Firmware & hardware integration
Embedded work and the protocols that connect devices to the software around them.
Manila · Mostly after 22:00
We're a small senior studio in Manila. We build custom software — mobile, web, backend, and the hardware-connected systems most teams won't touch. Ten years of shipping the complicated version means we can usually tell you the simple one.
The range is wide. The pattern isn't — we're usually hired for the part of the system someone else would rather not own.
Embedded work and the protocols that connect devices to the software around them.
Stabilizing, documenting and extending software someone else wrote — often after the original team is gone. Most of our engagements start this way. We do a lot of this.
iOS and Android from one codebase, including hardware-connected apps and store release pipelines.
APIs, data models and integrations, designed for the load you'll actually have.
Customer-facing products and internal tools, built to be maintained.
Cross-platform applications for teams that need more than a browser can give.
Five engagements. Different industries, different stacks, same shape of problem: we get called for the layer nobody else wants to own.
A consumer hardware device with a companion mobile app. Over several years we've owned the embedded firmware, the wireless protocol it speaks, the codec library that decodes it, the cross-platform app that drives it, and the desktop tool engineers use to inspect and flash devices in the field. When the protocol moved between two different wireless standards, that change had to land across all five layers in coordinated releases — including root-causing a hardware test-jig grounding fault that only appeared with one particular USB bridge chip. The same engagement included getting the app through App Store review as a hardware companion product — a category with its own rejection rules and its own appeal process.
Platforms
A high-value transaction platform: roughly twenty Java services communicating over an event bus, with signed inter-service requests and a four-stage release promotion pipeline. We were brought in for architecture documentation and targeted security work. We produced a 61-page developer handbook with 68 architecture diagrams, and shipped fixes for unbounded request handling and a re-entrancy ordering bug in the transaction layer.
Platforms
Three front ends over a single multi-tenant backend: the core compliance workspace where records and regulatory filings are managed, an internal control panel for administrators, and a self-service portal for the workforce it covers — with permissions, routing and configuration varying per tenant. We built the platform, wrote the tooling that migrated a client off their legacy system (1,280 records, idempotent re-runs, dry-run mode), and hardened it as it matured: API-token requests were failing silently across 22 endpoints and a nullable join was quietly dropping records from compliance reports, the kind of defect that surfaces during an audit rather than before one. We left the critical paths covered by 241 regression tests.
Platforms
A recovery and mental-health platform: structured program content, progress tracking, and a moderated community where members post and support one another. The hard part wasn't the feature list — it was the responsibility. Building a social product for people in recovery means treating moderation, privacy and data handling as first-order design problems rather than settings.
Platforms
A community app for a niche recreational audience: activity logging, location sharing, feeds and the social graph connecting them. We built the entire product — the Java backend and data model, the cross-platform iOS and Android app, and the admin tooling behind it — and carried it through two major versions.
Platforms
Client names withheld under NDA. That's typical of the engagements we take — the ones where we're handed the whole system rather than a ticket queue.
If your thing looks like one of these, we've already built something like it.
Start a conversationOur client work is confidential. Our open-source work isn't. It's built to the same standard, and every line of it is public.
Attesto
Receipt validation for App Store and Google Play in-app purchases. Apple JWS chain verification against pinned roots, encrypted per-tenant credentials, and webhook ingestion with cryptographic origin verification.
Babelon
AI-assisted localization. Translates application message catalogs while preserving ICU plurals and placeholders, with a Rust CLI for CI integration.
@nosslabs/iap
In-app purchase orchestration for Capacitor. We upstreamed fixes into the native plugin it builds on.
@nosslabs/bluetooth-classic
Bluetooth Classic for hybrid mobile apps, native on Android and iOS behind a single TypeScript API.
A small team, and no mystery about how.
We have no brand loyalty to frameworks or platforms — we pick what solves the problem and fits the budget. Sometimes that's a full cross-platform build; sometimes it's a static page and a spreadsheet. If the cheaper answer is the right one, we'll say so before you've signed anything.
They accelerate drafting, research and refactoring. They do not decide architecture, and nothing reaches your branch without human review. We run adversarial review as a required gate — a second pass whose job is to break what the first one wrote. The result is that a small team ships like a larger one, without shipping a larger team's defects.
We don't let a model make a decision we couldn't defend ourselves.
We run a staged QA pipeline with dedicated QA — code review, functional testing, then release testing — before anything reaches production.
Maintainable systems over quick fixes. If we can save you time and money by recommending a simpler approach, we will.
A small senior team: engineers, and QA who don't also write the code they're testing. Led by Joseph Harvey Angeles, who has been building software for over a decade and still writes it — previously at Nokia Networks, where he worked on cellular core and early 5G systems, and at Accenture. He spoke at the first Quasar Conference on building multi-platform applications.
More about Joseph →Tell us what you're building. No deck, no discovery fee.
What we'd build, what it costs, how long. Fixed before we start.
You see progress continuously, not at a milestone reveal.
Documented, tested, and yours. We're available after, not required.
Tell us what you're trying to build.
If we're not the right fit, we'll say so — and usually we'll tell you who is.
Or email us
nossteam@nossdev.comMessage sent
Thanks — we'll reply within two business days.