AI-native software engineering studio
BESPOKE
SOFTWARE
We design and build complete web applications and the whole environment they live in, with security engineered in from day one and AI agents under human supervision.
- 01
- Secure by design
- 02
- Multi-model, no lock-in
- 03
- Plugin published on WordPress.org
How we build
- 01Discovery
- 02Architecture
- 03App and environment
- 04Secure by designOWASP · MITRE ATLAS
- 05Human in the loop
- 06Deploy and observability
01Stack
- Anthropic
- OpenAI
- ElevenLabs
- n8n
- Make
- Qdrant
- WooCommerce
- Shopify
- WordPress
- Canva
- Google Drive
- 19 more
02What we build
The project and its environment
We don’t just hand over an application: we hand over the system and the operating environment that keeps it running.
03How we work
Autonomous agents, under human control
We build with AI agents that earn autonomy only after working under supervision: we observe, correct, improve.
- 01
Human-in-the-loop
Every agent action is observed and verified by a person.
- 02
Verify and measure
We measure behaviour and fix the edge cases.
- 03
Growing autonomy
Autonomy increases only where it proves reliable.
- 04
Confirmation on risk
Sensitive actions always keep a human confirmation.
04Secure by design
Real standards, really applied
Security is not a slogan: we design on recognised frameworks, from the web to LLM-based applications.
OWASP Top 10
Web applicationsThe most critical web application risks, from injection to broken access control.
OWASP API Security Top 10
APIsAPI-specific risks: object-level authorization, data exposure, abuse.
OWASP ASVS
VerificationAn application security verification standard to check software in depth.
OWASP Top 10 for LLM Applications
LLM appsRisks of LLM-based applications: prompt injection, data leakage, insecure output.
MITRE ATT&CK
ThreatsThe knowledge base of real-world adversary tactics and techniques.
MITRE ATLAS
AI system threatsThe threat landscape specific to artificial-intelligence systems.
NIST AI RMF
AI risk managementThe framework for identifying and managing the risks of AI systems.
ISO/IEC 42001
AI governanceThe standard for an artificial-intelligence management system.
EU AI Act
RegulationThe European regulatory framework for AI: transparency and obligations for those who build with AI.
05AI landscape
Hundreds of models. We pick the right one.
We know the frontier labs and use each for what it does best, without tying ourselves to a single vendor.
Our operating principle
- The right model for the right task: reasoning, speed or cost change the choice.
- Multi-provider routing, with no lock-in to a single vendor.
- Evaluation and fallback: we measure output and always keep a plan B.
- AnthropicClaude
The Claude family (Opus, Sonnet, Haiku).
- OpenAIGPT
The GPT family.
- GoogleGemini
The Gemini family.
- AmazonNova
Nova models, served on Amazon Bedrock.
- MetaLlama
The Llama family, open-weights.
- Mistral AIMistral
Mistral models, including open-weights.
06What we’ve built
Real software, in production
Our own products and commissioned work. No invented numbers: only things that exist and can be verified.
- Leomat product · E-commerce
Katapic
A SaaS that scans a WooCommerce catalogue, scores every product for visibility on Google and AI search, and rewrites the weakest listings in bulk.
Official plugin published on WordPress.org.
Visit - Leomat product · Web
leomat.it
This very site: an SPA with server-side rendering for crawlers, a blog powered by an AI editorial pipeline and AI-content disclosure as required by the EU AI Act.
Visit - Leomat product · Financial data
Portfolio intelligence for ETFs
A multi-user platform with per-user data isolation at the database level, signals put through statistical validation and the ability to abstain when the data is not enough.
- Commissioned · Travel
Tour-operator management system
Tour and fleet planning, operational tasks, quotes and an AI consultant that acts on the data with human confirmation on sensitive actions.
- Leomat product · Operations
Hours reporting
An hours-tracking tool integrated with project management, with monthly budgets, carry-overs and a security surface hardened after a full audit.
- Commissioned · Media
Competitive SEO for publishing
A tool for analysis and a competitive content loop grounded in a real crawl of the site: proposals come from data, never invented.
07Frequently asked questions
For agencies
Are you an agency? Here’s the AI department you don’t have.
White-label AI engineering arm: you keep the client and the brand, we bring the execution. Bespoke software, AI agents, integrations, operational tools. A dedicated page, made just for agencies.
08Next step
Let’s talk about your project
Tell us what you want to build. We’ll come back with an approach, an architecture and a real estimate.