Cloud & APIs
Stays up. Stays fast. Stays yours.
Backend systems, APIs and cloud infrastructure — built so things keep running, and documented so they can be handed to someone else. Including away from us.
What we build
The machinery underneath
REST and GraphQL APIs
Database design and migrations
Authentication and access control
Third-party API integration
Hosting and deployment pipelines
Monitoring, backups and recovery — tested, not assumed
Industries
Who we build these for
The plumbing looks much the same in every industry — that's rather the point.
Our approach
Design for the day it breaks
The most important things about a backend are the ones you meet after launch: who finds out when something fails, where the credentials live, and what the recovery plan actually is. We design for the day something breaks, not just the day it ships.
That's why everything lands in accounts you own, with documentation someone else could follow. If we vanished tomorrow, your systems shouldn't notice.
The other half of the job is headroom. A busy Saturday, a mention that sends ten times the usual traffic, or a year of steady growth should be something the system absorbs — not an outage you find out about from a customer.
How we build
Understand first, build second
Map what exists
What runs where, who holds which key, and what's backed up versus what only looks backed up.
Scope and price
A written scope and a fixed price, agreed before anything is built.
Build in stages
Live pieces early, behind monitoring — never one big cutover weekend.
Test and hand over
Recovery rehearsed, runbook written, every account in your name.
We use AI to move faster. We review everything it writes, and we test for the vulnerabilities it introduces.
See the full processHow we'd approach it
A worked example
No infrastructure case study to show yet — so here's the thinking, in the open.
A business's site goes down on a Saturday. Nobody knows who hosts it, the developer who set it up moved on years ago, and the one person with a login is on a plane. It comes back on its own hours later — and nobody knows why that happened, either.
We'd start with an audit: where everything runs, who holds which key, what's backed up and what only looks backed up. Then we'd move the pieces into accounts the business owns, with monitoring that alerts a human before customers notice anything.
The finish line is a one-page runbook: what runs where, what to do when each piece breaks, and who to call. Boring on purpose — the goal is that the next Saturday outage is a non-event with a named owner.
A worked example, not a case study — this outage isn't a client's. It's the situation we build to prevent.
Why Latchford
Four promises, in writing
Fixed price, agreed before we start
Written scope, so you know what you're getting
You own everything — code, domain, and accounts
We're here after launch, not just until it ships
Tell us what you're trying to get done.We'll tell you what it takes.
