From prototype to production
Your team is building prototypes: quick tools that solve a real problem someone knows inside out. This is how we turn them into software that can’t afford to break.
Where this starts
Turning your ideas into production-ready software
Somebody in your team understands a problem and has used AI tools to build something that works. That’s great, and by answering the “what should it do” question, they’ve given us a head start.
But, a prototype is built to show that an idea works. Before it becomes production-ready software it needs to be:
- Secure. Controlled access, secrets kept out of code, permissions so we know who can see what, and audit logging where needed.
- Dependable. Quality assured, tested for edge cases with error handling for if it does go wrong, and monitoring so you hear about any problems before your users.
- Maintainable. Somebody other than the author can read the code, understand how it works, make changes, and be confident that their change hasn’t broken something else.
- Usable. A prototype is usually tested with a handful of users. Production software has to work for everyone, which means accessibility testing and user experience design.
Then there’s the question of scale. Once you have a few prototypes in daily use, how do you keep track of them?
We take your prototypes and apply that engineering discipline, so your team and your users can rely on them.
How it works
The foundation gets built once. After that, each prototype goes through the same assessment and build process, and we look after everything.
Once
- Set up The secure foundation.
Then, for every prototype
- Assess A risk assessment, and how we recommend approaching the build.
- Build Specify, build, review in a demo environment, then live.
Once something is live, your team can keep experimenting on top of it. Anything they want in production starts again at Assess.
Ongoing, across everything
- Support We look after everything we’ve built for you.
Set up
The foundation needs to come first. This is a secure runtime inside your own cloud, using your own authentication, with controlled access to your data, managed deployment, and monitoring.
Every application we build later goes inside that runtime. Each one is isolated from the others, and anything it reaches beyond its own boundary goes through controls we manage.
This is also how you keep track of all your applications. Everything in production sits in one runtime environment with one set of controls. So you know what exists, what data they touch, and who looks after them all.
The scope of the foundation will be just enough to get your first application live, rather than covering every potential future scenario. We can always extend it later if something new needs it.
Your existing sign-in
Your cloud environment
Secure runtime
- App
- App
Each app isolated from the others
Your data and systems
Managed by us: deployment, secrets, monitoring, support
Assess
You talk us through the application and we produce a risk assessment that answers the following questions:
- What the prototype does, and why it was built
- What data it reaches, and how it interacts with it
- What happens if it goes wrong
- Whether it solves the right problem
- Whether its shape is clear, or there are unknowns
The questions are about your business and your data, not the code, so it just needs to be a demo and a conversation. This initial assessment for each prototype is included at no additional charge.
The risk assessment points to one of two potential next steps:
- If there’s low risk and clear scope then we can move straight to build.
- If the prototype touches a lot of your data, or if there are a lot of unknowns then we might propose a short Discovery to settle the scope before starting the build.
Build
The build runs as a set sequence:
- Analyse and specify. We use the prototype to create a specification and acceptance criteria so we’re all clear about what the application should and shouldn’t do.
- Agree scope and price. Once we have the specification we’ll give you a fixed price to build the application.
- Make it production ready. Secure, dependable, maintainable, and usable, to meet the specification we’ve agreed.
- Deploy to a demo environment. For you to review the application before going live.
- Go live. Inside the secure runtime, using your existing sign-in.
Support
Once it’s live we look after it. One support arrangement covers the foundation and the prototypes. We have flexible packages depending on how critical the software actually is.
Your team can continue to build on top of the new software inside a safe sandbox. When they’re at a stage where they want to put the changes into production, we start again at the assessment stage. Releasing to production is always a step we control, which makes everything else safe to experiment with.
Pricing
We don’t bill by the hour. Pricing follows the same shape as the build.
Once
- Set up One fixed price for the foundation.
Then, for every prototype
- Assess Included at no additional charge.
- Build A fixed price per application, set by its size once the assessment has established what’s involved.
Ongoing, across everything
- Support One arrangement covering everything we’ve built for you, not a charge per application.
A fixed price is fixed against the specifications we agree before building. If you want to change the scope along the way, then that’s OK; we can price those changes as we go.
Why us
We’ve built software for regulated sectors for over twenty years. We're a team of 25, based in York.
We hold ISO 27001, ISO 9001, and Cyber Essentials Plus, we’re an AWS Advanced Consulting Partner and a Microsoft Partner.
Bring us a prototype
If your team has built something that suddenly has to hold up in the real world, we’d love to hear about it. The assessment is free, with no obligation to build.
Talk to us about your prototypeTalk to us about your prototype: hello@isotoma.com