---
title: "Enterprise software delivery: pilot to production"
canonical: https://wavect.io/enterprise/
language: en
description: "A buying pathway built for enterprise: procurement and governance, security review, stakeholder alignment, integration with your internal teams, formal …"
image: "https://wavect.io/img/general/bak/open_graph_preview.jpg"
---

For enterprise buyers

# Prove it in a pilot before you commit to production

You need more than a demo before you commit budget and reputation to a build. We give you a way to procure, govern, secure and integrate one that lands inside your organization: a scoped pilot, proven against your acceptance criteria, then graduated to production with the documentation and continuity your stakeholders expect.

How we start Pilot first then production, on your criteria

In one sentence

Wavect runs enterprise engagements as a scoped pilot that graduates to production, with procurement, governance, security, stakeholder alignment and integration handled the way a large organization needs, and a complete handover so nothing depends on us staying.

Built for

- Enterprises that need a pilot to de-risk before a production commitment
- Buyers with a procurement, security and governance process to satisfy
- Teams integrating a build into existing internal systems and stakeholders

Probably not for

- Teams that want to skip a pilot and buy a fixed year-long program sight unseen
- Buyers who require an incumbent with ISO 27001 or SOC 2 on file today
- Work with no internal stakeholders, where founder-direct delivery is simpler

// 01

## The pathway, phase by phase

How an enterprise engagement moves from first contact to running in production. Each phase has a clear exit before the next begins, so budget and risk stay controlled.

01

Scoping & procurement

We agree the pilot’s goal, success criteria and commercials, and work through your procurement and vendor-onboarding process. Contract under Austrian law or your master agreement. The full legal and security detail lives in the [trust center](/trust-center/).

02

Governance setup

We agree who owns decisions, how often we report, and what a green, amber or red status means. You get a named contact, not a queue, and a cadence your steering group can rely on.

03

Pilot

A tightly scoped build that proves the risky part first. Weekly demos against the criteria we set, so there are no surprises at the end and the go or no-go decision is evidence-based.

04

Acceptance & documentation

We validate the pilot against the acceptance criteria agreed up front, then hand over architecture, setup, deploy and rollback documentation so your team can assess it independently.

05

Production & handover

Once accepted, the pilot graduates to production. Code lives in your repository, credentials are rotated to you, and runbooks make operations yours, not ours.

06

Continuity & support

Ongoing support runs on a retainer with a defined weekly commitment you can cancel without notice, or you run it entirely in-house. Either way, the handover means you are never locked in.

// 02

## What enterprise buyers need to see

The concerns a large organization raises that a founder-to-founder pitch skips. Straight answers on each, with the documented detail one click away in the [trust center](/trust-center/).

Procurement & contracting

You contract with Wavect GmbH, a registered Austrian company, under Austrian law or your own master agreement. Fixed price on a Werkvertrag for scoped work, or a cancellable retainer for ongoing delivery. Full entity, jurisdiction and IP-ownership detail is in the [trust center](/trust-center/).

Governance & reporting

We agree a decision-making structure and a reporting cadence before work starts: who signs off, how status is communicated, and what triggers escalation. Your steering group gets a consistent picture, not a black box.

Security & data

EU data residency by default, a signed data-processing agreement, least-privilege access you can revoke, and a documented subprocessor list. We are also honest about the ceiling: no ISO 27001 or SOC 2 certification today. The [trust center](/trust-center/) sets out exactly what we do and do not hold.

Stakeholder alignment

Enterprise builds succeed or fail on the people around them. We map the stakeholders early, keep the ones who matter informed at the right altitude, and translate between the business and engineering so decisions do not stall.

Integration with internal teams

We work inside your repositories, tooling and workflows rather than beside them, pair with your engineers where it helps, and leave your team able to own the code. The goal is a build your people can run, not a dependency on us.

Acceptance & documentation

Acceptance criteria are agreed before the build, not argued after it. On delivery you get architecture overviews, setup and deploy steps, rollback procedures and runbooks, documented in your repository so acceptance is an independent check, not a leap of faith.

Business continuity

Two founders on every engagement plus a vetted bench mean no single point of failure, and a complete handover means the software keeps running whether or not we do. Backup and recovery are designed into the build and owned by you afterwards.

Pilot-to-production transition

The pilot is built to graduate, not to be thrown away: production-grade choices from the start, a clear acceptance gate, and a handover that turns a proof into a system your team operates. No rebuild tax to go live.

// 03

## Enterprise-grade work we have shipped

Institutional and enterprise builds, delivered and handed over.

### [Bond Analytics Platform](/case-studies/bond-analytics/)
- **Status:** Live
- **Outcome:** 2 months - 0 to Enterprise
- **Summary:** Institutional bond analytics platform, zero to enterprise-ready in 2 months; raised multiple rounds.
- **Stack:** NestJS, React, Typescript

### [Polity](/case-studies/polity/)
- **Status:** Live
- **Outcome:** 7 services - Unified Testing
- **Summary:** 1.5 years owning QA across seven services and multiple vendors. Quality stayed shippable through every refactor.
- **Stack:** React, Java/Kotlin, Go

### [IKB](/case-studies/ikb/)
- **Status:** Live
- **Outcome:** Complete - Platform Handover
- **Summary:** Smart City IoT for Innsbruck: extended and scaled the LoRaWAN infrastructure, evaluated and integrated multi-vendor devices, wrote …
- **Stack:** Kubernetes, LoRaWAN, Docker

These are selected projects, not our full portfolio. We have shipped 75+ products since 2018.

// 04

## Keep reading

### [Trust center: procurement & security detail](/trust-center/)

### [Fixed price vs time and materials](/software-development-guide/fixed-price-vs-time-and-materials/)

### [What a discovery phase is](/software-development-guide/what-is-a-discovery-phase/)

### [Software development](/services/software-development/)

### [QA & testing](/services/software-quality-assurance/)

## Enterprise engagement, common questions

### Do we have to commit to a full program up front?

No. We start with a scoped pilot that proves the risky part and gives you an evidence-based go or no-go decision. Only once it passes the acceptance criteria we agreed does it graduate to production. You control budget and risk at each phase.

### How do you handle our procurement and security review?

We work through your vendor-onboarding, procurement and security-questionnaire process, sign your data-processing agreement, and contract under Austrian law or your own master agreement. Every fact a review asks for, legal entity, IP ownership, subprocessors, access control, is laid out on our [trust center](/trust-center/).

### How do you integrate with our internal engineering team?

We work inside your repositories, tooling and workflows, pair with your engineers where it helps, and document as we go. The aim is a build your team can own and run, not a dependency on us. At handover, everything transfers cleanly.

### How is acceptance handled?

Acceptance criteria are agreed before the build begins, and we demo against them weekly so there are no surprises. On delivery you get the documentation to validate the work independently: architecture, setup, deploy, rollback and runbooks, all in your repository.

### What happens to business continuity if a key person leaves?

Two founders sit on every engagement and a vetted bench backs them up, so no single person is a point of failure. A complete handover, with code in your repository and credentials rotated to you, means the software keeps running regardless. See the continuity detail on the [trust center](/trust-center/).

### Do you hold ISO 27001 or SOC 2?

Not today, and we will not claim otherwise. What protects an enterprise buyer instead is structural: a scoped pilot before commitment, your code in your repository from day one, a complete handover, and a contract under Austrian law. If a certification is a hard gate, tell us early and we will be straight about whether we can meet it. Full detail is on the [trust center](/trust-center/).

Last reviewed: 2026-07-10 by [Christof Jori](/team/christof-jori/) [wiki ↗](https://www.wikidata.org/wiki/Q139796367)

## Structured Data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@id": "https://wavect.io/#organization",
      "@type": [
        "Organization",
        "ProfessionalService",
        "LocalBusiness"
      ],
      "employee": [
        {
          "@id": "https://wavect.io/team/kevin-riedl/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Kevin Riedl",
          "url": "https://wavect.io/team/kevin-riedl/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        },
        {
          "@id": "https://wavect.io/team/christof-jori/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Christof Jori",
          "url": "https://wavect.io/team/christof-jori/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        }
      ],
      "founder": [
        {
          "@id": "https://wavect.io/team/kevin-riedl/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Kevin Riedl",
          "url": "https://wavect.io/team/kevin-riedl/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        },
        {
          "@id": "https://wavect.io/team/christof-jori/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Christof Jori",
          "url": "https://wavect.io/team/christof-jori/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        }
      ],
      "legalRepresentative": [
        {
          "@id": "https://wavect.io/team/kevin-riedl/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Kevin Riedl",
          "url": "https://wavect.io/team/kevin-riedl/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        },
        {
          "@id": "https://wavect.io/team/christof-jori/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Christof Jori",
          "url": "https://wavect.io/team/christof-jori/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        }
      ],
      "name": "Wavect GmbH",
      "subjectOf": {
        "@id": "https://wavect.io/verified-claims.json#dataset",
        "@type": "Dataset",
        "creator": {
          "@id": "https://wavect.io/#organization",
          "@type": [
            "Organization",
            "ProfessionalService",
            "LocalBusiness"
          ]
        },
        "description": "A machine-readable registry of quantitative and qualitative claims published by Wavect, with review dates, localized page appearances and public third-party citations where available.",
        "inLanguage": "en",
        "isAccessibleForFree": true,
        "license": "https://creativecommons.org/licenses/by/4.0/",
        "name": "Wavect verified publication claims",
        "url": "https://wavect.io/verified-claims.json"
      },
      "url": "https://wavect.io/"
    },
    {
      "@id": "https://wavect.io/team/kevin-riedl/#person",
      "@type": "Person",
      "jobTitle": "Managing Director",
      "name": "Kevin Riedl",
      "sameAs": [
        "https://www.wikidata.org/wiki/Q139796365",
        "https://www.linkedin.com/in/wsdt",
        "https://github.com/wsdt"
      ],
      "url": "https://wavect.io/team/kevin-riedl/",
      "worksFor": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      }
    },
    {
      "@id": "https://wavect.io/team/christof-jori/#person",
      "@type": "Person",
      "jobTitle": "Managing Director",
      "name": "Christof Jori",
      "sameAs": [
        "https://www.wikidata.org/wiki/Q139796367",
        "https://www.linkedin.com/in/jocr77/",
        "https://github.com/jo-chris"
      ],
      "url": "https://wavect.io/team/christof-jori/",
      "worksFor": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      }
    },
    {
      "@id": "https://wavect.io/#website",
      "@type": "WebSite",
      "inLanguage": [
        "en",
        "de",
        "es",
        "zh"
      ],
      "name": "Wavect",
      "potentialAction": {
        "@type": "SearchAction",
        "query-input": "required name=search_term_string",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://wavect.io/search/?q={search_term_string}"
        }
      },
      "publisher": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      },
      "url": "https://wavect.io/"
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@id": "https://wavect.io/enterprise/#webpage",
      "@type": "WebPage",
      "about": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      },
      "author": {
        "@id": "https://wavect.io/team/kevin-riedl/#person",
        "@type": "Person",
        "name": "Kevin Riedl",
        "url": "https://wavect.io/team/kevin-riedl/"
      },
      "dateModified": "2026-07-10",
      "description": "A buying pathway built for enterprise: procurement and governance, security review, stakeholder alignment, integration with your internal teams, formal acceptance and documentation, business continuity, and a pilot that graduates to production.",
      "headline": "Prove it in a pilot before you commit to production",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://wavect.io/#website",
        "@type": "WebSite"
      },
      "lastReviewed": "2026-07-10",
      "name": "Prove it in a pilot before you commit to production",
      "reviewedBy": {
        "@id": "https://wavect.io/team/christof-jori/#person",
        "@type": "Person",
        "name": "Christof Jori",
        "url": "https://wavect.io/team/christof-jori/"
      },
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          ".sp-hero__h1--xl",
          ".sp-hero__lead"
        ]
      },
      "url": "https://wavect.io/enterprise/"
    },
    {
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "item": "https://wavect.io/",
          "name": "Home",
          "position": 1
        },
        {
          "@type": "ListItem",
          "item": "https://wavect.io/enterprise/",
          "name": "Enterprise",
          "position": 2
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. We start with a scoped pilot that proves the risky part and gives you an evidence-based go or no-go decision. Only once it passes the acceptance criteria we agreed does it graduate to production. You control budget and risk at each phase."
      },
      "name": "Do we have to commit to a full program up front?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "We work through your vendor-onboarding, procurement and security-questionnaire process, sign your data-processing agreement, and contract under Austrian law or your own master agreement. Every fact a review asks for, legal entity, IP ownership, subprocessors, access control, is laid out on our trust center."
      },
      "name": "How do you handle our procurement and security review?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "We work inside your repositories, tooling and workflows, pair with your engineers where it helps, and document as we go. The aim is a build your team can own and run, not a dependency on us. At handover, everything transfers cleanly."
      },
      "name": "How do you integrate with our internal engineering team?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Acceptance criteria are agreed before the build begins, and we demo against them weekly so there are no surprises. On delivery you get the documentation to validate the work independently: architecture, setup, deploy, rollback and runbooks, all in your repository."
      },
      "name": "How is acceptance handled?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Two founders sit on every engagement and a vetted bench backs them up, so no single person is a point of failure. A complete handover, with code in your repository and credentials rotated to you, means the software keeps running regardless. See the continuity detail on the trust center."
      },
      "name": "What happens to business continuity if a key person leaves?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Not today, and we will not claim otherwise. What protects an enterprise buyer instead is structural: a scoped pilot before commitment, your code in your repository from day one, a complete handover, and a contract under Austrian law. If a certification is a hard gate, tell us early and we will be straight about whether we can meet it. Full detail is on the trust center."
      },
      "name": "Do you hold ISO 27001 or SOC 2?"
    }
  ],
  "speakable": {
    "@type": "SpeakableSpecification",
    "cssSelector": [
      ".faq-question",
      ".faq-answer"
    ]
  }
}
```
