PENCILL LTD

03

Services, described in the terms we work in.

Twelve service lines, delivered individually or combined into a single programme of work. Each engagement is scoped in writing before it starts, and each description below reflects work we take on directly.

We describe capabilities rather than outcomes we cannot control. Where a requirement falls outside what we do well, we say so.

Service index

  1. 01Custom software development
  2. 02Web application development
  3. 03Cloud solutions and infrastructure
  4. 04API and systems integration
  5. 05Product design and UX engineering
  6. 06Data engineering and analytics
  7. 07Quality assurance and test automation
  8. 08Cybersecurity-oriented engineering
  9. 09Legacy system modernisation
  10. 10Technical consulting and architecture
  11. 11DevOps and continuous delivery
  12. 12Software maintenance and support

Detailed service descriptions

01

Custom software development

Systems built around a specific domain rather than around a template.

We design and implement applications where an off-the-shelf product does not fit the process it is meant to support. The domain rules are captured in writing, modelled explicitly in the code, and covered by tests so that the behaviour remains inspectable as the business changes.

  • Domain modelling
  • Specification and acceptance criteria
  • Incremental delivery
  • Handover documentation

02

Web application development

Browser-delivered applications built for accessibility, speed and durability.

Interfaces are built with semantic markup, keyboard operability and readable contrast as baseline requirements. We measure page performance rather than assume it, and structure front-end code so that a later team can extend it without rewriting the foundation.

  • Component architecture
  • Accessibility baseline
  • Performance budgets
  • Progressive enhancement

03

Cloud solutions and infrastructure

Environments defined as code and provisioned the same way every time.

We describe infrastructure declaratively so that development, staging and production stay comparable. Capacity, cost and failure behaviour are considered at design time, and the resulting configuration is version-controlled alongside the application it supports.

  • Infrastructure as code
  • Environment parity
  • Cost and capacity review
  • Backup and recovery design

04

API and systems integration

Reliable movement of data between the systems an organisation already runs.

Integration work starts with an explicit contract: what is exchanged, in what shape, how often, and what happens when the other side is unavailable. Retries, idempotency and error visibility are part of the design rather than later corrections.

  • Interface contracts
  • Data mapping
  • Failure and retry design
  • Monitoring of exchanges

05

Product design and UX engineering

Interface design carried all the way through to implemented components.

Design and implementation are treated as one activity. Flows and states are worked out with the people who will use them, then expressed as a component system so that what is designed and what ships remain the same thing.

  • Flow and state design
  • Design system components
  • Usability review
  • Accessible interaction patterns

06

Data engineering and analytics

Pipelines and models with traceable lineage from source to report.

We build ingestion and transformation pipelines whose outputs can be explained. Each figure in a report can be traced back through the transformations that produced it, and data quality checks run as part of the pipeline rather than as periodic audits.

  • Ingestion pipelines
  • Dimensional modelling
  • Data quality checks
  • Reporting layers

07

Quality assurance and test automation

Layered testing arranged around the risks that actually matter.

Test strategy is written before suites are built, so effort concentrates where failure would be costly. Automated checks run on every change, and manual exploratory testing is reserved for the areas where judgement outperforms scripts.

  • Test strategy
  • Unit and integration suites
  • End-to-end automation
  • Regression management

08

Cybersecurity-oriented engineering

Security treated as a property of the design, not a later addition.

We carry out threat modelling during architecture, define trust boundaries explicitly, and apply least-privilege access across services and data stores. Secure delivery practices — dependency monitoring, secret management, hardened pipelines — are part of the standard build.

  • Threat modelling
  • Access and trust boundaries
  • Dependency monitoring
  • Secure delivery practice

09

Legacy system modernisation

Incremental replacement that keeps the business running throughout.

Rather than a single cut-over, we identify seams in the existing system and replace behaviour behind stable interfaces. Each step is independently valuable and reversible, which keeps risk proportionate to the size of the change.

  • System assessment
  • Seam identification
  • Strangler-pattern migration
  • Data migration planning

10

Technical consulting and architecture

Written architecture, options analysis and considered second opinions.

We produce architecture documents that state the options considered, the trade-offs of each, and the reasoning behind the recommendation. The deliverable is something a technical and a non-technical reader can both act on.

  • Architecture documentation
  • Options and trade-off analysis
  • Technology assessment
  • Review of existing designs

11

DevOps and continuous delivery

Pipelines, observability and release practice that reduce release risk.

Build, test and deployment are automated so that releasing is routine rather than an event. Logging, metrics and tracing are configured alongside, so the behaviour of a release can be observed instead of inferred.

  • Build and release pipelines
  • Environment automation
  • Observability setup
  • Release and rollback practice

12

Software maintenance and support

Corrective, adaptive and preventive care for systems in production.

Support is defined as a service with an agreed scope and response arrangement. Maintenance covers fixing defects, adapting to platform changes, and the preventive work — dependency updates, capacity review — that stops small issues becoming outages.

  • Defect resolution
  • Platform and dependency updates
  • Preventive maintenance
  • Ongoing improvement

Scope

How work is scoped

Every engagement begins with a written scope: the problem, the constraints, the acceptance criteria and the assumptions we are relying on. Estimates state what is uncertain and why. Where an assumption turns out to be wrong, the scope is revised in the open rather than absorbed quietly.

Written

Scope and criteria recorded before work starts.

Reviewed

Progress demonstrated against those criteria.

Revised openly

Changes discussed, costed and agreed.

Abstract diagram of data paths passing through layered protective rings in cool blue tones
Fig. F — Controlled delivery path

Service enquiries

Written enquiries are answered in English. Company details are shown below as plain text.

Company
PENCILL LTD
Email
shawnanguyen1981@gmail.com
Website
pencillgroup.com