The books
Ledger
Double-entry accounting for money, credits and stock. It keeps our books and is the same service we sell.
- Built on
- Auth, PostgreSQL
- Data available as
- CSV and JSON
How we run
Our books, specifications, bill of materials and SBOM, commercial record and email all run on systems we wrote and operate. Every platform we sell runs the company first, so a release that would break a set of books breaks ours first.
Comparison
Each of these records sits on a system we run, so we are accountable when one is wrong.
| Concern | Usually bought in | We run |
|---|---|---|
| The books | An accounts subscription | Ledger |
| Specifications and change control | A hosted issue tracker | Tracker |
| Bill of materials and SBOM | A spreadsheet, if anything | Provenance |
| The commercial record (CRM) | A sales subscription, separate from the accounts | Trace |
| Documentation and runbooks | A documentation subscription | Knowledge base |
| Company email | A mail and office subscription | Webmail |
Every system above is built, deployed and running on its own database. Checked 2026-09-09.
The systems
Each system covers one concern, signs people in through our own identity service, has its own database and exports its data in open formats.
The books
Double-entry accounting for money, credits and stock. It keeps our books and is the same service we sell.
Specifications and change control
Every change to every repository starts with a written specification and a ticket, and closes with a note of how it was verified.
Bill of materials and SBOM
An asset register for the hardware, an SBOM for every software release we ship, and security findings tracked against both.
Open Provenance Provenance product page Sign-in required
The commercial record (CRM)
Customer relationship and revenue records, reconciled against the ledger.
Open Trace Trace product page Sign-in required
Documentation and runbooks
Documentation for every platform on the estate, kept so that no service’s runbook exists only in one engineer’s head.
Open Knowledge base Sign-in required
Company email
A mailbox interface over our own mail platform, so company correspondence stays on infrastructure we operate.
Open Webmail Sign-in required
Inside
Four screens from Provenance: the hardware asset register, the evidence pack organised by control reference, the findings table with VEX positions, and the component explorer.
Build or buy
For most of these systems, buying one in would make little sense.
The ledger that keeps our books is one of the products on this site. Paying someone else for an equivalent would be odd, and running it ourselves shows us what each release does to a working set of books.
A small supplier cannot subscribe to a component inventory and security findings across its own estate in CycloneDX, SPDX and VEX, so we built a register for it.
Everything above runs on PostgreSQL, FreeBSD, Python, OpenID Connect and Publicly trusted TLS. We write the application layer, and we do not write our own databases, operating systems or cryptography.
A company that runs its own systems has to cope with the people who built them being unavailable. Every repository has its own runbook. Every change has a specification and a ticket recording how it was verified. Database migrations are stored inside the database they manage, so they survive a restore. Restores are tested end to end, and the whole estate is described in a published topology.
Dependencies
Each row shows a concern, the system that handles it, and the platforms from our own catalogue that it runs on.
The books
Ledger
Auth, PostgreSQL
Specifications and change control
Tracker
issuedb-cli + EARS, Identity
Bill of materials and SBOM
Provenance
Auth, PostgreSQL
The commercial record (CRM)
Trace
Ledger, Auth
Documentation and runbooks
Knowledge base
Auth, TokenGate
Company email
Webmail
RODMENA Mail API, Identity
The right-hand column comes from our own product catalogue. The platforms we sell are the ones we rely on to invoice, ship and keep records. See how the platforms fit together.
We can take you through any of these systems, or send the topology, policies and capability statement for your procurement pack.