Insights · Cloud & security
Cloud and security guides for internal applications
Security for an internal application starts with who can sign in, what each role can reach, and where the data and logs live. These guides cover AWS foundations, single sign-on and least privilege, security testing before launch, staff and customer mobile apps, plant network boundaries and the controls AI workflows need.
Browse by topic
Guides are drafted with AI assistance; facts checked against any sources a guide cites. General guidance, not advice for your situation; verify before relying on them.
Guides
9 guides on cloud & security.
Mobile · Internal apps
A mobile app for your staff: PWA, native or cross-platform, personal phones and distribution
How to plan a mobile app for employees at a mid-sized company: choosing between a progressive web app, native iOS and Android and React Native; company-owned devices vs. personal phones, MDM and app protection; sign-in and data on the device; and private vs. app store distribution.
8 min read
Mobile · App stores
Publishing a customer-facing company app on the App Store and Google Play: accounts, review and ownership
What IT leaders at a mid-sized company need to settle before a customer-facing app goes into the App Store and Google Play: developer accounts enrolled in the company's name with a D-U-N-S number, roles instead of shared passwords, signing keys the company controls, privacy disclosures and account deletion, the review guidelines that trip up company apps, staged releases, and the yearly platform updates someone has to own.
11 min read
AI integration · Workflows
Adding AI to document and email workflows safely
A practical guide to using AI for classifying, extracting and summarizing business documents and email: where it fits, human review, data handling, choosing between Claude, OpenAI, Gemini and Grok, and how to evaluate it.
7 min read
AI integration · Agents
Putting AI agents to work on internal processes, with guardrails
Where AI agents help inside a mid-sized company and how to run them safely: scoped tool permissions, human approval for actions, audit logs, spending limits and evaluation. Vendor-neutral across Claude, OpenAI, Gemini and Grok.
7 min read
AI integration · Human review
Designing human review and approval into AI workflows
How to design human review and approval into AI workflows so it catches real errors without becoming a rubber stamp: deciding what needs review, routing on signals you can trust, review screens, approval gates for actions, capturing corrections, and reducing review safely over time.
9 min read
Cloud · AWS foundations
AWS foundations for a mid-sized company's first custom apps
What to set up in AWS before the first custom app goes live: separate accounts, single sign-on, infrastructure as code with CDK, CloudFormation or Terraform, CI/CD with OIDC, environments, monitoring and cost guardrails.
7 min read
Security · Identity
Securing internal apps with single sign-on, Entra ID and least privilege
How to secure a custom internal app with single sign-on through Microsoft Entra ID, Okta or a similar identity provider: OIDC vs SAML, where roles should live, least-privilege authorization, API tokens and service accounts, shared plant-floor devices, and joiners, movers and leavers.
8 min read
Cloud & security · Testing
Security testing a custom web or mobile app before launch: automated checks, a pen test and evidence to keep
How IT leaders at a mid-sized company can get a custom web or mobile app through security review before launch: a short list of what the app protects and who could misuse it, automated checks in the deployment pipeline for dependencies, secrets, code and cloud settings, tests that prove each role sees only its own data, an independent penetration test scoped and timed so there is room to fix findings, and the evidence your security team and customers will ask for.
9 min read
Manufacturing · OT/IT
Getting plant data to IT systems safely across the OT/IT boundary
How to move plant data to business-side systems without opening a path into the control network: industrial DMZ patterns, one-way and read-only flows, where the collector sits, firewall rules worth approving, and who owns what between IT and controls.
10 min read
Have a project in mind? Put it on one page in eight short questions.
Need an internal app set up securely on AWS?
A 30-minute call. You leave with a clear approach and the real risks, whether or not you hire us.