Skip to content

Software development for the DACH Mittelstand from an EU-resident, ISO 27001 certified partner.

Twenty of the 61 client reviews on our Clutch profile come from companies in Germany, most of them software and product firms buying engineering capacity. This page answers the procurement questions in the order a German buyer asks them.

You sign with an EU company under EU law, the security practice is externally audited, and the working language is English. The FAQ answers the entity, language and NIS2 questions in plain terms.

  • ISO 27001Certified security practice, audited by Quay Audit UK
  • ISO 9001Certified quality management, audited by Quay Audit UK
  • ISTQBCertified QA inside every sprint
  • 120+Projects delivered across 12 countries since 2012
  • 2 to 4 weeksTypical time from signature to start

01Overview

What a procurement check actually asks a foreign supplier

unicrew is a nearshore custom software development partner (founded 2012, formerly Artelogic) working with software and product companies in Germany from offices in Ukraine, Poland, Estonia and the UK. Twenty of the 61 client reviews on our Clutch profile are from German companies: CaT Concepts in Cologne, Bitergo in Dortmund, meinUnterricht in Berlin, Logic Screen Solutions in Karlsruhe, an ERP SaaS provider in Hamburg. A German buyer, usually the Geschäftsführer or the head of IT, runs four checks before the technical conversation starts.

  • The entity you signWho the contracting party is, under whose law, and where the invoice comes from.
    • Artelogic OÜ, Tallinn
    • Registry code 16127919
    • EU and UK GDPR, both named
  • The certificatesWhich standards are held, who audited them, and whether they are current.
    • ISO 27001:2022
    • ISO 9001:2015
    • Audited by Quay Audit UK
  • The peopleEmployees or subcontractors, how they are vetted, and who you actually meet.
    • Senior in-house engineers
    • ISTQB-certified QA in the sprint
    • You interview the engineer
  • The evidenceWhether the reference list is a logo wall or something you can check yourself.
    • 20 German clients reviewed on Clutch
    • Every review verified by Clutch
    • Named case studies, linked

02Compare

Three ways to add engineering capacity, side by side

Most German software companies weighing a build partner are choosing between three routes. A fourth, individual freelancers from a platform, is left out of the table because it moves the vetting, the contract and the security review onto you rather than removing them. Read the rows against your own checklist rather than ours.

Hire in GermanyIn-house Nearshore inside the EUunicrew Offshore, outside the EUOffshore
Best whenThe knowledge has to stay in the building and you can wait out a hiring cycle to get it there. Best whenYou need a specific skill set now and the contract has to clear an EU data-protection review. Best whenThe work is tightly specified, cost decides, and nobody is auditing your vendor list.
Contracting and dataGerman employment law, your own systems throughout, and no third party in scope at all. Contracting and dataOne EU counterparty, Artelogic OÜ in Tallinn. Delivery runs from Ukraine, Poland and Estonia, and the access model is agreed before anyone starts. Contracting and dataCounterparty and delivery both outside the EU, which is its own assessment for your data protection officer.
Getting startedA hiring cycle, then onboarding, then the months it takes to build the knowledge internally. Getting startedTwo to four weeks from signature on most engagements, with your team interviewing the engineer first. Getting startedQuick to start. The time-zone gap usually shows up later, as review and rework.
If it endsYou keep the person, the knowledge and the payroll. If it endsYou keep the code in your own repository, written in your process, with the contract closing on the engagement. If it endsYou keep the code, plus whatever documentation the contract asked for.

03Capabilities

Six kinds of work German software companies bring us

Six things German clients have actually hired us to do, each with the service page that covers it properly. Every one comes from an engagement with a published client review.

  • The most common German engagement: one or two engineers who join your stand-ups, your repository and your process. A Cologne learning-software vendor, a Hamburg ERP SaaS provider and a Karlsruhe automotive-software company all run this shape.

    Who buys it
    Product teams with more roadmap than people
  • Replacing legacy interface components without losing behaviour, and rebuilding front ends that have outgrown their framework. TypeScript, React, Vue and Angular work sits here.

    Who buys it
    Vendors whose product outlived its own UI
  • iOS and Android clients built on a web product already in the market, including layout, theming and video streaming for a German building and security software vendor.

    Who buys it
    Web-first products whose buyers now expect an app
  • Relevance, filtering and autosuggest, plus the AI tagging and embeddings behind vector search. The Berlin ed-tech platform meinUnterricht measured a roughly 9 percent lift in search success rate from this work.

    Who buys it
    Products where search is the product
  • A Munich software company had two people typing datasheets into a product database. We built document recognition around it on C# and AWS, and the throughput doubled.

    Who buys it
    Teams paying salaries to re-key data
  • Four corporate sites for a Regensburg financial-services group, with accessibility handled as a requirement from the first sprint rather than an audit at the end.

    Who buys it
    Groups whose public sites carry obligations

Run the security and data questions before the technical trial, not after it. A partner can answer paperwork in a day, and you need weeks to judge the engineering. Do it the other way round and you spend a month liking a team your own auditor will not let you sign. Ask for the documents on the first call.

Vuhar MamedovManaging Partner, Europe, unicrew

04Delivery

The order we suggest you run the evaluation in

Four stages, in the sequence the quote above argues for. Paperwork first, because it is cheap to check and expensive to discover late. Then a piece of real work small enough to walk away from.

  1. Send the security questionnaire firstBefore the technical call, not after it. Which entity signs, which standards are certified and who audited them, how access to your systems is granted, and where the engineers sit. If those answers do not clear your review, nothing later matters.You getWritten answers on entity, certification and access
  2. One technical call, with the engineer on itNot a sales qualifier. The person who would do the work joins, you describe the problem, and we say whether it fits. German clients have sat in on our candidate interviews and picked the engineer themselves, which is the normal arrangement rather than a favour.You getA named engineer and an opinion on scope
  3. A pilot small enough to throw awayOne deliverable, a few weeks, real code in your repository. Bitergo in Dortmund started exactly this way before committing to anything larger. It is the cheapest way to find out how a partner behaves when something goes wrong.You getWorking code in your process, and a decision
  4. Scale it, or stopIf the pilot earns it, the same engineers become the standing team and the engagement moves to a monthly team-extension model. If it does not, you have lost a few weeks and learned something about your own codebase.You getA standing team, or a clean stop

05Security

Security, contracting and what each side owns

Two halves of one conversation: the obligations that stay yours whichever supplier you pick, and what unicrew brings to them. The FAQ says where ISO 27001 reaches NIS2 and where it stops.

Stays with youYour obligationsWhat your regulator and your own auditor hold you to, whoever writes the software.
  • Your NIS2 classification

    Whether you are in scope, and the registration, reporting and governance duties that follow, are decided by your sector and your size rather than by your supplier.

    Who owns it
    You, with your regulator
  • Your vendor questionnaire

    Your own review of us: the contracting entity, the certification and its auditor, the access model, and where delivery physically happens. We would rather answer it before the technical call than after.

    Who owns it
    You ask, we answer in writing
  • Personal data inside your product

    GDPR obligations for the data your own software holds do not transfer to a development partner. What we can do is design retention, access and erasure into the build instead of bolting them on.

    Who owns it
    You, in the build with us
unicrewWhat we bring to itThe credentials, the delivery practice and the access model behind them.
  • ISO 27001:2022 and ISO 9001:2015

    Information security and quality management, both renewed through a multi-stage audit with Quay Audit UK. Externally checked rather than self-declared.

    In an engagement
    The controls your questionnaire asks about
  • ISTQB-certified QA inside the sprint

    Certified QA engineers sit inside the team on every engagement rather than a test pass added at the end. On a product your own customers already run, that is the difference between a release and an incident.

    In an engagement
    Defects caught before your customers
  • Least-privilege access, agreed first

    Contracts and NDAs before anyone starts, then access agreed with your technical contact, read-only wherever the work allows. On a build engagement the access model is written down before the first commit.

    In an engagement
    Read-only where the work allows
When compliance is the project

A fixed-scope readiness sprint, run separately from a build

Where the gap is the compliance work itself rather than the software, it runs as its own engagement: a fixed-scope review that maps your GDPR and, where relevant, NIS2 obligations, ranks the findings by risk, and ends in a written report and a remediation roadmap.

06Proof

The record a German buyer can check without us

Four things on this page you can verify from outside it: a public review profile, two numbers the clients measured themselves, and one piece of criticism.

  • Twenty German clients have reviewed us in publicNamed: CaT Concepts, Bitergo, meinUnterricht, Logic Screen Solutions, meta-fusion, Goldn, QUEO, Interone, JewelCandle, Bigfood Group and RWTH Aachen. Nine more publish anonymously, among them a Hamburg ERP SaaS provider and a building-security software vendor. All 61 carry Clutch's verified badge and are readable in full on client reviews.
    20of our 61 Clutch reviews come from Germany
  • The one thing a German client told us to fixRichard Klees, Managing Director of CaT Concepts and Training GmbH in Cologne, was asked on Clutch what we could have done differently. His answer: "They could have told earlier that they have a business entity in the EU." He was right, and this page is the correction. The same review says we were "super responsive and did exactly as we agreed upon".
  • Numbers the clients measured, not usA Munich software company automated a manual database process with us on C# and AWS. Its CEO writes: "Two people typing data into the database went about 5,000 new data sets per month. With this component, we’re reaching twice the amount of data sets per month." Berlin ed-tech platform meinUnterricht reports a roughly 9 percent lift in search success rate, from a controlled experiment.
    2xdata-entry throughput, in the client's own count
  • Clients who stayed, and said so where you can read itSven Grundmann, CEO and Lead Architect of Logic Screen Solutions in Karlsruhe, calls unicrew a "Very reliable business partner. We already did recommend them on multiple occasions." A Hamburg ERP SaaS provider, describing work done under our former Artelogic brand, credits developers who "frequently offer reports, track their times accurately, and keep track of their activities in version control frequently".

07Client voices

German clients, in their own words

See our client reviews
5.0 unified ratingacross 61 verified client reviewsRead them on Clutch

09Questions

What procurement asks before the technical call

Artelogic OÜ, registered in Tallinn, Estonia under company code 16127919 and trading as unicrew. It is an EU company, so the agreement sits under EU law and your data protection officer reviews one European counterparty. We hold no German legal entity and no German VAT registration, so if your procurement requires a German-law contract with a German company, raise it on the first call rather than at signature.

No. The working language is English, in writing and in meetings, and we would rather say so here than in week three. One German client put it on Clutch: "It could help if a teammate from Artelogic spoke German professionally." Another, the Managing Director of a contract research organisation, wrote "Very good communication skills, no language barrier". If your team works only in German, we are the wrong partner.

Directly, but not completely. ISO 27001 maps to roughly 70 to 80 percent of NIS2's baseline requirements (Reed Smith, January 2026), and we cover the distance to your specific obligations with you. Our ISO 27001:2022 certification was renewed through a multi-stage audit with Quay Audit UK, so the controls are externally verified rather than self-declared. Your registration, reporting and governance duties stay yours: no vendor certificate makes you NIS2 compliant, ours included.

No. unicrew holds ISO 27001:2022 for information security and ISO 9001:2015 for quality management, both renewed through a multi-stage audit with Quay Audit UK, and GDPR practice is standard on every engagement rather than a special request. SOC 2 is the North American equivalent and we have not pursued it. If your review board requires a SOC 2 report specifically, that is a real blocker and worth raising early.

Not on our public record. All twenty of the DACH reviews on our Clutch profile are from companies in Germany, and every German case study on this site is a German client. We would rather say that than let the word DACH imply work we cannot show you. The contracting entity, the certifications and the engineering are the same whichever of the three countries you are in.

Three engagement models: time and materials billed hourly and quoted per project, fixed price quoted per project against an agreed outcome, and team extension billed monthly per team member. Which one fits depends on how firm the scope is, and we recommend one at the end of discovery rather than before it. Most engagements start within two to four weeks of signature, and there is no recruitment or placement fee on a team extension.

By distributing delivery across Ukraine, Poland and Estonia, and by pointing at the record. Our engagement with the Munich agency Interone ran from December 2021 to January 2023, and its executive credits "dedication and resilience during moments of crisis (russian invasion)". Goldn CTO Frank Rössler writes that we "deliver in a highly professional way while being in a volatile and insecure situation". Ask about the setup in detail on the first call.

Send the questionnaire, and we will answer it in writing

A call with a senior engineer rather than a sales qualifier. Bring the procurement checklist as well as the technical problem, and we will clear both on the same call.

Let's talk

What happens after you contact us

  1. We reply within one business dayA senior engineer reads your message, not a bot.
  2. Entity, certification and access, in writingThe procurement answers before the technical conversation.
  3. A technical call with the engineer on itYour product, your constraints, and whether we fit them.
  4. Engagement model, then a pilotTime and materials, fixed price or team extension. Most engagements start within two to four weeks.

Thank you

Thanks for your message. We will get in touch with you shortly.

Book a call