Who you'd be working with.
Point It Here is a joint branch of Maison TergaDo and ΣigmaClava, headquartered in Andover, Kansas, because we're from Andover. The numbers first, then how we work, then how we build and how we protect what we build.
We build from the human to the tech, not the other way around. Most software makes you adapt to it. We start with how you and your customers actually work, then build the tech to fit.
Before we build, we get to know you the way friends do. It's the only way you'll tell us what you really want, and the only way we can build exactly what you picture. You won't have to settle.
You're good at your business. We handle the parts that aren't your specialty. The site, the systems, the tech decisions, explained in plain words, and help making your operations run better.
If we take your project, it means we believe in your business. We're choosy on purpose, and we treat you as someone valuable to us, because you are.
We build with what will still work in five years. Current technology and a design language that ages well, so what we make for you stays relevant longer.
Our team comes from the service industry, engineering, and finance. We've built banking networks, blockchains, AI systems, storefronts, and point-of-sale systems, and we've worked inside the development of the kinds of software tools most businesses already use. We keep learning, both the new technologies and the older systems still running underneath. The engineers are human, supercharged by AI.
Since 2024, Point It Here itself has built and operated its own products too. They're on the work page, next to the client sites.
No change reaches your business without a second engineer reading it, an automated test suite passing, and a way back if we're wrong.
Every change to a system we build or operate follows the same path. There's no express lane, not for an urgent fix, not for a senior engineer, not for a one-line change. The discipline is the point: it's what makes a small change safe enough to make often.
Security
Keeping your business out of trouble.
These are commitments, not aspirations. If we can't meet one on your engagement, we tell you which one and why before the work starts.
Access
- Every person and every service gets the narrowest access that lets it do its job, and nothing beyond it.
- Access is granted for a named reason, reviewed on a schedule, and revoked the day a role changes or someone leaves.
- No shared logins anywhere. Every action in your systems traces back to a named person.
Sign-in
- Multi-factor authentication is required on every account that can reach your systems or ours, including ours.
- Sessions expire, and a sign-in from somewhere unexpected has to prove itself again.
Encryption
- Your data is encrypted in transit and at rest, on every system we run, without exception.
- Laptops and phones that touch client work are encrypted and centrally managed.
Secrets
- The passwords and keys that open your systems are held in a vault built for them, never pasted into code, spreadsheets, tickets, or chat where copies quietly survive.
- They rotate on a schedule, and immediately when anyone with access changes role or leaves.
Separation
- Your data and your environments are isolated from every other client's.
- Production is walled off from everything else, and development never runs against live client data.
Dependencies
- Most software is assembled partly from other people's code, and every piece of it is a possible way in. We use as little as we can, fix each piece to a version we have checked, and watch continuously for newly discovered flaws.
- Security patches are applied on a stated clock: critical fixes the same day, the rest within the week.
Backups
- Systems we operate are backed up daily and kept off the machine they came from.
- Restores are rehearsed on a schedule, a backup nobody has restored isn't a backup.
Monitoring
- Systems we run keep a record of who did what and when that cannot be quietly altered, and you can read yours.
- Failures, unusual access, and error spikes raise an alert to a person, not just a dashboard nobody opens.
When something goes wrong
- You get one named contact who owns the incident from first alert to final write-up.
- We tell you within 24 hours of confirming an incident that touches your data, before we have all the answers, not after.
- You receive a plain-language account of what happened, what we did, and what we changed so it can't happen the same way twice.
Our own people
- Everyone who touches client systems is trained on these practices before they get access, and re-trained every year.
- Offboarding is same-day: access removed, devices returned, credentials rotated.
Third parties
- You get the full list of outside services that touch your data, and what each one is for.
- We tell you before we add one, not in a changelog you were meant to have read.
Engineering
How the work actually gets done.
Good practice isn't paperwork. Each of these exists because skipping it is how systems quietly break at the worst possible moment.
Everything is tracked
- Every change to your system is recorded: what changed, who changed it, when, and why. If you ever need to know what happened, the answer exists.
- Nothing reaches your live system by hand, from somebody's laptop, or quietly over a weekend.
Review
- A second engineer reads every change before it goes anywhere near your business. No exceptions for urgency, seniority, or size, because the faults that matter are usually the ones the author couldn't see.
Tests
- Automated checks run against every change, and anything that breaks them can't ship.
- When a fault does get through, we add the check that would have caught it before we fix the fault itself, so the same failure can't come back later.
Rehearsal
- Nothing is tried out on your live system. Changes prove themselves first on a copy built to behave like the real thing.
- Anything that alters your existing records is reviewed, rehearsed against a duplicate first, and built so it can be undone.
Release
- We ship small changes often rather than large ones rarely, because a change small enough to understand is one we can reverse.
- Every release has a way back, decided before it goes out rather than improvised afterwards.
Accessibility and speed
- Built to WCAG 2.2 AA, usable without a mouse, and tested with a screen reader, so customers who need that can still buy from you.
- Pages are held to a speed limit, and a change that pushes them over it doesn't ship.
Documentation
- Every system is handed over with a runbook in plain language: how it works, how to operate it, what to do when it misbehaves.
- If only we can run it, we haven't finished it.
Ownership
It's your business, and it stays that way.
The uncomfortable questions are the ones worth answering in writing: what happens to your systems, your data, and your options if you stop working with us.
You own it
- The code, the data, the infrastructure, and the accounts are yours. We hold the keys; we don't hold them hostage.
- You get repository access from the first commit, not at the end of the engagement.
You can leave
- Every engagement has an exit plan written at the start: how your systems and data come across, and how long it takes.
- Your data exports in a documented, open format whenever you ask, for any reason or none.
We keep only what we need
- We collect the minimum data a system needs to work, and delete it on a stated schedule.
- Your business data is never used to train models, sold, or shared with anyone you haven't approved.
No lock-in by design
- We build on widely used, open technology so another firm could pick your system up and carry on.
- Where we recommend a paid service, we tell you what it costs, why it earns it, and what replacing it would take.
Reporting a problem
Found something? Tell us.
If you believe you've found a vulnerability in one of our systems or a system we built, we want to hear it, and we'll not come after you for telling us.
- We acknowledge every report within one business day.
- We tell you our assessment, and what we plan to do, within five business days.
- We keep you updated until it's fixed, and we credit you if you would like to be credited.
- Testing in good faith against our own systems will never be met with legal action.
- Please don't access, modify, or retain data that's not yours while testing.
- Automated tooling reads our contact details from security.txt.
Hold us to all of it.
Bring these practices to your first conversation and ask us to show our work. Every project starts with a signed contract and a working demo: $200 for a website, or a website and apps, and a quoted demo price for everything else.