Cruise
A luxury cruise line
One portal for a luxury cruise line's operations, from procurement to ship provisioning
- back-end services behind one portal
- 36
- functional areas, from procurement to crew payroll
- 20+
Architecture and operations, at Codedesign, means designing the structure of critical systems — security, data, integration, hosting — and then running them: monitoring, maintenance, continuous releases and documentation that stays true.
The decisions made in the first weeks — how people sign in, where data lives, how services talk — determine what a system will cost to change for years. When they are made implicitly, nobody remembers why, and nobody dares to touch them.
Operations is where software shows how well it was built. A system that nobody monitors, updates or documents slowly becomes a legacy system, however recent its code.
Design at the start, care for as long as the system runs.
01
The structure of a new system — modules, data, integration, hosting — designed around its load, its risks and the team that will maintain it.
02
An independent review of an existing system, with the risks ranked by impact and a plan you can act on.
03
Single sign-on, roles and permissions, audit trails, secrets management, and a security baseline mapped to recognised references such as ISO/IEC 27001 controls and OWASP guidance.
04
Hosting on Microsoft Azure — App Service, Azure SQL, Blob Storage, Service Bus — or on your own Windows servers with IIS and SQL Server, chosen for the system, not for fashion.
05
Logs, metrics and traces, with OpenTelemetry where it fits, that show how the system behaves in production and where it fails.
06
Updates, fixes and new features released in small versions, each described in a changelog.
07
Architecture decision records, operating guides and technical documentation kept current with every release.
01
We read the code, the infrastructure and the incident history, and talk with the people who run the system.
02
Each architectural choice is written down as an architecture decision record: context, options, decision, consequences.
03
Builds, releases and checks are automated, so that a release is routine rather than an event.
04
We monitor, update and release, and report what changed and why.
An architecture decision record for every significant choice, so the reasoning outlives the meeting where it was made.
Identity, roles and audit are part of the first design, not a checklist before go-live.
Established technologies for the core of the system; newer ones only where they earn their place.
If it runs in production, it produces logs, metrics and traces that someone reads.
Frequent, documented releases are safer than rare, large ones.
An industrial fan manufacturer's production and shipping application runs on Azure with single sign-on and has reached 68 releases, each documented in a changelog. Read the case study. For a luxury cruise line we built a platform of 36 back-end services on Windows Server, IIS and SQL Server, with scheduled jobs and Microsoft Entra ID sign-in with two-factor authentication. Read the case study.
Cruise
A luxury cruise line
Industry
An industrial fan manufacturer
Sometimes the right answer is a product off the shelf, and we say so. Sometimes the licence that looked cheap becomes one of the largest lines in the budget. How to tell the difference.
, 6 min read
Governance is what lets a company put AI into production without losing control of its data. What the GDPR and the EU AI Act ask of a company that uses AI, with the AI Act timeline as amended in July 2026.
, 7 min read
An architecture decision record (ADR) is a short document that captures one significant technical decision: the context, the options considered, the choice made and its consequences. Kept alongside the code, ADRs let a team understand years later why a system is built the way it is. One of Codedesign's current projects has 25 of them.
An architecture review examines the code structure, data model, integrations, security, hosting and operations of an existing system, based on the code itself and on conversations with the team. The result is a written report with the risks, their likely impact and a prioritised plan.
Both. Codedesign delivers systems on Microsoft Azure (App Service, Azure SQL, Blob Storage, Service Bus) and on clients' own Windows servers with IIS and SQL Server. The choice depends on data, integration and cost, not on preference.
Security by design means that identity, permissions, audit trails and data protection are designed into a system from the start. In practice: single sign-on with two-factor authentication, roles defined by function, every sensitive action logged, and a security baseline mapped to references such as ISO/IEC 27001 controls and OWASP guidance.
Yes, after an initial assessment. Codedesign reviews the code and the infrastructure, documents what it finds, sets up monitoring, and then takes over maintenance and releases step by step.
Architecture and operations
That is usually the right place to start. Tell us about it, and we'll propose how to assess it.
Request a private meeting