Atmora Tech

Enterprise technology partner

We build the systems your business runs on.

Atmora Tech designs, builds and runs the software that moves your orders, your money and your material — product engineering, AI, cloud and enterprise platforms for organisations where downtime is measured in lost revenue.

10 yrs
in production
120+
engineers
14
countries

AWS Partner · Microsoft Partner · Google Cloud Partner

Selected outcomes

In production
  • 19 → 1

    auction formats consolidated onto one bidding engine

    Meridian Exchange

  • 11 days → 40 min

    quote-to-cash cycle time

    Kestrel Industrial

  • 99.98%

    uptime across two years of continuous migration

    Vantara Metals

Trusted by

Since 2016

  • Meridian Exchange
  • Kestrel Industrial
  • Northwind Commodities
  • Vantara Metals
  • Corvus Logistics
  • Aldridge Risk
  • Halden Group
  • Orbit Supply
10
years in production
120+
engineers and designers
14
countries shipped into
240+
projects delivered

What we do

44 services, six disciplines

We do not keep a long-tail service list. These are the practices we staff properly, and every page says plainly when the service is the wrong fit.

Industries

Sectors we know well enough to argue about

Domain knowledge is the difference between shipping software and shipping the right software.

Featured work / 2024

Rebuilding Meridian Exchange's bidding engine around per-lot single-writer partitions

Meridian was losing bids to lock contention in the closing seconds of every auction, and disputes over bid order had to be settled manually. We rebuilt the engine around per-lot single-writer partitions and an append-only log, trading cross-lot transactions for provable ordering at 1,800 bids per second.

  • B2B Marketplace
  • 9 months
  • 7 engineers, 1 designer, 1 delivery lead
Read the case

Selected work

Systems currently
running in production.

All 8 case studies

Why Atmora

Claims you can check

Each of these is falsifiable. If we miss one on your engagement, you will know before we do.

  • Production deployment in week three

    Not a staging environment and not a demo. By the end of week three a real slice of the system is deployed to production in your cloud account, behind a feature flag, with Prometheus alerts and an on-call runbook. Pipelines, secrets management and rollback are proven with live traffic before anyone writes the second feature. If we miss that date, it appears on the week four steering report with the reason.

  • Named engineers, held by contract

    The statement of work lists the team by name, seniority and allocation percentage. Any change requires 30 days' written notice and a two-week overlap handover, and the replacement is proposed to you rather than assigned. Over the past three years, 78% of engineers stayed on an account for its full duration; on our four longest-running clients, the original tech lead is still in place.

  • Discovery you can walk away from

    Two to three weeks, fixed fee, no obligation to continue. You receive the architecture assessment, the risk register, the migration sequence and a costed estimate with an explicit ±25% band, all under your copyright. Roughly one discovery in six ends with us recommending you do less than you asked for, or nothing at all. We have written that recommendation for clients who were ready to sign eight-figure programmes.

  • Your repositories, your cloud, from the first commit

    Code lands in your GitHub organisation and infrastructure in your AWS, Azure or GCP accounts on day one. There is no Atmora-hosted runtime, no proprietary framework you have to keep licensing, and no source code escrow arrangement, because there is nothing to escrow. If you terminated tomorrow, the system keeps running and your team keeps deploying it.

  • Delivery metrics published every month

    Every steering pack carries the DORA four per team — deployment frequency, lead time for change, change failure rate, mean time to restore — pulled from your CI and incident tooling rather than from a slide. Current portfolio medians: 11 deployments per week, 2.4 days lead time, 6% change failure rate, 41 minutes to restore. You can audit the source data yourself; it sits in your systems.

  • Modernisation without a code freeze

    We replace legacy systems with strangler-fig routing: old and new run side by side, traffic moves capability by capability, and each cutover is reversible by a routing flag in under ten minutes. Across more than 40 modernisation programmes since 2016, none has required a business change freeze longer than 48 hours, and no cutover has been rolled back more than once.

How we work

Two weeks. A written definition of done.

Each increment opens with a signed scope and closes with something deployed to your production environment. You can stop at any boundary and keep everything built so far.

  1. Discovery and technical due diligence

    Two engineers and a delivery lead go into your codebase, database and incident history. We read the schema, run a dependency and CVE inventory, sit with the people who actually use the system, and measure what is slow rather than accept what is reported as slow. Output is a written architecture assessment, a risk register with named owners, and a costed delivery sequence carrying a stated ±25% confidence band. Fixed fee, and the documents are yours whether or not the engagement continues.

    2–3 weeks
  2. Architecture and delivery plan

    We record the decisions as architecture decision records: service boundaries, data ownership, sync versus event-driven integration, the consistency model, and what we deliberately are not building. Non-functional targets get numbers — p95 latency, concurrent users, recovery point and recovery time objectives, retention windows. You approve the plan, the team roster by name, and the definition of done before any production code is written.

    1–2 weeks
  3. Foundation sprint and first production deploy

    Infrastructure as Terraform in your cloud account, repositories in your GitHub organisation, CI with unit tests, SAST and container scanning, and Argo CD promotion into staging and production. Before feature work starts we put a thin but real slice of the system into production behind a feature flag, with dashboards, alerts and an on-call runbook attached. That deployment happens in week three and is the point at which the pipeline stops being a promise.

    3 weeks
  4. Iterative build

    Two-week sprints, trunk-based development, deployment to production on merge behind flags. Each sprint ends with a working increment on your infrastructure, not a demo environment. You get a burn-up against the agreed scope, the DORA four metrics for the team, and an explicit list of what moved out of scope and why. The first release to real users typically lands between weeks 10 and 16, depending on integration surface.

    8–20 weeks
  5. Hardening, performance and security testing

    Load testing to twice the agreed peak, with results published as latency percentiles rather than averages. Failure injection on the dependencies that matter — database failover, broker partition, third-party timeout. A third-party penetration test against the release candidate, with every high and critical finding closed before cutover and mediums scheduled with dates. Backup restore is rehearsed in full, timed, and written into the runbook.

    3–4 weeks
  6. Cutover, hypercare and handover

    Migration runs as a rehearsed sequence with a rollback path measured in minutes, usually strangler-fig routing so the legacy system stays live and reversible. Four weeks of hypercare with our engineers on your on-call rota, then a structured handover: runbooks, architecture diagrams that match the deployed system, recorded walkthroughs and paired shifts with your team. Where you keep us on, the same named engineers move to a run-and-evolve cadence.

    4–6 weeks, then ongoing

Technology

What we build with

Chosen for operational boredom rather than novelty. Everything here is something we run in production today.

Languages

  • TypeScript
  • Python
  • Go
  • Java
  • C#
  • PHP
  • Rust

Frontend

  • React
  • Next.js
  • Angular
  • Tailwind CSS
  • Vite

Backend

  • Node.js
  • NestJS
  • Django
  • FastAPI
  • Spring Boot
  • Laravel

Mobile

  • React Native
  • Flutter
  • Swift
  • Jetpack Compose

Cloud

  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud Platform
  • Cloudflare

Data

  • Apache Kafka
  • Apache Airflow
  • dbt
  • Apache Spark
  • Debezium
  • Power BI

AI/ML

  • PyTorch
  • scikit-learn
  • Hugging Face Transformers
  • LangGraph
  • MLflow
  • Anthropic Claude API

DevOps

  • Kubernetes
  • Docker
  • Terraform
  • GitHub Actions
  • Argo CD
  • Prometheus
  • Grafana
  • OpenTelemetry

Databases

  • PostgreSQL
  • MySQL
  • MongoDB
  • Redis
  • ClickHouse
  • Elasticsearch

Security

  • HashiCorp Vault
  • Keycloak
  • Snyk
  • Trivy

Clients

What they said afterwards

  • Our bidding engine collapsed above roughly 400 concurrent bidders on a closing lot, always in the last 30 seconds. Atmora rebuilt the bid path around Redis streams with an idempotent write model and moved settlement onto an event log. We now hold 6,000 concurrent bidders with p99 bid acknowledgement at 180ms. The first version was in production in week three, and they kept the old engine live alongside it for two months until we were satisfied.

    Priya Raghunathan

    Chief Technology Officer · Meridian Exchange

  • We asked for a full shop-floor scheduling replacement and got an honest answer that two thirds of what we wanted already existed in our ERP and had been switched off. The scope they did take — machine allocation and cutting optimisation — reduced offcut waste from 9.1% to 4.6% across three plants in the first quarter. They talked us out of about a third of the original budget before we signed anything.

    Martin Vance

    Group Head of Manufacturing Systems · Kestrel Industrial

  • Position and P&L used to arrive at 10:00 the following morning, at the end of a chain of spreadsheets nobody fully understood. Atmora rebuilt the valuation run on Airflow and ClickHouse with exception reporting; it now completes at 19:40 and reconciles itself. Four analysts who spent their mornings chasing breaks moved onto actual risk work. The new run operated in parallel with the old process for six weeks before we turned that off.

    Sarah Whitfield

    Head of Risk Technology · Northwind Commodities

  • Three years in, two engineers from the original team are still on the account and the tech lead has never changed. That continuity is why a carrier integration that used to take six weeks now takes four days: they wrote the adapter framework, and they still remember why every decision in it was made. When we did need a replacement, we met the person before they joined and got a fortnight of overlap.

    Rajat Menon

    VP Engineering · Corvus Logistics

  • They pushed back on our language model plan, and they were right to. Rather than a chatbot over policy documents, they built retrieval with enforced citation and an explicit refusal path when confidence is low. Compliance signed it off in a single review because every answer traces to a clause number and the evaluation set is versioned. Handling time on policy queries fell 44%, and we can show the regulator exactly how it works.

    Fiona Sharpe

    Director of Compliance Technology · Aldridge Risk

  • Our approval matrix runs to 14 levels across four legal entities and three currencies, and every previous vendor wanted to hard-code it. Atmora modelled it as data, so our own team now changes thresholds without waiting for a release. Go-live slipped by one week against a 22-week plan, and we were told in week nine rather than week 21. Purchase order cycle time is down from 11 days to under three.

    Tom Beasley

    Head of Procurement Systems · Orbit Supply

FAQ

What procurement asks first

Pricing model, IP ownership, security, data residency, team continuity and exit. Answered here rather than on the fourth call.

How do you price engagements, and what is actually fixed?

Three shapes. Discovery is fixed price for two to three weeks. Well-specified work packages — an integration, a migration, a defined module — can be fixed price once discovery has produced the design. Ongoing product development runs as a dedicated team on time and materials with a contractual monthly cap, billed on named roles rather than a blended rate, so you can see what each person costs. Teams are typically five to eight people including a delivery lead and a QA engineer. Notice is 30 days for scale-down and 60 days for termination for convenience. There are no licence fees, per-seat charges or runtime royalties on anything we build for you.

Who owns the intellectual property in what you build?

You do, assigned on creation rather than on final payment, so a payment dispute never becomes an IP dispute. The contract schedules any pre-existing Atmora components used — mostly infrastructure modules and CI templates — and grants you a perpetual, irrevocable, royalty-free licence to them with no field-of-use restriction. Every release ships with an SPDX software bill of materials listing open-source dependencies and licences; we will not introduce copyleft-licensed code into your distributed products without written approval. We do not retain a copy of your source after transition, and we do not reuse client-specific code across accounts.

What is your security posture, and can you evidence it?

ISO 27001 and SOC 2 Type II, with reports available under NDA and a completed CAIQ on request. Engineers work on managed, encrypted, MDM-enrolled laptops; no client code sits on personal devices; access to your systems runs through your identity provider with hardware-backed MFA. Secrets live in HashiCorp Vault or your cloud's secret manager, never in repositories. CI runs SAST, dependency scanning and container scanning on every pull request, with builds failing on new criticals. Background and right-to-work checks are completed before onboarding. We notify you of a security incident within 24 hours of detection and provide a written root-cause analysis inside ten working days.

Where does our data live, and who can see it?

Systems deploy into your cloud accounts and your chosen regions — for UK and EU work that usually means London, Ireland or Frankfurt — and data does not leave them. Engineering staff in India reach non-production environments through a virtual desktop with clipboard and local storage disabled, so nothing is copied to a device outside the region. Production access is exception-based, time-boxed, approved by you and logged. Where regulation or internal policy requires it, we staff the engagement entirely from our London office at a higher day rate. Data processing agreements include EU standard contractual clauses and the UK international data transfer addendum, plus a sub-processor list with 30 days' notice of any change.

How do you keep the same people on our account?

The statement of work names each engineer with role, seniority and allocation. We cannot rotate someone off without 30 days' written notice to you, a proposed replacement you can interview, and a two-week paid overlap that we do not bill twice. Key-person clauses cover the tech lead and the architect. Across the portfolio, 78% of engineers remain on an account for its full duration and average tenure at Atmora is 4.1 years. We staff from our own permanent employees; we do not backfill from contract markets when someone leaves, which is the usual cause of silent team churn.

What happens at the end, or if we want to leave early?

Exit is designed in from the start: your repositories, your cloud accounts, your CI, no Atmora-hosted runtime and no proprietary framework, so there is no technical lock-in to unwind. Contractual transition assistance is 90 days at agreed rates and can be invoked for any reason, including a move to another supplier. Handover covers runbooks, architecture diagrams verified against the deployed system, recorded walkthroughs, a dependency and licence inventory, and paired on-call shifts with the incoming team. On request we run an exit rehearsal midway through the engagement: your team deploys and restores the system unaided while we watch. Anything it exposes is fixed as defect work at our cost.

How is change controlled when scope moves?

Estimates come out of discovery with an explicit ±25% band and named assumptions; we do not quote precision we do not have. Anything that changes agreed scope goes through a written change request with its own estimate and an impact statement on date and cost, approved by your sponsor before work starts. Inside a fixed-price package we absorb our own estimation error — that is what the fixed price buys. Scope trades are encouraged: swapping work of comparable size within a sprint needs no paperwork. Every steering pack lists what moved out of scope that month and who decided it.

What support do you provide after go-live, and against what SLAs?

Four weeks of hypercare after cutover is included, with our engineers on your on-call rota alongside your team. Beyond that, managed support is a separate agreement with tiered response: P1 (service down or data at risk) 30-minute response and continuous work until service is restored, P2 four business hours, P3 next business day. Cover is business hours in your timezone by default, or 24x7 on a follow-the-sun rota across Bengaluru and London. Service credits apply against monthly fees for missed response targets. Monthly service reviews publish incident counts, mean time to restore, and the known-defect backlog with ages.

Do you subcontract or use third-party staffing?

No. Everyone on your account is a permanent Atmora employee, which is what makes the continuity terms enforceable. We will not place contractors or partner-firm staff on an engagement without your prior written approval, and if you approve one they are named in the statement of work under the same background-check and device policies. Cloud providers and SaaS tools we use to deliver — source control, CI, observability — are disclosed as sub-processors in the data processing agreement, with 30 days' notice before any addition.

Do your engineers use AI coding tools on our code, and how is that governed?

Yes, under enterprise agreements with zero data retention and no training on submitted content; we can name the vendors and share the terms during diligence. Generated code is reviewed by a human before merge and passes the same tests, SAST and licence scanning as anything hand-written — the author of the pull request owns it regardless of how it was produced. If your policy prohibits AI assistance, we disable it at organisation level for your repositories and can evidence that configuration. Where we build AI features for you, model choice, prompt versions, evaluation sets and refusal behaviour all live in your repository and are open to review.

Start a project

Tell us what is
breaking.

We reply within one working day, and the first call is with an engineer who would actually work on it — not an account manager. If we are not the right studio for the problem, we will say so on that call.

Start a project