Service · Production Platform
The product your business runs on — or sells.
A full production system that scales and survives real customers. Accounts, billing, AI, search, security, dashboards — built to a standard most agencies can’t match because we built the engine that enforces it.
From £25,000
What you get
The full system, built to last.
Every capability a production SaaS or internal platform needs — not a menu you pick from, but the complete system delivered together.
Multi-tenant accounts
Organisations, roles, invitations, member management. Per-row security enforced at the database, not just hidden in the UI. A misrouted query returns nothing.
Billing and subscriptions
Stripe with real webhooks, dunning, grace periods, refunds, and a billing portal. Not a Stripe Checkout redirect — a real billing surface.
AI features
Chat with history, autonomous agents with tool permissions and audit logs, RAG over your data, AI-generated content. Eval gates in CI so quality regressions fail the build.
Search — hybrid and semantic
Fuzzy keyword + trigram inside Postgres for typo tolerance. Vector embeddings for semantic similarity. A unified search surface across both.
Security, enforced
Eight security patterns on every table and action. The automated pentest suite runs on every deploy. Not a checklist — a system that makes the bad paths impossible.
Admin dashboards
A full admin CMS for your team — typed content models, media management, role-based access, audit log on every write. Built with the generated CMS.
Integrations and job queues
Webhooks with retry logic and signature verification. Background job queues for async workloads. Realtime subscriptions for live UI updates.
Notifications and email
Transactional email wired to real data events. In-app notifications. Structured event delivery with delivery guarantees — not a fire-and-forget.
Engineering rigour
We built the engine. Every client build runs on it.
Built for ourselves — and for clients.
canarlo-core — the engine
30+ generators across every surface
Config in, full production system out — the same engine on every build.
AIchatagentsRAGsummariessemantic searchBuildauthpaymentsCMSstorageCSV/SDKIntegratewebhooksjob queuesrealtimeedge functionsSecurity — eight patterns, enforced
Eight security patterns on every table and action
Not a checklist — the generator makes the bad paths structurally impossible.
ValidateZod inputsUUID checksMIME validationIsolategetUser() authRLS data isolationcorrect client scopeHardenstructured errorspagination clampsMigrations — auto-diffed
Schema changes that never break production
Additive-only SQL, every change a reviewable diff before it touches the database.
Alwaysadditive-onlyreviewable diffNeversilent DROPsdata-truncating castsremoved constraintsDelivery OS
Supervised AI agents on every build
An internal dashboard that supervises parallel AI agents — every client build runs through it.
Runsparallel subagentsovernight jobsscheduled pipelinesTracksplan → build → shiplive progressPentest suite
The platform tests itself
Automated security tests run on every deploy — vulnerabilities caught before they ship.
TestsSQLiIDORauth bypassMIME bypasspagination exploitfield leakageWhat you own
The code is yours. So is the data.
No Canarlo runtime in production — your repo, your cloud, your keys.
YoursVercel accountSupabase projectStripe accountplain TypeScriptIncludedhandover docevery env var namedevery cron named
How it works
From first call to production system.
Discovery
One scoping call, then a written brief. Load-bearing pieces named, failure modes mapped, assumptions identified. Two weeks. No workshops.
Architecture
Schema, API surface, security boundary, integration contracts — on the page before a line is written. You sign off. Two weeks.
Build
Twelve to twenty weeks. Weekly preview URL, readable diffs, every security pattern enforced from day one. You see what shipped and why.
Ship
Deployed to your cloud, keys transferred, pentest run, runbook delivered. First week of real traffic monitored. Not a goodbye email.
The system your business runs on, built to a standard that holds under load.
Questions
What technical buyers ask before they commit.
What makes this a 'production platform' rather than just a web app?
The full system: multi-tenant accounts, Stripe billing with real webhooks and dunning, AI features with cost dashboards and eval gates, semantic and keyword search, job queues, realtime subscriptions, admin dashboards, notification systems, structured audit logs. Eight security patterns enforced on every table and action — not bolted on after launch. It's the product your business runs on, not a prototype you need to rebuild.
How long does the build take?
Two weeks discovery, two weeks architecture, twelve to twenty weeks production build depending on scope. The timeline is defined in the architecture phase — not guessed at kickoff. Every phase ends with a concrete artefact: a brief, a schema, a deployment.
Who owns the code?
You do. Your repo, your Vercel account, your Supabase project, your Stripe account, your keys. No Canarlo SaaS in the loop, no licence fees. The handover doc names every environment variable, every cron, and every failure mode. You can take it in-house tomorrow.
How do you handle security compliance?
Eight security patterns are enforced by default on every table and action: Zod validation, getUser() auth checks, UUID validation, correct Supabase client scope, RLS-backed data isolation, structured error responses, MIME validation on uploads, and clamped pagination. Our auto-diffing migration engine ensures no migration drops security constraints silently. The platform includes its own automated pentest suite.
We already have an MVP. Can you take it to production?
Yes. We start with an audit — a structured review of the existing codebase, security posture, data model, and scalability profile — then produce a written report and migration plan. We'll tell you what's worth keeping, what needs to change, and what the build will cost.
What does AI add at this tier?
Real AI features: chat interfaces with history and session management, autonomous agents with tool permissions and audit logs, RAG over your own data with source citations, AI-generated summaries and content blocks, semantic vector search. All with cost dashboards, eval gates in CI, and circuit breakers — not a ChatGPT wrapper bolted on.
Where we work
UK-wide from Leeds. On-site across Yorkshire.
The service covers the whole of the UK, remote-first. Looking for an AI development company near Leeds? The local pages cover on-site availability and area-specific context.
Start here
One call, honest answer.
Tell us what you’re building and where you are. If the work fits, we’ll say so. If you’re better served by an audit first, we’ll say that too.