Services
Pragmatic engineering with direct accountability, operational reliability and client control. I remain responsible for the agreed scope and coordinate the contributions it needs: data, applications and their integration, Azure and Google Cloud, servers and hosting, and artificial intelligence. Connected services, with named boundaries and contributors.
Data
Databases, pipelines, models and warehouses, then the dashboards built on them. Every figure keeps its definition, its owner and its source, on PostgreSQL, SQL Server, BigQuery or Snowflake for instance, sized to the need.
Needs I take on
Monthly reporting produced by the platform, absorbing source changes without a rebuild by hand
One definition per figure, so every department quotes the same number in the same meeting
A warehouse sized to the real volume, with a documented model, versioned transformations and orchestration that reports its own failures
Years of data comparable with each other, kept in one place under the same definitions, ready for analysis or forecasting
A forecast of demand, consumption or failure tested against the simple method in place before any decision rests on it
Dashboards in the BI tool already in place, fed by reviewed transformations rather than pasted exports
What I put in place
- Connectors to existing systems, a source register, shared definitions, quality checks and a central database where it is useful
- A documented data model and a warehouse sized to the need: PostgreSQL or SQL Server on a modest server, BigQuery, Snowflake or a Databricks-class platform when volume and operations justify it
- Transformations versioned and reviewed like code, with dbt for instance, and sober orchestration, Airflow or Azure Data Factory for instance, that replays expected failures and reports the ones needing a decision
- Dashboards in your BI tool (Power BI, Tableau, Looker, Metabase or any other) or custom-built, with every indicator's definition one click away
- A data governance register covering uses, purposes, data classes, connected systems, providers, subprocessors, locations, retention, owners and review dates
- Operating the platform: pipeline monitoring, updates, tested restores and a monthly report, within a written scope
Relevant experience
Data-pipeline architecture on Google Cloud for an international index and financial-data provider
Airflow · dbt · BigQuery · Terraform
Azure data pipelines for a European solar-energy group
Data Factory · Graph API · Business Central
Bioinformatics data pipelines for a genomics research institute
Python · Linux
Salesforce-Tableau connectors for a Lausanne-based media foundation
JavaScript · SQL
Data-workflow automation for an internationally renowned classical-music festival
Power BI · Python
Data-access tooling for a Swiss energy producer
Python · R · API
Solutions and applications
Applications and integration
Web, mobile and desktop applications, business tools, APIs and automation: the software missing between your software, written in whatever language the need dictates, tested, connected to what exists and delivered with its documentation.
Needs I take on
The rule that runs the business moved out of the shared workbook, into an application with permissions, tests and history
The ERP, accounts, CRM and website connected by monitored integrations, with no retyping between them
An invoicing chain that follows the banking formats version after version, tested before each published date
A portal that serves clients the information the system already holds, with permissions, validation and logging
Field data captured once, on site, then carried through to quote, order and invoice by the system
A documented, versioned and monitored API in front of your data, for a partner, a portal or a mobile app, with per-client rights and a log
Internal tools with an owner, tests and a production procedure, taken over and brought back to deliverable state
What I put in place
- Web, mobile (native Android, for instance) and desktop applications with acceptance criteria, accessibility and security testing, a deployment procedure and rollback
- APIs and integrations: documented interface contracts, versions, per-client rights, logs, retries and a named owner, between the ERP, the accounts, the CRM, the banks and the web
- Automation and scripting: scheduled jobs with logs, alerts, recovery and a named owner, rather than a macro on somebody's machine
- Secure application delivery: scoped threats and trust boundaries, reviewed identity, secrets and dependencies, security acceptance cases, deployment evidence and a remediation register, without presenting this as penetration testing
- Taking over an existing tool: dependencies, build access, documentation, tests, repair and handover to your team
- Explicit delivery: code, documentation, access, third-party components, licences and usage or assignment rights defined in the contract
Relevant experience
An AI-agent environment for software development (scope review, testing, code memory), built and in daily use
Copilot · Claude Code · MCP
Salesforce-Tableau connectors for a Lausanne-based media foundation
JavaScript · SQL
Data-workflow automation for an internationally renowned classical-music festival
Power BI · Python
Data-access tooling for a Swiss energy producer
Python · R · API
Azure and Google Cloud
Architecture, migration and operations on Azure and Google Cloud, or with a Swiss host when the file calls for it. The infrastructure is described in code, every cost has an owner and every cutover has a tested rollback.
Needs I take on
Every line of the cloud bill attributed to a service and an owner, with each change measured against performance and risk
Hosting selected for a written reason, jurisdiction, cost, support, latency or exit, and migrated with evidence
Azure or Google Cloud infrastructure described in reviewed code, with Terraform for instance, that the team can rebuild and where every change keeps its author and reason
A test environment aligned with production, so a change rehearses before it commits
Migrations run with cutover, rollback and restore written and rehearsed before the first wave moves
A data or AI platform deployed into a clean landing zone: subscriptions, networks, identities and budgets separated per environment, with logs and alerts in place from day one
What I put in place
- A decision matrix covering operator, contract, regions, support access, subprocessors, keys, cost, portability and closure of the old environment
- A landing zone on Azure or Google Cloud: subscription or project layout, identities, networks, logs, budgets and alerts, described in code and reviewed before application
- Migration through a trial and waves, with reconciliation, cutover, rollback, restore and available closure evidence
- Versioned infrastructure: the automatable part described with Terraform or an equivalent tool, change history, drift detection and a tested rebuild
- Cost attribution: every resource tied to a service and an owner, savings measured after each change, the previous setting ready to restore
- Service-based resilience: separated copies and, according to risk, offline or immutable copies, recovery objectives and planned tests
Relevant experience
Data-pipeline architecture on Google Cloud for an international index and financial-data provider
Airflow · dbt · BigQuery · Terraform
Azure data pipelines for a European solar-energy group
Data Factory · Graph API · Business Central
Bioinformatics data pipelines for a genomics research institute
Python · Linux
Solutions and applications
Servers and hosting
Active Directory, Exchange, Microsoft 365, Google Workspace, kSuite, private or dedicated servers: I build them, integrate them with identity and backups, then operate them with role-based access, tested restores and a monthly report.
Needs I take on
A server the business has never run, a directory, a mail server, an ERP or a database, built from scratch and integrated, not bolted on
Permissions rebuilt on roles and groups: every access carries its explanation and the review fits on one page
A Microsoft 365, Google Workspace or kSuite tenant with separated admin roles, reviewed external sharing, justified licences and a protected mail domain
The servers carrying production mapped with their dependencies and moved to supported ground before the deadline forces it
Staying and leaving costed like for like over the same period, so the virtualisation renewal is a decision, not a reflex
A full restore, identity, servers, keys and application, timed and validated, not assumed from green backup jobs
Every alert with a threshold, a recipient, a handling time and an escalation, defined and tested
Ownership of access, contracts, backups and deadlines back in your hands, with a workable exit whatever the provider does
The warehouse, the pipelines and the integrations operated: monitoring, updates and restores owned
Private servers, storage and remote access redesigned as one architecture, with an owner and a plan instead of accumulated additions
What I put in place
- Server build and integration: Active Directory, Entra ID, Exchange, SQL Server, Business Central or any other server, installed, hardened, documented and integrated with identity and backups
- Group and role architecture: every permission belongs to a role, people inherit through their groups, direct assignments are removed and the review fits on one page
- Microsoft 365, Google Workspace and kSuite tenants: design, migration, separated admin roles, external sharing, mail-domain protection and justified licences
- Private or dedicated servers and hosting: virtualisation, file sharing, identity-based remote access and off-site backup, on your premises, with a Swiss host or in a Swiss cloud region
- Backup and recovery: separated credentials, an isolated or immutable copy, a restore performed in front of you and timed, recovery objectives decided per service
- Operations within a written scope: maintenance windows, signal-by-signal monitoring, patching, capacity, a monthly report and continuity cover, Monday to Friday during agreed hours
Relevant experience
Systems and storage engineering at a global storage-solutions vendor
FC · iSCSI · NAS/SAN
Bioinformatics data pipelines for a genomics research institute
Python · Linux
Artificial intelligence
Assistants that cite your documents, agents that run a bounded task, document extraction, and the infrastructure serving them: an open model on your machines, Swiss hosting or a cloud provider's API, chosen after reviewing the data and the contract.
Needs I take on
The document archive searchable by meaning rather than by the exact file name
An internal assistant governed from day one: rules by data type, approved tools and answers that cite their source
PDFs, emails and scans read by extraction pipelines, with the data checked before it is written into the systems
AI taken from demonstration to production: evaluated, integrated, monitored and owned
An open model served on your machines or with a Swiss host, sized in memory and context for your documents, with latency and cost per request measured
A cloud provider's AI APIs integrated behind a gateway that logs, caps spend and applies the rules per data type
Every AI subscription inventoried: the data it reaches, the systems it touches, the settings it runs with, all owned
What I put in place
- Internal assistants and RAG: answers accompanied by source passages, a confidence signal and a human verification path
- AI automation: document or code review, testing, data extraction from your feeds whatever the format (emails, XML, PDF), with versioned prompts, guardrails and human oversight
- Agents that carry a bounded task through several steps, with an action log, planned stops and approval before any sensitive decision
- AI infrastructure: an open model served on your servers or on Swiss hosting, memory and context sizing, or a gateway to a cloud provider's APIs, with location, access, retention and training use documented
- A versioned knowledge base: reviewed content, metadata, permissions, search and a link graph, prepared and evaluated before use by an AI assistant
- An AI-use register and policy: purposes, data classes, connected systems, providers, evaluations, owners and review dates, with hands-on workshops on your own cases
Relevant experience
AI extraction of data from financial announcements, in production at an international index provider
Vertex AI · BigQuery · prompts versionnés
An AI-agent environment for software development (scope review, testing, code memory), built and in daily use
Copilot · Claude Code · MCP
Security as a property of every line
I don’t sell security as a line of its own. The access rights of a data platform, the tested restores of a server, the separated roles of a tenant and infrastructure described in reviewed code are part of the work delivered, within each line’s scope. Workstations, the network, awareness training and incident response belong to other providers, and I say so before starting.
My share of the work, and yours
Six subjects where responsibility usually goes missing between two providers: the restore, the leavers, the alerts, the tenant, the incident and the insurer’s questionnaire. For each one, my share, yours, a named third party’s share, and the evidence you are left holding.
Backup and restore
Who restores, and how long does it take?
- My share
- I size the copies, local, off-site and immutable, write the restore procedure and run it for real, stopwatch in hand.
- Your share
- You decide which services come back first and how much data you accept losing. Those two figures drive everything else, the bill included.
- A named third party’s share
- When your business-software vendor hosts the database itself, its restore depends on that contract: I test it with them, or I write down that it wasn’t tested.
The evidence you keepA dated restore report: what came back, how long it took, and what was missing.
The places involved
Joiners, movers and leavers
Someone leaves on Friday. What is still open on Monday?
- My share
- I map the access that actually exists, directory, business applications, remote access, shared accounts and providers, then write the procedure for all three moments and what happens to the break-glass account.
- Your share
- Only you can say who is entitled to what. I carry it out and record it; I don’t settle an access request on your behalf.
- A named third party’s share
- An application administered by its vendor can only be revoked there. It’s named in the procedure rather than assumed to be covered.
The evidence you keepA current access matrix, and one revocation carried out in front of you rather than promised.
The places involved
Monitoring and alerts
Who gets the alert at three in the morning, and what do they do with it?
- My share
- I decide what deserves to wake somebody, set the threshold, the recipient and the response time, and send everything else to the log rather than to a phone.
- Your share
- You set the covered hours and who is reachable. An alert with nobody at the other end is noise a team learns to ignore.
- A named third party’s share
- I don’t run a 24/7 watch. If your operations need one, it’s contracted elsewhere and I connect the monitoring to it.
The evidence you keepAn alert list where every line carries a recipient, a response time and a hand-off, tested with a real send.
The places involved
Microsoft 365 and the workspace
Where are our documents, and who can read them?
- My share
- I establish the state of the tenant: the domains, the licences actually used, the open external shares, the connected applications and the logs you have. Then the contractual state that goes with it: operator, regions and subprocessors.
- Your share
- Purpose, data categories and external sharing stay your decisions. I show you what is open; you say what should stay open.
- A named third party’s share
- Microsoft remains the operator. A Swiss region changes neither the provider’s jurisdiction nor its administrative access, and a migration won’t either.
The evidence you keepA dated tenant statement, and the gaps between what is configured and what you believed was configured.
The places involved
Incidents: preparation, not a hotline
Something happens tonight. What do you do?
- My share
- Before: the plan fits on two pages, the roles and the numbers are written down, the rehearsal has happened at least once. During: I bring the logs, the technical access and whatever the contract provides for.
- Your share
- You lead the crisis and decide on notifications with your adviser. Those decisions aren’t delegated to a technical provider, and nobody serious will offer to take them for you.
- A named third party’s share
- Emergency response, forensics and criminal complaints belong to an appointed provider and the authorities, with the report to the NCSC.
The evidence you keepA short plan, the date of the last rehearsal, and the list of what that rehearsal broke.
The places involved
The insurer’s questionnaire
Twelve pages of technical questions, to be signed. On what basis?
- My share
- I answer the technical part and cite the source of each answer: a configuration, a log, a dated test. Anything unverified is marked as such rather than rounded up.
- Your share
- You sign: these are your representations, not mine. An optimistic answer becomes a breached undertaking on the day of a claim.
- A named third party’s share
- The insurer or auditor decides on acceptance, and a legal question goes to qualified counsel. I issue neither certification nor independent audit.
The evidence you keepA pack where every answer points at evidence that already exists. It falls out of the work done; it isn’t manufactured for the questionnaire.
The places involved
The first assignment
No engagement here starts from a catalogue: it starts from your situation. The first assignment that follows is short, two to six weeks depending on scope, with the price fixed up front; its result is handed over under the agreed rights and formats, whatever comes next.
Depending on the context, these first assignments have included:
- Reporting rebuilt on reliable pipelines, replacing scattered spreadsheets
- Automated data extraction from incoming documents, put into production
- A CRM connected to dashboards that management actually reads
Principles
Your data, your choice
The decision records purpose, operator, contracts, locations, access, subprocessors, transfers, retention and exit. Public cloud, a Swiss provider and your own premises are architecture options, not automatic legal conclusions.
Right-sizing
Tools scaled to your organisation. A 50 GB problem doesn’t justify a platform built for 50 TB.
Reversibility
Documentation, access, exports, standards and a handover rehearsal are defined within scope. Any remaining contractual, licensing or provider lead-time dependencies stay explicit.
Nothing resold
No hardware, no licences: no recommendation earns me a commission, which makes the advice checkable rather than merely credible.
Plain language
Decisions are discussed in plain language, not in tech jargon.
The assessment is agreed with you: its scope, its length and its price, before it starts.Projects are quoted from the roadmap, ongoing support on a monthly retainer.
Direct questions, direct answers
Who actually works on my file?
I remain your point of contact and the engineer accountable for the agreed scope. If a specialist, provider or subcontractor is needed, their role, data access and operating framework are named and approved before they intervene.
Who takes over if you are ill or away?
Priority access, dependencies and procedures are documented. The contract states hours, escalation, exclusions and what is genuinely arranged for an absence; backup cover is promised only when a named person has rehearsed it.
How do I get my data back if we stop?
Your rights, export formats, access, return, revocation and available evidence are defined from the start. The handover is rehearsed, while limits imposed by a vendor, contract or licence remain visible.
Do you resell hardware or licences?
No, nothing, ever. No recommendation earns me a commission: when I suggest a tool, it serves your situation, not my margin.
Who owns the code that gets developed?
The contract distinguishes purpose-built code, reusable pre-existing components and third-party dependencies. It specifies assignment or licensing of economic rights, source, documentation, build access and maintenance obligations.
Where is the data hosted?
Through a documented decision covering purpose, operator, contracts, locations, support access, subprocessors, transfers, retention, export and exit. Location matters, but it doesn’t answer the legal or risk question by itself.
How do you bill?
The assessment at a firm price, projects with scope and price fixed up front, ongoing support as a monthly retainer. No end-of-month surprises: what wasn’t agreed isn’t invoiced.
A first conversation, no commitment
A few lines about your project or your question are enough: I reply directly, usually within one working day.
Get in touch