---
title: "Software development with hard quality gates: the last 10% | Lightweb Media GmbH"
description: "Web, apps, and browser extensions that hold up in production, including whitebox pentest, DB load tests, AI endpoint evals, and reproducible CI/CD. So releases do not just go live, they pass."
canonical: "https://lightweb-media.de/en/software-development/"
source_url: "https://lightweb-media.de/en/software-development/"
---
Web · App · Extensions · Secure delivery

# We deliver the last 10% many MVPs never survive.

Fast demos are standard today. What breaks teams in production comes after: broken auth, leaking databases, AI endpoints without evals, releases without evidence. We build web apps, native apps, and browser extensions so every release is reliable.

[Book an intro call](/en/contact/) [AI & automation](/en/ai-solutions/)

4,7 ★ [Aus 398 Rezensionen auf Google](https://www.google.com/search?q=Lightweb+Media+GmbH+Bewertungen)

Stack & delivery

-   TypeScript
-   Node.js
-   Python
-   PHP
-   PostgreSQL
-   MySQL
-   Redis
-   n8n
-   CI/CD
-   MERN
-   Django
-   Next.js

Hosting & operations

-   Docker
-   AWS
-   Hetzner
-   Portkey
-   Huggingface
-   Ollama

### Web, app & extensions that reach production quality

From internal dashboards to public products: we choose the stack for your use case, not the trend. What your platform actually needs, not what is hyped right now.

### Clarity in days instead of corrections in months

Rapid prototyping paired with a crystal-clear product scope: before the first sprint, the MVP concept is fixed. Procurement, stakeholders, and the dev team start the first iteration in sync with maximum planning certainty.

### Hard quality gates before go-live

Every release follows the same verification path: security, database load, AI interfaces, and documented sign-off. Details are in the release gate section below.

### Reproducible deployments without gut feeling

Container images, manifests, and pipelines that make every release repeatable. If something goes wrong, your team knows first: detailed monitoring with Sentry, before it escalates in production.

Operations & delivery

## Hosting-ready, not hosting-obsessed

Classic hosting, Docker on Hetzner or AWS: we deliver the right set of manifests, runbooks, and CI/CD integration. Coolify, containers, and pipelines in focus; deep third-party infrastructure ops only in an advisory role.

### Start

From idea to clickable prototype in hours, with a clear product scope as supporting documentation so product, procurement, and stakeholders start in sync.

### Outcome

Releases with evidence and runbooks your team can operate after the project ends, regardless of who originally wrote the code.

Verification paths

-   ### Whitebox pentest
    
    Security testing on the running app before external audits begin.
    
-   ### DB load tests
    
    Load on the database paths that actually hurt in production, not just on demo data.
    
-   ### AI evals
    
    Measurable quality at AI interfaces instead of hoping for model behavior.
    

Delivery

-   ### Product scope
    
    Written boundaries before sprint 1 so budget does not flow into irreversible decisions.
    
-   ### CI/CD & artifacts
    
    Reproducible builds and signed releases from staging through production.
    
-   ### Runbooks & monitoring
    
    Operations documentation and alerts before users notice an outage.
    

Operations

-   ### Containers & manifests
    
    Docker, Coolify, or cloud: deployment-ready for your target platform.
    
-   ### Observability
    
    Make errors, latency, and regressions traceable, e.g. with Sentry.
    
-   ### Handover to your team
    
    Code, tests, and documentation so internal teams can keep building.
    

Release gate

## Every release follows the same path.

Unit and integration tests, whitebox pentest, DB load test, and AI evals: nothing goes live until every step is green. Promotion from staging to production is a documented path, not gut feeling.

Plan

Prototype

Build

CI / CD

Prod

RELEASE\_GATE · **Required**

FAQ

## Common questions about software development

Short and concrete, before you reach out.

Do you take on only the last 10% of a running project? +

Yes. We step in when MVPs wobble in production: auth, databases, AI interfaces, or deployment lack a reliable foundation. In an intro call we clarify whether repair, rebuild, or a targeted gate pass is the better path.

What sets you apart from a classic web agency? +

We deliver more than surface and features: verification paths with evidence, pentests, load tests, evals, and reproducible releases. The goal is software that holds up in production.

How fast do I get a response? +

We typically respond to project inquiries within 24 hours with an honest assessment of scope, risk, and next steps.

## From idea, AI prototype, or browser extension to a reliable product.

Send us where things stand. In an intro call we clarify scope, risk, and the sensible next step, for greenfield projects and stuck deliveries alike. For funding programs (Digital Jetzt, ZIM, Mittelstand-Innovativ Plus, INVEST, go-digital) we provide the technical substance that holds up in the grant decision.

![Portrait of Joel Burghardt](/images/team/joel-burghardt.png)

Joel Burghardt

Managing director

![Portrait of Sven Hoffmann](/images/team/sven-hoffmann.png)

Sven Hoffmann

Client advisor & senior developer

[Book an intro call→](/en/contact/)
