04 / SECTION
TECHNICAL.
41
articles
File formats, software, compatibility, hosting, security, large-file delivery, and infrastructure.
41 articles
What file formats do you deliver?
Format depends on discipline. Below is the standard delivery matrix — additional formats free during the 12-month window.
How technical debt is documented
How trade-offs, shortcuts, and deferred improvements are recorded instead of hidden.
How email sending is configured
How transactional email, domain verification, templates, and deliverability are handled.
How app store submissions are handled
What is needed for Apple and Google review and why client accounts own the listing.
How CMS projects are handed over
What clients receive when a content-managed site is finished.
How search features are built
How site search, knowledge-base search, filters, ranking, and empty states are planned.
How staging and preview links work
How review builds are shared before public launch and why they should not be treated as production.
How security reviews are handled
What is included in normal security hygiene and when specialist penetration testing is needed.
How backups are handled
What backup expectations apply to sites, apps, assets, exports, and client-owned services.
How API integrations are scoped
How third-party APIs are assessed for docs, limits, auth, reliability, and long-term ownership.
How credentials should be shared
Why passwords, API keys, and admin access should use secure vaults rather than chat or email.
How large files are transferred
How big footage, source archives, builds, and handover files move without unsafe public links.
What file formats are best for audio
How WAV, MP3, stems, loops, project files, and mix notes are delivered.
What file formats are best for video
How review cuts, masters, social exports, captions, and archive versions are delivered.
What file formats are best for logos
How SVG, PDF, PNG, JPG, and source files are used for logo delivery.
How cookies and consent are handled
When a cookie banner is needed and how tracking scripts are kept minimal.
How analytics are added
How privacy-friendly measurement, conversion events, and dashboard reporting are scoped.
How payments are integrated
How checkout, invoices, deposits, subscriptions, and webhooks are planned for app projects.
How databases are designed
What gets decided before a database-backed app is built: entities, permissions, backups, and retention.
How authentication is scoped
How sign-in, roles, password reset, OAuth, and admin access are designed safely.
How domains and DNS are handled
What access is needed to launch a domain and why ownership should stay with the client.
How hosting choices are made
How static sites, full-stack apps, client portals, and media-heavy projects are matched to hosting.
How performance budgets are set
How page weight, media, animation, fonts, and third-party scripts are kept under control.
How accessibility is handled
What accessibility checks are included by default and what needs specialist audit scope.
How responsive design is tested
How mobile, tablet, desktop, high-density screens, and awkward breakpoints are checked.
What browsers do you support
How browser support is set for websites, apps, dashboards, and interactive prototypes.
What software and frameworks do you use?
Modern, well-supported tools per discipline. Source files are deliverable in the format you can open.
Do you handle hosting, domains, and infrastructure?
We set it up; you own and pay for it. We do not run shared studio hosting for client sites.
What CMS do you build websites on?
Sanity, Payload, or markdown-in-git by default. WordPress only when the client already runs it. No proprietary studio CMS.
How do you handle security and client data?
Encrypted at rest and in transit. Project data deleted 12 months post-handoff unless retention is contracted. UK GDPR registered.
What browsers and devices do you support?
Latest two versions of every evergreen browser; iOS Safari 15+; Chrome on Android 10+. Older targets quoted separately.
What accessibility standards do you follow?
WCAG 2.2 AA by default on web. Reduced-motion always honored. Full AAA audit available as a separate engagement.
What SEO and structured data work is included?
Technical SEO baseline on every web build: meta, OG, JSON-LD, sitemap, robots, performance. Ongoing SEO is a separate engagement.
What testing and QA do you do before delivery?
Cross-browser smoke tests, accessibility audit, performance budget check, content review. Automated tests where they add value, not as a religion.
Do you handle App Store and Play Store submission?
Yes — submission, asset preparation, first review response. The developer accounts stay yours.
How do you deliver large files (raw footage, multitracks)?
Time-limited download links up to 50 GB. Beyond that, encrypted hardware shipped within Europe; client courier for elsewhere.
Do you work to a performance budget?
Yes. Default budgets for LCP, CLS, INP, and bundle size. Every page is measured before sign-off.
Do you deliver design tokens and a component handoff for our team?
Yes. Tokens as JSON, components as Figma library with code parity, plus a one-page system spec.
What analytics and tracking do you install by default?
Nothing by default. Privacy-first analytics on request. We do not install Google Analytics or third-party trackers without your written instruction.
Do you set up transactional email and deliverability?
Yes — provider integration, SPF, DKIM, DMARC, and test sends across major inbox providers. Account stays in your name.
What backup and disaster recovery is in place for sites you build?
Code in git, content in the CMS provider's native backups, database snapshots daily for 30 days. Restore runbook delivered at handoff.