Foxinelo Ltd. · London · since 2020

Software that isn’t just built. It’s operated.

We build our own SaaS products and selected systems for businesses – to the same standard: multilingual, tax-correct, secure, and proven in production.

Direct access to the architect. No sales layer in between.

Our product

HandiVo

Quoting, job and invoicing platform for trades businesses. Developed, operated and owned by Foxinelo.

HV
HandiVohandivo.app · SaaS · Multi-Tenant

From floor plan to signed invoice – in 16 languages.

Room planner, material calculator, quotes, customer portal with signed acceptance, PDF, invoicing with country-specific tax logic. One system that handles a tradesperson’s books in France as well as in Malaysia.

7weeks from idea to launch
23market–locale combinations
9country compliance modules
76email templates × 16 languages
Open handivo.app

Why this is here: HandiVo is the most credible evidence of how we work. Running software for yourself – with Stripe webhooks, App Store reviews and tax auditors on the other side – makes you build differently from someone who walks away after handover. We bring the same discipline to your systems.

Services

Three areas of focus. Nothing else.

We take on projects that fit these three areas – and decline the rest.

A

Product engineering

Custom platforms meant to run for years: SaaS, customer portals, multi-tenant systems, mobile apps.

  • Architecture, backend, web frontend, iOS/Android
  • Multilingual systems with country-specific tax and invoicing logic
  • Stripe billing, entitlements, trial-abuse protection
  • Operations: Docker, Cloudflare, monitoring, tested backups
Also · Websites & online shops

Websites are built individually, without page builders or themes: our own code, our own design, fast and cut precisely to your business. No plugin stack, no maintenance dependency, no site that already exists a hundred times over. Online shops run on SureCart – checkout, subscriptions, taxes and payment providers as one system. Our agency licence covers your shop permanently, with no licence fees on your side.

B

Security

Penetration tests, audits and hardening for web applications and servers – with reports both management and engineers can read.

  • OWASP-based penetration testing, manual, not just scanners
  • Security audits with a prioritised action list
  • System hardening for production environments
  • Incident analysis and recovery
C

AI inside existing workflows

Not showcase chatbots – AI placed where it replaces a measurable step in your process.

  • Classification, extraction and routing of documents and requests
  • Integrated into existing systems rather than isolated tools
  • Data processing agreements with model providers (OpenAI, Anthropic) in place
  • Traceable outputs, no black box in your core process
Security

What a report from us looks like.

Excerpt from an anonymised penetration test report. Every finding has a severity, evidence and a status.

Findings · Web app · ExcerptRetest passed
Critical
IDOR on invoice endpointOther tenants’ invoices retrievable by ID. Evidence: 3 requests, screenshots attached.
Fixed · Retest OK
High
Session not invalidatedToken remains valid after password change.
Fixed · Retest OK
Medium
No rate limiting on loginBrute force succeeded in 4 minutes.
Fixed · Retest OK
Low
Content Security Policy in report-only modeRecommendation with a timeline for enforcement.
Accepted

We test manually because scanners don’t find the flaws that actually hurt: authorisation logic, tenant isolation, payment flows. Every report includes reproducible evidence and a retest after remediation.

01
ScopeWhat gets tested, what doesn’t, and why – in writing before the first request.
02
TestManual, focused on business logic. Tooling only as support.
03
ReportOne-page management summary, technical section with evidence.
04
RetestIncluded. A finding is closed only once we can no longer reproduce it.
How we work

What you can expect from us.

Three commitments that apply to every project – from an online shop to a multi-tenant platform.

Decisions at architecture level

From day one you talk to the person designing the system, not a project manager relaying requirements.

Delivered ready to operate

Documentation, deployment, backups and monitoring are part of the delivery. You could run what we build yourself on the day of handover.

Data protection to EU and UK standards

Processing agreements, impact assessments and sub-processor contracts are part of the project, not an afterthought.

Foxinelo Ltd. · London Registered in England & Wales · 12657178 ICO registration (UK data protection authority) · ZB613316 Clients in the UK · Germany · Austria · Switzerland · USA · Southeast Asia
Contact

Tell us what you’re planning.

You’ll receive a technical assessment within one business day – not a sales pitch.

By sending this form you agree that Foxinelo Ltd. processes your details to handle your request. See our privacy policy for details.