Modernize legacy systems without stopping operations.

We work where software cannot be rebuilt but has to be changed while it keeps running: in regulated environments with evidence obligations, grown interfaces, and real downtime costs.

Legacy replacement•Database migration•Verifiable operations•Sovereign AI

Most projects don't fail on code. They fail on what already exists.

A system that nobody fully understands anymore, interfaces that have been running for years, and the question of who takes responsibility when something stops: this is where our work begins. We take on clearly scoped projects as fixed-scope contracts with defined deliverables and acceptance criteria, with our own liability, our own team, and our own responsibility for the result.

Read about Fürstwerk →
Fixed-scope contracts•Fixed price•Own liability

Focused on the systems that carry your business

A narrow focus is what enables us to take responsibility for the result.

Existing systems first

We work on systems that already carry the business and have to keep running while they change.

Defined results

Clearly scoped packages with defined deliverables and acceptance criteria, delivered by our own team.

Verifiable, not just configured

What we set up is documented and tested to a standard that withstands an audit.

Interfaces as part of the whole

Portals, apps, and interfaces have their place in a modernization project when the core system behind them needs them.

Whether your project fits this scope is something we are happy to clarify in a first conversation.

What you can hold us to

Verifiable facts about the company, the contract model, and our experience.

  • Fixed-scope contracts with defined deliverables and acceptance criteria.
  • Business and professional liability insurance with documented coverage.
  • Experience in environments with elevated security requirements.
  • Projects since 2016 in insurance, rail, banking, medical technology, and public administration.

About Fürstwerk

Modernization and operation of critical systems in regulated environments

We define our work by the class of problem and the type of client, not by technology. Technologies change; the systems that carry a business, and the obligations attached to them, stay. Our clients run core systems in insurance, industry, medical technology, and public administration, where a change has to be proven, accepted, and kept running.

One question decides what we take on: does the system already carry the business, and does someone have to assume liability for the change? That is the environment we specialize in. The people behind the company have been working in such environments since 2016.

  • Work on grown systems under operational risk.
  • Evidence, acceptance, and certification capability.
  • Integration into grown landscapes: ERP, host, on-premises.
  • Operability: high availability, failover, proven recoverability.
  • Regulatory knowledge: what an auditor accepts.
Discuss your project with us →

How we step in

  1. 1

    Assess what exists

    Start with the existing system, its interfaces, and its obligations. The assessment always includes one implemented measure, never just a report.

  2. 2

    Define the cut and the sequence

    Target architecture with the cut line and the order of replacement, as a fixed-price package with its own acceptance.

  3. 3

    Deliver in packages, with a fallback

    Implementation in packages of 4 to 12 weeks, each with its own acceptance and a fallback level, while operations continue.

Insurance Industry Medical technology Public administration

Services

Four clearly delineated services. Each one is delivered as a fixed-scope package with defined deliverables and acceptance criteria.

Legacy replacement without interrupting operations

The problem

A core system carries the daily business but can no longer be maintained. The developers who built it are no longer available. A replacement in a single step is out of the question because operations must not stop.

What we deliver

  • Target architecture with cut line and order of replacement
  • Step-by-step migration with a fallback level for each step
  • Individual services as separately accepted work packages
  • Documentation and handover to your team

Typical scope

Target architecture as its own fixed-price package (3 to 6 weeks), then implementation in packages of 4 to 12 weeks, each with its own acceptance.

Typical signal

Every change to the core system requires several rounds of alignment, and nobody wants to sign it off.

Database and persistence migration

The problem

License costs, end of support, or sovereignty requirements force a change of database system. The data is business-critical, the dependencies have grown over years, and a mistake only shows months later.

What we deliver

  • Dependency analysis and assessment of the target system
  • Migration concept with validation and abort criteria
  • Execution including data validation and logging
  • Operational handover with a documented target state

Typical scope

Analysis and concept as a fixed-price package, execution as a second package accepted against defined validation criteria.

Typical signal

You know the migration is due, but nobody wants to own the risk.

Operability and evidence obligations

The problem

Regulatory requirements demand more than technology. They demand evidence: that backups can be restored, that outages are absorbed, that access is traceable. When it matters, what counts is not what is set up but what can be proven.

What we deliver

  • High-availability and operating concepts
  • Executed and logged failover and recovery tests
  • Backup, logging, and reporting chains with audit-ready documentation
  • Operations manuals that withstand an audit

Relevant obligations

NIS2 and supply-chain requirements, DORA in finance, BSI IT-Grundschutz in public administration, IEC 62304 and MDR in medical technology.

Typical scope

Assessment with one implemented immediate measure as the entry package. Never a pure report.

Typical signal

A key customer or auditor demands evidence, and you don't know who produces it.

Sovereign AI infrastructure

The problem

AI capabilities are wanted, but the data must not leave the organization: because of professional secrecy, classified information, patient data, or contract clauses.

What we deliver

  • Operation of open models in your own data center or with European providers
  • Retrieval on your own document holdings with permission checks
  • Traceability: logging of requests, sources, and results
  • Integration into existing systems instead of an isolated solution

Typical scope

A clearly scoped initial setup with a measurable use case, then expansion.

Typical signal

The obvious cloud service is off-limits for legal reasons.

A clear path from assessment to acceptance

Every package has a defined scope, defined deliverables, and acceptance criteria agreed before work starts.

  1. 1

    Assessment

    Record the existing system, its interfaces, and its obligations. Always with one implemented measure, never just a report.

  2. 2

    Target architecture

    Cut line, order of replacement, validation and abort criteria, as a fixed-price package.

  3. 3

    Work packages

    Implementation in packages of 4 to 12 weeks with a fallback level for each step. Operations keep running.

  4. 4

    Acceptance

    Each package is accepted against the criteria agreed up front. We owe the result, not the hours.

  5. 5

    Handover

    Documentation, operations manual, and transfer to your team, so that operation does not depend on us.

Built for environments where evidence counts

When it matters, what counts is not what is set up but what can be proven. We know the standards auditors apply to evidence.

Verifiable Documented Accepted

Regulatory context

NIS2 and supply chain

Evidence that suppliers of critical operators have to deliver: incident reporting, access control, recoverability.

DORA in finance

Operational resilience for insurers and banks: tested failover, documented recovery, traceable third-party risk.

BSI IT-Grundschutz

Public administration: operating concepts and documentation aligned with the BSI building blocks and with procurement requirements.

IEC 62304 and MDR

Medical technology: software lifecycle evidence, classification, and interfaces such as DICOM, HL7, and FHIR.

Data sovereignty

Professional secrecy, classified information, patient data: processing that stays in-house or with European providers.

GDPR and audit trails

Logging of access, requests, and results so that processing can be reconstructed.

How we cut an engagement

Clearly scoped packages, each with a value of its own, even if the larger project is not commissioned.

How you know you need us

  1. Every change to the core system requires several rounds of alignment

    Nobody is willing to sign it off. The system carries the business, but nobody fully knows it anymore.

    Legacy replacementOperations continue
  2. You know the migration is due

    Nobody is willing to own the risk. License costs, end of support, or sovereignty requirements are forcing the change.

    Database migrationValidated
  3. A key customer or auditor demands evidence

    You don't know who produces it. Backups, failover, access: what is set up is not the same as what can be proven.

    Verifiable operationsAudit-ready
  4. The obvious cloud service is off-limits for legal reasons

    The data must not leave the organization, yet the AI capability is still needed.

    Sovereign AIOn-premises

If you recognize one of these situations, a first conversation is the right next step.

Which package fits your project is something we define together.

Selected project references

A selection of project contexts in which we have delivered modernization, migration, integration, analytics, and AI-related work. For reasons of confidentiality, each project is described by industry and scope rather than by client name.

Insurance Group

Service Platform Modernization

Delivered UI/UX optimized frontend, backend proxy, and architecture work for modernization of the operative insurance service and customer contract management platform.

Angular Java Spring DB2 OpenShift On-Prem
AI Solutions Provider

Event-Driven AI Assistant Framework

Designed a distributed and scalable AI platform framework built from containerized microservices, event-driven agents, secure RAG retrieval, and connectors to business systems, documents, mail, and telephony for context-aware automation.

Kafka AsyncAPI Python Rust C++ TypeScript Node.js NestJS Angular Kubernetes AWS
National Rail Operator

Transportation Analytics Platform

Built and extended analytics-heavy delivery structures for operational reporting, data-stream handling, cloud deployment, and performance-oriented service design.

Angular Python Quart Microsoft SQL Azure NiFi
National Rail Operator

Financial Analytics Redesign

Restructured an analytics environment around financial simulation data, cloud infrastructure, DWH reporting, and clearer delivery foundations for business-critical evaluation workflows.

Angular Python Flask MariaDB MS SQL Azure
Insurance Group

AI Voicebot Introduction

Delivered frontend, backend, and architecture work for service workflows, including telephony integration and authentication flows.

Angular Java Spring DB2 OpenShift Cognigy On-Prem
Agricultural Machinery Manufacturer

ERP Module Migration

Supported a complex ERP modernization with module consolidation, migration planning, interface adaptation, quality assurance, and process-oriented architecture work around the target system.

PSIpenta/ERP Groovy Java Oracle DB On-Prem
IT Consulting Group

Banking Data Platform

Focused on scalable data architecture, resilient backend services, and performance improvements for document-heavy processing and high-volume database workloads.

React Java Spring MongoDB REST
Telecommunications Equipment Manufacturer

Data Integration & Mobile Tools

Combined data-intensive backend work with web and mobile delivery, integration pipelines, and analytics-oriented architecture across distributed platform components.

Angular Node.js MongoDB Flutter iOS Android AWS
Renewable Energy Provider

Workflow Digitalization Suite

Built workflow and tracking solutions for internal operations, with a strong focus on process digitalization, distributed data handling, and secure enterprise integration.

Angular Node.js NestJS PostgreSQL GraphQL AWS

Frequently asked questions

Straight answers about scope, liability, pricing, and the way we work.

Do you work on a time-and-materials basis or at a fixed price? +

We work at a fixed price. Each package has a defined scope, defined deliverables, and acceptance criteria. Additional work outside the agreed scope is commissioned separately.

Who is liable for the result? +

We are liable for the result. A fixed-scope contract means we owe the result, not the working time. Acceptance takes place against criteria agreed in advance.

How large is your team? +

The team is deliberately small and specialized. Larger packages are delivered with dedicated developers under our own lead, usually with one point of contact on our side.

Do you also build portals, apps, or web interfaces? +

Yes, as part of a larger modernization project. When a core system needs a portal, a mobile client, or a new interface, we deliver it within the same package and against the same acceptance criteria. Our focus stays on the system behind it.

Can you assess a project before we invest? +

Yes, though not as a pure study. The assessment always includes one implemented measure that has value even if the larger project is not commissioned.

Which regulatory requirements are you familiar with? +

With the requirements that regulated industries place on operations and evidence: NIS2 and supply-chain requirements, DORA in finance, BSI IT-Grundschutz, IEC 62304 and MDR in medical technology, and the procurement and audit procedures that come with them. We have been working in environments with elevated security requirements since 2016.

We are happy to answer further questions in a first conversation in which we assess your situation together.