Skip to content

Capability map

Five practices.Sixteen answers.

Nothing here is a package. Each is a starting point for a scope built around one organisation’s systems, obligations and deadlines — which is why there are no prices on this page, and why the first step is always a conversation.

Capability map · hover to name a cellFIG. 01
01Practice

Build

Systems designed for one organisation rather than configured from a template. Where the thing you need does not exist yet.

01

Platform engineering

The work that starts when off-the-shelf software stops fitting: an operations platform shaped around how your business actually runs, a marketplace with its own matching and settlement logic, an integration layer between systems that were never meant to speak. Architected to be handed over, not to require us permanently.

What you end up holding

  • Architecture decision records, not just code
  • Infrastructure defined as code and owned by you
  • A handover that assumes we leave
Enquire about this
02

Product and interface design

Interface work for organisations with more than one product and more than one team building them. A design system with real component contracts, accessibility built into the primitives rather than audited afterwards, and documentation a new engineer can act on without asking a designer.

What you end up holding

  • A component library with usage contracts
  • Accessibility encoded in the primitives
  • Design tokens that survive a rebrand
Enquire about this
03

Data and decision systems

Moving analytics out of spreadsheets and prototypes and into systems people can rely on: instrumented pipelines, a warehouse with defined ownership, models with monitoring and a rollback path. The emphasis is on what happens on the worst day, because that is when a decision system is actually tested.

What you end up holding

  • Lineage you can trace from number to source
  • Models with drift monitoring and a rollback path
  • Definitions agreed once, not per report
Enquire about this
04

Cloud and reliability engineering

Making an existing system survivable. Load and failure testing against real traffic shapes, observability that answers questions rather than producing dashboards, runbooks written before the incident, and a cloud bill examined line by line — which in our experience is where the fastest uncontroversial savings are.

What you end up holding

  • Runbooks written before they are needed
  • Alerting tuned to signal, not volume
  • A cost baseline with the drivers named
Enquire about this
02Practice

Intelligence

The layer between a language model and something an organisation can depend on. Most of this work is plumbing, evaluation and governance rather than prompting.

01

AI systems and agents

The context layer an organisation needs before any of this is useful: documents, tickets, code and operational data made retrievable with permissions intact, then agents given tools that reach the systems where work actually happens. Built with evaluation from the first week, because an agent without a test suite is a demo.

  • A retrieval layer that respects existing permissions
  • An evaluation suite that runs in CI
  • Cost and latency budgets per workflow
Enquire about this
02

Tooling and MCP integration

Model Context Protocol servers and equivalent tool layers over your own systems — CRM, ERP, ticketing, internal APIs — so an assistant can read and act inside them under real authorisation rather than through copy and paste. Scoped, audited access is the whole engineering problem here, and it is where most of the work goes.

  • Scoped, revocable tool access per system
  • An audit trail of every action taken
  • Human approval gates where they belong
Enquire about this
03

Agent assurance and red-teaming

Almost everyone shipping an agent is testing it the way they hope it will be used. This is the opposite: prompt injection, tool misuse, data exfiltration through retrieval, jailbreaks against your specific system prompt, and the failure modes that only appear under adversarial load. Delivered as findings with reproductions, then as a regression suite you keep.

  • Reproducible attacks, not a list of concerns
  • A regression suite that runs on every deploy
  • A severity model your team can triage against
Enquire about this
04

Discovery engineering

Search is no longer the only way a buyer finds you. Generative engine optimisation is the technical work of being retrievable, quotable and correctly attributed inside AI answers — structured data, canonical claims, entity consistency and source authority — carried out alongside conventional technical SEO rather than instead of it.

  • Structured data an answer engine can parse
  • Entity and claim consistency across sources
  • Measurement of citation, not just ranking
Enquire about this
03Practice

Assurance

Everyone is building things that can do work. Almost nobody is building the layer that answers for whether the work was any good. This is that layer.

AI-build certification

Bring the application your team generated. We inspect it, fix it, and put our name on it.

Applications built with Cursor, Lovable, v0, Replit and their equivalents now run real workloads, and almost none of them have been reviewed by anyone. We audit security, performance, accessibility and data-protection exposure, remediate what is broken, and certify the result — with a defined warranty behind the certificate rather than a badge and a disclaimer.

  • A findings report ranked by exploitability
  • Remediation carried out, not just recommended
  • A certificate with a warranty period attached
Enquire about this

Technical diligence

Code, infrastructure, licences and IP reviewed before the money moves.

Diligence for transactions that are too small to interest a large consulting firm and far too large to take on trust. What the codebase actually is, what it depends on, which licences travel with it, who holds the accounts, and — increasingly the question that stalls deals — whether the seller can demonstrate they own what they are selling.

  • A dependency and licence inventory
  • Key-person and access-concentration risks named
  • A remediation cost estimate for the buyer
Enquire about this

Digital custody and succession

Source, keys, credentials and provenance held so the business survives a departure.

Most organisations cannot answer a simple question: if the person who set this up left tomorrow, could we get in? We hold source, credentials and the licence and authorship chain under structured escrow, with defined release conditions — so a resignation, a dispute or a death is an inconvenience rather than an outage.

  • An inventory of every account and who holds it
  • Escrowed credentials with defined release conditions
  • A provenance record for commissioned work
Enquire about this
04Practice

Governance

Obligations with dates attached. This is the work that stops being optional on a specific day, and the calendar is already published.

  1. Data protection engineering

    India's Digital Personal Data Protection regime reaches every organisation that collects a name, a phone number or an email — there is no turnover threshold and no exemption for smaller companies. The work is technical: consent capture and withdrawal that actually propagates, retention and deletion that runs, a breach process that has been rehearsed, and records that survive being asked for.

    • A data inventory mapped to lawful purpose
    • Consent and withdrawal wired to real deletion
    • A breach process that has been rehearsed
    Enquire about this
  2. Accessibility engineering

    Automated scanners find perhaps a third of real accessibility defects. The rest are keyboard traps, focus order, live-region behaviour and screen-reader semantics, and they need a person. We audit against WCAG, remediate the code rather than filing tickets, and leave the patterns in your component library so the same defects do not return next quarter.

    • Manual audit against WCAG, not a scanner dump
    • Remediation in the components, not per page
    • Documentation your procurement team can use
    Enquire about this
  3. Cryptographic resilience

    Harvest-now-decrypt-later is a real threat model for anything with a long confidentiality horizon, and the post-quantum standards are finalised. The useful work today is inventory and agility rather than prediction: knowing every place cryptography is used, how it is configured, and how long a swap would take. Regulated sectors will be asked first.

    • A cryptographic inventory across the estate
    • A crypto-agility assessment per system
    • A sequenced migration plan with dependencies
    Enquire about this
05Practice

Infrastructure

Pixirain runs a delivery rail — escrowed milestones, assigned accountability, structured deliverables, a platform guarantee. These are the ways another organisation can run work over it.

01 · Infrastructure

White-label delivery

Agencies and consultancies deliver under their own brand, on our rail, invisibly.

For firms that are capacity-constrained rather than demand-constrained. You keep the client, the brand and the relationship; delivery runs underneath on escrowed milestones with named accountability and a guarantee. The objection to offshore delivery is almost always about recourse rather than skill, and recourse is the part that is already built.

  • Delivery under your brand, end to end
  • Escrowed milestones with defined approval gates
  • One accountable owner per engagement
Enquire about this
02 · Infrastructure

Agentic commerce engineering

Making services and systems purchasable by software agents, with accountability intact.

The settlement and authorisation rails for autonomous agents became usable in 2026, and they handle discovery, authorisation and payment. None of them handle whether the purchased work was any good. We build the machine-payable surface — priced endpoints, proof of intent, escrowed settlement, verifiable delivery — for organisations that want to be buyable by an agent without giving up recourse.

  • Machine-payable endpoints with proof of intent
  • Escrowed settlement and verifiable delivery
  • A human escalation path that actually resolves
Enquire about this

16 capabilities · 5 practices · one scope at a time

None of it starts with a quote. It starts with a session.

We map what exists, what it has to become, and what would make the project fail. You keep that map whether or not you engage us.

Start a conversation