Existing systems first
We work on systems that already carry the business and have to keep running while they change.
We work where software cannot be rebuilt but has to be changed while it keeps running: in regulated environments with evidence obligations, grown interfaces, and real downtime costs.
A system that nobody fully understands anymore, interfaces that have been running for years, and the question of who takes responsibility when something stops: this is where our work begins. We take on clearly scoped projects as fixed-scope contracts with defined deliverables and acceptance criteria, with our own liability, our own team, and our own responsibility for the result.
Read about Fürstwerk →A narrow focus is what enables us to take responsibility for the result.
We work on systems that already carry the business and have to keep running while they change.
Clearly scoped packages with defined deliverables and acceptance criteria, delivered by our own team.
What we set up is documented and tested to a standard that withstands an audit.
Portals, apps, and interfaces have their place in a modernization project when the core system behind them needs them.
Whether your project fits this scope is something we are happy to clarify in a first conversation.
Verifiable facts about the company, the contract model, and our experience.
About Fürstwerk
We define our work by the class of problem and the type of client, not by technology. Technologies change; the systems that carry a business, and the obligations attached to them, stay. Our clients run core systems in insurance, industry, medical technology, and public administration, where a change has to be proven, accepted, and kept running.
One question decides what we take on: does the system already carry the business, and does someone have to assume liability for the change? That is the environment we specialize in. The people behind the company have been working in such environments since 2016.
How we step in
Assess what exists
Start with the existing system, its interfaces, and its obligations. The assessment always includes one implemented measure, never just a report.
Define the cut and the sequence
Target architecture with the cut line and the order of replacement, as a fixed-price package with its own acceptance.
Deliver in packages, with a fallback
Implementation in packages of 4 to 12 weeks, each with its own acceptance and a fallback level, while operations continue.
Four clearly delineated services. Each one is delivered as a fixed-scope package with defined deliverables and acceptance criteria.
Legacy replacement without interrupting operations
The problem
A core system carries the daily business but can no longer be maintained. The developers who built it are no longer available. A replacement in a single step is out of the question because operations must not stop.
What we deliver
Typical scope
Target architecture as its own fixed-price package (3 to 6 weeks), then implementation in packages of 4 to 12 weeks, each with its own acceptance.
Typical signal
Every change to the core system requires several rounds of alignment, and nobody wants to sign it off.
Database and persistence migration
The problem
License costs, end of support, or sovereignty requirements force a change of database system. The data is business-critical, the dependencies have grown over years, and a mistake only shows months later.
What we deliver
Typical scope
Analysis and concept as a fixed-price package, execution as a second package accepted against defined validation criteria.
Typical signal
You know the migration is due, but nobody wants to own the risk.
Operability and evidence obligations
The problem
Regulatory requirements demand more than technology. They demand evidence: that backups can be restored, that outages are absorbed, that access is traceable. When it matters, what counts is not what is set up but what can be proven.
What we deliver
Relevant obligations
NIS2 and supply-chain requirements, DORA in finance, BSI IT-Grundschutz in public administration, IEC 62304 and MDR in medical technology.
Typical scope
Assessment with one implemented immediate measure as the entry package. Never a pure report.
Typical signal
A key customer or auditor demands evidence, and you don't know who produces it.
Sovereign AI infrastructure
The problem
AI capabilities are wanted, but the data must not leave the organization: because of professional secrecy, classified information, patient data, or contract clauses.
What we deliver
Typical scope
A clearly scoped initial setup with a measurable use case, then expansion.
Typical signal
The obvious cloud service is off-limits for legal reasons.
Every package has a defined scope, defined deliverables, and acceptance criteria agreed before work starts.
Assessment
Record the existing system, its interfaces, and its obligations. Always with one implemented measure, never just a report.
Target architecture
Cut line, order of replacement, validation and abort criteria, as a fixed-price package.
Work packages
Implementation in packages of 4 to 12 weeks with a fallback level for each step. Operations keep running.
Acceptance
Each package is accepted against the criteria agreed up front. We owe the result, not the hours.
Handover
Documentation, operations manual, and transfer to your team, so that operation does not depend on us.
When it matters, what counts is not what is set up but what can be proven. We know the standards auditors apply to evidence.
Regulatory context
NIS2 and supply chain
Evidence that suppliers of critical operators have to deliver: incident reporting, access control, recoverability.
DORA in finance
Operational resilience for insurers and banks: tested failover, documented recovery, traceable third-party risk.
BSI IT-Grundschutz
Public administration: operating concepts and documentation aligned with the BSI building blocks and with procurement requirements.
IEC 62304 and MDR
Medical technology: software lifecycle evidence, classification, and interfaces such as DICOM, HL7, and FHIR.
Data sovereignty
Professional secrecy, classified information, patient data: processing that stays in-house or with European providers.
GDPR and audit trails
Logging of access, requests, and results so that processing can be reconstructed.
Clearly scoped packages, each with a value of its own, even if the larger project is not commissioned.
How you know you need us
Every change to the core system requires several rounds of alignment
Nobody is willing to sign it off. The system carries the business, but nobody fully knows it anymore.
You know the migration is due
Nobody is willing to own the risk. License costs, end of support, or sovereignty requirements are forcing the change.
A key customer or auditor demands evidence
You don't know who produces it. Backups, failover, access: what is set up is not the same as what can be proven.
The obvious cloud service is off-limits for legal reasons
The data must not leave the organization, yet the AI capability is still needed.
If you recognize one of these situations, a first conversation is the right next step.
Which package fits your project is something we define together.
A selection of project contexts in which we have delivered modernization, migration, integration, analytics, and AI-related work. For reasons of confidentiality, each project is described by industry and scope rather than by client name.
Delivered UI/UX optimized frontend, backend proxy, and architecture work for modernization of the operative insurance service and customer contract management platform.
Designed a distributed and scalable AI platform framework built from containerized microservices, event-driven agents, secure RAG retrieval, and connectors to business systems, documents, mail, and telephony for context-aware automation.
Built and extended analytics-heavy delivery structures for operational reporting, data-stream handling, cloud deployment, and performance-oriented service design.
Restructured an analytics environment around financial simulation data, cloud infrastructure, DWH reporting, and clearer delivery foundations for business-critical evaluation workflows.
Delivered frontend, backend, and architecture work for service workflows, including telephony integration and authentication flows.
Supported a complex ERP modernization with module consolidation, migration planning, interface adaptation, quality assurance, and process-oriented architecture work around the target system.
Focused on scalable data architecture, resilient backend services, and performance improvements for document-heavy processing and high-volume database workloads.
Combined data-intensive backend work with web and mobile delivery, integration pipelines, and analytics-oriented architecture across distributed platform components.
Built workflow and tracking solutions for internal operations, with a strong focus on process digitalization, distributed data handling, and secure enterprise integration.
Straight answers about scope, liability, pricing, and the way we work.
We work at a fixed price. Each package has a defined scope, defined deliverables, and acceptance criteria. Additional work outside the agreed scope is commissioned separately.
We are liable for the result. A fixed-scope contract means we owe the result, not the working time. Acceptance takes place against criteria agreed in advance.
The team is deliberately small and specialized. Larger packages are delivered with dedicated developers under our own lead, usually with one point of contact on our side.
Yes, as part of a larger modernization project. When a core system needs a portal, a mobile client, or a new interface, we deliver it within the same package and against the same acceptance criteria. Our focus stays on the system behind it.
Yes, though not as a pure study. The assessment always includes one implemented measure that has value even if the larger project is not commissioned.
With the requirements that regulated industries place on operations and evidence: NIS2 and supply-chain requirements, DORA in finance, BSI IT-Grundschutz, IEC 62304 and MDR in medical technology, and the procurement and audit procedures that come with them. We have been working in environments with elevated security requirements since 2016.
We are happy to answer further questions in a first conversation in which we assess your situation together.