Skip to content

Southern Germany

Laravel development for companies in Frankfurt

In Frankfurt our projects are nearly always about traceability: who changed what and when, and can it be evidenced if it comes to that?

Frankfurt lives off banks, insurers and everything that has settled around them. The European Central Bank is here, so is the Bundesbank, and the financial regulator is on the doorstep. Add to that an infrastructure found nowhere else in this density. A good part of European data traffic hangs off DE-CIX, and Frankfurt is Germany’s largest data centre location.

For software projects that has an immediate consequence. Questions that sit at the edge elsewhere sit at the start here.

Traceability is not an added feature

In most projects the question “who changed that?” is a side matter. Here it is the starting point. When a transaction has to be evidenced later, storing the current state is not enough. There has to be a trail showing the way there, and it must not be possible to smooth it over afterwards.

Technically that is manageable. It does cost decisions about what gets logged, how long it is kept and who may read it. Those questions belong at the start, because they shape the data model. Retrofitted, something like this is expensive.

One point gets overlooked regularly. Logs must not only come into being, they also have to go away again. A trail that keeps everything for ever is not a security gain but a data protection problem on a delay.

Connecting to what is already there

Greenfield builds are the exception here. More usual is an application that sits between existing systems and moves data in both directions without either of them being touched. How we cut and secure interfaces like these is under API and backend development.

Operations come up for discussion earlier than elsewhere

In many projects, where the application should run is settled at the end. In Frankfurt that rarely goes well. When the data centre, the network zones and the approval routes are settled before the first design exists, it saves a round that would otherwise arrive near the end and hurt.

In practice that means we ask early about your operations requirements, even when we are not running it. An application requiring a particular database version that does not exist there is an avoidable annoyance.

A second opinion before the decision

Some of the enquiries from Frankfurt are not about building anything. A quotation is on the table, or an application already in service is to be assessed before somebody releases money. That is what the code audit is for: an assessment with reasons, including when the answer is that everything is in order.

Süddeutschland

Weitere Städte in Süddeutschland

All locations

FAQ

Questions from Frankfurt

Can you implement requirements from an internal audit?
If they are concretely worded, yes. What we do not supply is a legal opinion on whether an implementation satisfies a regulation. We build what your department or your auditor requires, and say in advance which parts get technically expensive.
Where does the application run in the end?
Wherever you want it to. A large share of our clients host in Germany, some in their own data centre, some with a provider based here. We follow that, and we run nothing without it being settled who has which access during an incident.
How long do logs have to be kept?
Your organisation decides that, not us. What we contribute is the technical side: that logs are complete, cannot be altered after the fact, and actually do disappear once the period is over. That last point gets forgotten regularly and is the more delicate one in data protection terms.
Do you work with our security team?
Gladly, and preferably early. A security review at the end of a project almost always leads to rebuilding that could have been avoided. If we know the requirements before the design, they cost a fraction.
Can you support a penetration test?
We do not carry them out ourselves but we work with the results regularly. With us a report turns into a sorted list with effort attached and a view on which findings really press and which are not exploitable in your environment at all.

A project in Frankfurt?

Where auditability matters, we settle it before the quotation. It changes the scope.