What we do

Three engagement models, three expertises.

The model is chosen before the scope: it decides what is billed, who operates, and who answers the day the system fails.

Two questions come up, and the order matters. The first is contractual: on what terms do we come in, and who carries operations the day the system fails. The second is technical: in which domain. A supplier file that answers the second before the first produces a scope nobody can hold, because nobody said who was holding it.

Three models answer the first question: engineers embedded in your teams for twelve months and up; an audit and architecture engagement of one to three months, ending in a report; a support contract that covers your entire open source stack against a monthly pool of hours. Three expertises answer the second — data and lakehouse, security and governance, artificial intelligence. The two combine freely: one expertise can be delivered by embedded engineers, examined in an audit, or maintained under a support contract.

What sets us apart comes from an old and expensive choice: we go down to the level where the components are written. We write, in Rust, the Trino client and the Talos client we run at our clients' sites, and we publish them under open licences. You cannot operate what you do not understand.

Engagement models

The terms we work under.

What is billed, for how long, who operates, how escalation works, what is guaranteed and what stays with you when you leave.

The contract, model by model.
CriterionEmbeddedAudit & architectureOpen source support
What is billedDedicated engineers, on the time they spend inside your teams.A fixed-price engagement, with the scope settled before it starts.A monthly pool of hours, one contract for the whole stack.
Commitment lengthTwelve months and up.One to three months.Ongoing.
Who runs it day to dayYour teams, with our engineers inside them.Nobody. The engagement produces a document, not a running system.Your teams. We step in at L2 and L3 on the components written into the contract.
Who decides the architectureYou. We prepare the case, you decide.You, from a written file that carries its assumptions and its limits.You. We flag whatever makes the stack impossible to keep running.
How escalation worksThrough your own channels: our engineers are in the team, and hold priority on our critical support.Not applicable: there is no production to hold up.Straight to L2 then L3, with the engineers who write the code. No general-purpose first line.
What gets deliveredCode, infrastructure described as code, operational runbooks.A report: current state, target architecture, migration plan, costs.Operational and security maintenance, patches, version upgrades, CVE monitoring bulletins.
Hours and targetsYour teams' own rhythm: our engineers are part of them.Not applicable.Covered hours, response and resolution targets: written into the contract, according to how critical the component is.
What you keep when you leaveEverything we write belongs to you.The report, its assumptions and its calculation annexes.Your components as they are: they are open source and do not depend on us.

Embedded

12 months and up

Engineers embedded in your teams

Our engineers work inside your teams, on your tooling and your processes. Continuous skills transfer, direct access to the experts, priority on critical support.

  • Dedicated engineers, no imposed rotation
  • Continuous skills transfer to your teams
  • Priority on critical support
  • Reversibility: everything we write belongs to you

Best for

Continuous transformation, infrastructure and data teams.

Audit & architecture

1 to 3 months

An architecture decision, costed

Data stack audit, application security audit, migration plan, infrastructure and GPU sizing. The deliverable is a report your committee can read — with its assumptions and its limits written in the same place as its conclusions.

  • Data stack and application security audit
  • Target architecture and migration plan
  • Infrastructure and GPU inference sizing
  • A written deliverable that holds up in committee

Best for

Scoping, strategic decisions, building an investment case.

Open source support

ongoing

One contract for your whole open source stack

You do not want one support contract per component. We cover your open source stack with a single monthly fee, one point of contact, and direct escalation to our engineers — not a general-purpose helpdesk.

  • A single fee, not one contract per component
  • Direct L2/L3 escalation to our engineers
  • Maintenance, patching and CVE monitoring included
  • Component scope written into the contract

Best for

Day-to-day security, predictable budget, a broad open source stack.

Scope covered by the open source support contract

One contract, one monthly pool of hours, one point of entry for all of these components — where the market bills them one at a time. Operational and security maintenance, patches and CVE monitoring are included. The exact list is settled in the contract, and it holds only components we run ourselves.

Platform and runtime

KubernetesTalos LinuxKubeVirt

Data

PostgreSQLTrinoCephMinIOAirflowKafka

Identity, network and observability

KeycloakIstioCiliumcert-managerstack Grafana

Expertises

Three domains, and what we can do in them that others cannot.

In each one we go down to component level: the result transport protocol, the node administration API, the distributed inference chain.

01

Data & Lakehouse

Data you can query, trace and move.

We design and run open data platforms: open table formats, a query engine decoupled from storage, lineage and catalogue. Reversibility guides every choice — being able to leave without a rewrite.

TrinoApache IcebergMinIOCephAirflowKafkaPostgreSQL

Evidence We write trino-rust-client: 45 Rust files, 6,374 lines, MIT licence, spooling protocol implemented. nudibranches-tech/trino-rust-client

Capabilities

  • Medallion architecture, data vault, modelling
  • ETL, OCR, document ingestion
  • Iceberg lakehouse, Trino engine, catalogue and lineage
  • Streaming and high-volume processing
  • Vector search and semantic indexing

02

Security & Governance

Architectures where a leak is not an option.

Encryption, fine-grained access control, complete audit logging, segmentation. We audit existing data stacks and we tool the technical requirements of NIS2 — without ever claiming to make you compliant on your behalf.

KeycloakIstioCiliumcert-managerOWASPTalos

Evidence We write talos-rust-client: 14 files, 8,316 lines, mandatory mTLS, published on crates.io. nudibranches-tech/talos-rust-client

Capabilities

  • Data stack and application security audits
  • Encryption, key management, multi-tenant segmentation
  • Fine-grained access control and audit trail
  • Tooling for the technical requirements of NIS2 and GDPR
  • Zero Trust, mTLS, supply chain control

03

Artificial intelligence

Your models on your side, your data never leaves.

Inference and fine-tuning on your infrastructure: GPU sizing, serving architecture, agents and the MCP protocol. We favour sourced answers — an answer that does not cite its document is unusable in a regulated business.

vLLMTritonKServeKubeflowMCPpgvector

Evidence A chain we run in production: KServe, LeaderWorkerSet, the NVIDIA GPU Operator and vLLM, described in GitOps.

Capabilities

  • In-house LLMs, on-premises inference and fine-tuning
  • GPU sizing and serving architecture
  • AI agents, pattern selection, MCP implementation
  • Sourced answers, structured extraction
  • Model selection support, with no vendor lock-in

Compliance

What stays your responsibility.

  • We hold no certification: no SecNumCloud, no HDS, no ISO 27001.
  • Built to tool the technical requirements of NIS2 — shared responsibility matrix published. Risk-management measures fall on the entity, not on its supplier. §

Get in touch

Choose the model before describing the need.

A first thirty-minute conversation is enough to settle the first question — embedded, audit, or support contract — and to know whether we are the right supplier. We will also say so when we are not.

contact@nudibranches.tech · +33 6 01 82 82 30