Riff Apps

Services

We work as a small senior team on a handful of projects at a time. That means you get the people who scoped the work actually building it.


Application development

Web applications and native mobile apps, built with React, Next.js, TypeScript and a Postgres‑shaped data layer. We ship to the App Store, Google Play and the web, and we set up the deployment pipeline so releases are routine rather than an event.

Everything is written to be handed over. Documented architecture, readable code, infrastructure as configuration and accounts in your name — so you are never locked into us by accident.

Discovery and scope 1–2 weeks
Prototype 2–3 weeks
Build cycles 2 weeks each
Launch and run Ongoing

AI engineering

We use current frontier models where they genuinely improve the product, and say so plainly when they don’t.

Assistants and conversation

Assistants that hold context, use your data through retrieval, and call real tools rather than guessing. Built with explicit limits on what they can see and do.

Generation with structure

Generated documents, lessons, summaries and reports that stay coherent across a whole body of work — the hard part is consistency, not a single good output.

Matching and classification

Scoring, ranking and routing, with the reasoning surfaced so a user can see why they got a result.

Evaluation harnesses

Test sets and scoring that run in CI, so a prompt or model change can’t quietly degrade quality.

Guardrails and fallbacks

Input and output filtering, rate limits, cost ceilings and a defined behaviour for when a model is unavailable.


Governance and assurance

Available inside a build, or on its own if you have a product already live and a deadline approaching.

Data protection

Records of processing, lawful basis, DPIAs, retention schedules and subject access handling.

AI documentation

Model cards, intended use, known limitations, human oversight design and an audit trail of changes.

Accessibility

WCAG 2.2 AA audit with a prioritised remediation plan and retesting after the fixes land.

Security review

Threat modelling, dependency and secrets auditing, authentication and authorisation review, and coordination of third‑party penetration testing where the risk profile calls for it.

Policy set for launch

The public documents a product needs on day one — privacy, terms, cookies, acceptable use, AI transparency — written to match what the software actually does, then reviewed by your legal advisers.


How we charge

Three ways of working. We’ll recommend the one that fits the certainty of your scope, not the one that bills most.

Discovery sprint

Fixed price, one to two weeks. Scope, prototype, technical approach and a costed plan. You keep everything whether or not you continue with us.

Fixed‑scope build

A defined product for a defined price, staged across milestones. Best once discovery has removed the big unknowns.

Ongoing team

A monthly retainer for continuous development, support and improvement after launch. Cancellable with notice.

Not sure which you need?

Send a paragraph about the problem. We’ll reply with what we’d do first and a rough range, at no cost.