Skip to Content

How we build — the technical page

We build with AI. That is precisely why we built the factory around it.

This page is more technical than the rest of the site. That is deliberate: this is where the only question that matters gets settled when you hand your pricing rules to someone. Will it hold?

We may as well put them on the table

Code written by an AI is risky. Here are the numbers.

45%

of generated code contains an OWASP top 10 flaw, with no improvement on newer models

Veracode · July 2025

2.74×

more security issues at most, across 470 real pull requests

CodeRabbit · December 2025

+322%

rise in privilege escalation paths on enterprise repositories

Apiiro · Dec. 2024 – June 2025

+153%

rise in design flaws on the same repositories

Apiiro · Dec. 2024 – June 2025

DORA, in 2025, observes that AI increases delivery throughput while remaining negatively correlated with stability. Figures current as of 2 September 2026.

The conclusion: the danger does not come from the tool, it comes from the absence of a system around it. That system is what we built first, before the first client.

Eight gates, seven blocking

No line of code reaches production without clearing the gates

Every change goes through a series of automated checks, and each one of them can block the release.

01BLOCKING

Before push

No password, no key in the code

02BLOCKING

Static analysis

Known security flaws in the code written

03BLOCKING

Dependencies

Vulnerable libraries, pinned versions

04BLOCKING

Infrastructure

Containers and server configuration

05BLOCKING

Tests

Minimum coverage, and reinforced tests on price calculation and the rules engine

06BLOCKING

Signing

Traceability of what is deployed

07WARNING

Penetration test

On a disposable environment, before production

08BLOCKING

Human review

A person reads it and approves. Always.

And one operating rule: the coding assistant never has access to your real data or to production passwords. It works on an isolated environment.

One stack per client

Your installation belongs to you alone

Most platforms keep all their customers in the same database, separated by a rule in software. That works, right up to the badly written query.

We do it differently: your database, your application containers and your code repository are separate from everyone else's. What that means concretely:

An urgent fix at your site does not ship to the other nineteen. You are not waiting for a shared maintenance window.

A leak from one customer to another is impossible by construction, not by discipline.

You migrate at your own pace. Nobody forces an update on you because another customer needs it.

Leaving is clean. You go, we hand you a full copy of your database. No surgical extraction, no negotiation.

Backups are automatic, geo-redundant, and restores are tested periodically. A backup that has never been restored is not a backup.

The foundation

We do not reinvent, and we do not generalise too early

The pricing engine, cost price calculation, bill of materials generation, the quote lifecycle: these are components we wrote once, improve continuously, and that each project picks up in its chosen version. You do not pay for work already done elsewhere.

In the other direction, we forbid ourselves from generalising too fast. A need becomes a shared component only at its third occurrence, never at the first. An abstraction built for a single customer complicates life for all the others.

What stays unique to you is what has to be: your rules, your rates, your shop-floor constraints, your proposal templates.

Engrenages imbriqués, un mécanisme en mouvement

No proprietary licence in the stack

The database, the language, the rules engine, the authentication server, the tooling: all of it is open, and open in the sense that you can keep it, change it and have someone else pick it up. There is nobody above you who can change the terms or triple the price of a licence.

You are not a tenant in your own configurator.

Where your data lives

Hosted in Quebec, and not just for show

Your data is hosted in Beauharnois, with a provider of French origin, running on Quebec hydroelectricity.

The distinction that matters: hosting in Canada is not the same thing as being out of reach of American law. A Canadian region of an American provider gives you data residency, not sovereignty, because the CLOUD Act follows the provider's country of incorporation and not the location of the server. No American provider can contract that exposure away.

Law 25 does not require keeping data in Canada. It requires an assessment before any transfer outside Quebec, including an examination of the legal framework of the receiving country. We simplify that assessment for you by having nothing to transfer.

The limits, up front

What we do not promise

We have no formal compliance certification today. No SOC 2, no ISO 27001. The technical practices are in place, the audit process is not. The day one of your contracts requires it, we open the file and tell you plainly, with the cost and the timeline.

We do not promise a timeline before seeing your rules. A quoting configurator is a project whose size depends entirely on the number of product families, the density of the rules and the state of your ERP. Anyone who gives you a price before looking has not looked.

We do not promise a quantified result. You will not find "+30% win rate" anywhere on this site. We do not have the data to claim it, and nobody really has it for your sector.

You have technical questions? Good.

Send them over. If your IT director wants the long version, we give it to them.