We are a lean German engineering company. We don't try to be everything. We work on a narrow set of hard problems where security, regulatory reality (NIS2, ISO 27001, ISO 9001, TISAX, GDPR) and modern AI actually meet, and we try to build the tooling we wished already existed.
Most of what lives here is infrastructure and developer tooling, not products: the things we reach for daily and would rather maintain in the open than rebuild in private.
- Multi-agent tooling for letting AI agents pick up, execute and ship real engineering work.
- Supply-chain and security utilities for keeping dependencies and pipelines honest.
- An MCP server and other glue for wiring AI assistants into real operational workflows.
- Experiments in European digital sovereignty and sovereign infrastructure: early, sometimes dormant, always with intent.
- Craft over scale. Two people means every line has an owner. We'd rather ship one well-considered thing than ten half-finished ones.
- Open by default. If a tool doesn't need to be private, it isn't. We learn more in the open.
- Run on what we build. We increasingly operate the company itself with the agent tooling you see here: dogfooding, not demos.
- European by conviction. Sovereignty and compliance aren't features we bolt on; they're the constraints we design from.
Heads-down on the core work. The repos here are a window into how we build, not a catalogue of what we sell.
elvatis.com · blog.elvatis.com · Munich, Germany