Security Services · Mobile App & Product Services · Platform Engineering
Our Services
Practical security, app, and AI services for New Zealand businesses
Security Services
Practical security assessments, hardening, and ongoing advisory for your digital assets
Mobile App & Product Services
Security-integrated mobile development, MVP delivery, and rescue services
Strategic Product Partnership
For selected app products, a longer-term partnership path may be a better fit than a standard package. It is selective, application-based, and reviewed directly.
Explore Partnership →App work
What we've built
Cross-platform products built and delivered for the region.
Real completed client engagements. Client identities and identifying operational details are withheld for confidentiality.
Real BilgeQor-owned product work. These are owned product cases, not client engagements or demos.
Meyo Party Video Stream
iPhone · iPad · Android
Real-time video streaming app
Client work
Null Null Football Tips
iPhone · iPad · Android
Sports tips and analytics app
Client work
Hukas Law Assistant
iPhone · iPad · Android
AI-assisted legal research app
Client work
Physician Application
iPhone · iPad · Android
Clinical workflow management app
Client work
Relay VPN Utility
iPhone · iPad · Android
VPN utility app
BilgeQor products
Private Chat
iPhone · iPad · Android
Private messaging app
BilgeQor products
Relay Access
iPhone · iPad · Android
Secure access management app
BilgeQor products
BilgeQor: Aura
iPhone · iPad · Android
Privacy-first mobile app
BilgeQor products
Platform Engineering
Scoped backend, API, cloud, production, rescue, and platform modernisation work with documented boundaries, controlled transition, operational visibility, and technical handover.
Before You Build
For clients planning a mobile product. Define what to build, what it will cost, and what it will look like — before committing to development.
Additional Security Services
Specialised security support for modern risks, urgent recovery, and ongoing care
Specialised Security Engagements
Targeted, scoped engagements for service availability and resilience under agreed conditions.
AI Services & Secure Adoption
AI work is scoped before it starts. We review, document, and integrate AI tools within clear boundaries — with written human oversight built in.
AI work is request-first. We confirm scope, data handling approach, and delivery expectations in writing before any deposit, invoice, or payment link is issued.
Plan & Review
Build & Integrate
Review & Improve
BilgeQor Method
The Security File turns risk signals into decisions.
Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.
What the Security File contains
A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.
01
Market and sector context
We connect official market signals and industry exposure to the business surfaces in scope.
02
Exposure map
We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.
03
Priority register
We separate urgent risks, important improvements and lower-priority findings so the next action is clear.
Custom Engineering & Applied R&D
For specialised systems, integrations or technical problems outside a standard service, we begin with a short technical assessment and written scope. Research-heavy or uncertain work may first be directed to Technical Feasibility & PoC; feasibility, production readiness, performance, security and commercial outcomes are not guaranteed.
Custom SaaS & enterprise systems — specialised portals, operational workflows, internal systems, complex integrations, and multi-tenant or permission-sensitive systems. Full application development, managed operations, 24/7 SRE, SOC, MDR, NOC and live incident response are separately scoped.
Real-time communication & media systems — messaging, notifications, WebSocket/WebRTC, signalling, STUN/TURN, room and media-access boundaries, live streaming and media delivery. Production or destructive changes require written authorisation.
High-performance, distributed & intelligence systems — Rust/Go services, collectors, gateways, event-driven systems, distributed experiments, data processing, entity resolution, intelligence pipelines, and low-level performance work. Scope, access, data quality and third-party availability affect feasibility and timing.
Blockchain, Web3, protocol & applied R&D — Web3 backends/APIs, wallet and transaction flows, indexing, protocol/SDK development, digital-payment infrastructure, measurable research hypotheses, bounded prototypes and technical decision records. Mainnet, data migration, security testing, third-party licences, cloud, API, transaction and specialist-tooling costs, and independent smart-contract or economic-security assessment require separate written confirmation.
