
Product engineering, end to end
Web platforms, internal tooling and customer-facing apps designed for the specific way your business works — no template SaaS, no boilerplate.
SALT & FISH LIMITED engineers cloud platforms, secure applications and automation systems for organisations where downtime is not an option.

SALT & FISH LIMITED is a specialist IT company. We design, build and operate software systems for organisations that treat technology as core infrastructure — not a cost centre. Our people are career engineers, architects and security practitioners who ship production systems, own the on-call pager, and stay long enough to be accountable for the outcome.
We measure success in business outcomes, not tickets closed.
Everything ships with observability, SLOs and runbooks.
Threat modelling and least-privilege from day one.
Most clients renew year over year — that's the point.
A focused portfolio of capabilities we deliver end-to-end — from architecture through production.

Web platforms, internal tooling and customer-facing apps designed for the specific way your business works — no template SaaS, no boilerplate.
AWS · Azure · GCP · Kubernetes · IaC.
Threat modelling, hardening, incident response.
Workflows, integrations, back-office AI.
System design and technology strategy.
| Sector | Typical engagement | Focus |
|---|---|---|
| Financial services | Payment platforms, ledgers, compliance tooling | Availability, auditability |
| Healthcare | Clinical workflows, patient portals, HL7/FHIR | Privacy, interoperability |
| Logistics | Fleet ops, WMS integrations, real-time tracking | Latency, reliability |
| Retail & e-commerce | Storefronts, OMS, POS integrations | Scalability, conversion |
| Manufacturing | IIoT dashboards, MES connectors | Data quality, uptime |
| Public sector | Citizen services, digital forms, secure APIs | Accessibility, security |
We pick tools that are proven, well-supported, and boring in the best possible way. No hype-driven architecture.

We meet the people who use the system, map real workflows and separate accidental complexity from essential.
Architecture, threat model, data model and delivery plan — reviewed jointly before code is written.
Small, working increments in production every week. Observability, tests and docs shipped with the feature.
SLO-backed operations, on-call rotations, continuous hardening. We stay accountable in production.

No offshore junior farms. The engineers you meet are the engineers who build.
Weekly demos, transparent burn-down, no surprise invoices.
Systems we build, we help operate — with real SLOs, not marketing ones.
You own the code, the infrastructure, the docs. No lock-in.

Security is not a phase — it's an operating discipline. Every workload we deliver is engineered for least-privilege access, encrypted data flows, continuous scanning and rapid recovery.
Identity-aware access, short-lived credentials, no shared secrets.
At rest and in transit. Keys managed, rotated, audited.
SIEM, anomaly detection, tamper-evident audit logs.
Backups, failover and disaster-recovery drills — actually run.
Migrated a monolithic ledger to an event-sourced architecture on Kubernetes, cutting infrastructure spend and clearing time by 60%.
FHIR-based integration, SSO, audit trail, and accessible UX rolled out across a multi-site provider network.
Rebuilt the picker experience on offline-capable devices, integrated with WMS via a resilient event pipeline.
We favour depth over headcount. Every discipline below is represented by practitioners with more than a decade of production experience.
System design, migrations, high-availability topologies.
Full-stack, backend, mobile — production-grade delivery.
AppSec, cloud security, incident response.
Kubernetes, observability, on-call operations.
Warehouses, pipelines, streaming, governance.
UX for complex, data-heavy internal tools.
Discovery, planning, stakeholder alignment.
Test strategy, E2E frameworks, performance testing.
Finance, healthcare, logistics, retail, manufacturing and public sector organisations that require reliable, secure software systems.
Yes. We embed alongside in-house teams, providing capacity, specialist knowledge and delivery discipline without disrupting your existing workflow.
Every engagement follows secure-by-default practices: least-privilege access, hardened cloud baselines, encrypted data flows, code review and continuous monitoring.
We routinely re-platform legacy monoliths onto modern cloud architectures with zero-downtime migration strategies.
From short discovery sprints to multi-year platform builds. Every engagement is scoped to a concrete outcome.
Distributed across multiple time zones, aligned to the client's operating hours for real-time collaboration.
Every inbound message is read by a member of our delivery team — not a form router. Reach us directly using the address below.