a number on this page would be a number about somebody else. What can be said in advance is how the commitment is structured — and that is a more useful thing to know first anyway.

Model programme

Fixed-outcome programme

Scope agreed up front and priced as a whole. Funds sit in escrow and release against milestones you approve, so payment tracks delivery rather than elapsed time. The usual shape for a build with a known destination.

Fits

A system with a clear definition of done.

Discuss this shape

Governance · India

The DPDP clock is running.

India’s Digital Personal Data Protection Rules were notified on 13 November 2025. Full substantive compliance — notice, consent, security safeguards, breach reporting and data-principal rights — becomes enforceable eighteen months later.

Until 13 May 2027

———
Days
——
Hours
——
Minutes
——
Seconds

No threshold

Nothing about turnover or headcount decides whether you are in scope. Recognised startups can be notified out of a handful of obligations — never out of the Act.

One field

Collecting a name, phone number or email digitally makes an organisation a Data Fiduciary.

₹250 crore

The ceiling for failing to keep reasonable security safeguards. Penalties are set per violation category, so one incident can draw several.

  1. Done

    DPDP Rules notified

    MeitY published the Rules. The provisions constituting the Data Protection Board came into force the same day.

  2. Next

    Consent Manager framework operational

    Rule 4 comes into force, governing Consent Manager registration, eligibility and obligations.

  3. Enforcement

    Full substantive compliance

    Eighteen months after notification. Notice, consent, security safeguards, breach reporting and data-principal rights all become enforceable.

What happens next

Four steps, and the first one is free.

Step 01

Scoping

A working session, not a sales call. We map what exists, what it has to become, and what would make the project fail. You leave with that written down whether or not you engage us.

Step 02

Definition

The scope becomes milestones with acceptance criteria attached to each. Ambiguity gets resolved here, in writing, because it is the only place resolving it is cheap.

Step 03

Delivery

Work runs in a shared workspace you can watch. Each milestone is submitted, reviewed and approved by you before the next one is funded.

Step 04

Handover

Source, credentials, infrastructure definitions and decision records transfer to you, and stay recoverable afterwards. An engagement that ends should not strand anything.

Start here

Tell us whatdoes not exist yet.

Not a demo request and not a qualification call. A working session that maps the problem — and you keep that map whether or not you engage us.