Some companies need a CTO's decisions long before they can justify a CTO's salary. Others have the engineering team and need an experienced pair of eyes on the architecture, the cloud bill, or the security questions their largest customer has started asking. We do that work for companies in Dubai, across the Emirates and the wider GCC, and for European companies whose expansion here has just made their systems someone's problem.
Engineering sits in Bordeaux. Albina Lanina is our contact in Dubai. We are here on visits through the year, and the work in between is remote by design rather than by compromise.
Hugo co-founded Side, the French temporary-work platform, and saw it through from early fundraising to its sale. Its whole job was turning staffing paperwork into software that ran itself. Julien was Side's first employee and became its CTO.
Our own operations run on software we built: a CRM, a couple of hundred tools behind a single MCP server, and the data pipelines that feed them. The advice comes from operating, not from a framework.
The same team that reviews the architecture can implement the roadmap. Most of our advisory work turns into build work, and when it should not, we say so.
We do not have a Dubai office and we are not going to describe a contact as one. If daily on-site presence is a requirement for you, an established local firm is the better choice.
Three situations, in the order they usually reach us.
You have a product that works in Europe and a customer, an investor or a partner in the Gulf. Now someone has to answer where the data will live, whether the platform can run two regions without doubling the bill, and what happens to your security posture when the first enterprise questionnaire arrives in a different regulatory vocabulary. We have made those calls before, from the European side, which is the side your engineering team thinks in.
The product found its market and the architecture did not follow. The symptoms are consistent: a cloud bill growing faster than revenue, deploys that have become events, a security review blocking a large deal, and an engineering team that is busy without being fast. None of these is fixed by hiring more developers, which is usually what has already been tried.
There is a technical team, or an agency, and nobody senior enough to say no. Roadmaps get built from whoever asked last. A fractional arrangement puts an experienced technologist in the decisions that are expensive to reverse, at a fraction of the cost and none of the recruitment risk.
Six problems, described the way they actually present rather than the way a service catalogue would name them.
Usually three or four causes, not thirty: over-provisioned always-on capacity, egress nobody costed, a database sized for a spike that ended, and environments that were never turned off. Finding them takes days, not a transformation programme.
An enterprise buyer sent a questionnaire and the honest answers are not the ones you want to give. The work is to fix what genuinely matters, write down the rest accurately, and stop the same document blocking the next three deals. This is readiness work. It is not certification and it is not a penetration test, though we will tell you when you need either.
The design that carried you to product-market fit is now the reason every change is slow. The answer is rarely a rewrite. It is usually finding the two or three seams worth cutting first.
Velocity is a symptom. The cause is normally somewhere in branching, environments, test coverage, review latency, or an absent decision-maker, and it is measurable rather than a matter of opinion.
Staff are pasting customer data into tools nobody approved, suppliers are shipping AI features whose data handling is undocumented, and there is no baseline for what is allowed. A workable policy for a company with no in-house legal function is a short document and a small number of enforced controls, not a framework.
An investor wants to know what they are underwriting. A founder wants to know what will surface before it surfaces. Technical due diligence, from people who have been on both sides of it.
If your problem is that the software works and nobody left can change it safely, that is a different service with a fixed price. Code audit and project takeover
Delivery is remote-first, and that is a design decision rather than a concession. Bordeaux is two to three hours behind Dubai, so there is a genuinely shared working day: you are not waiting overnight for an answer, and there is no window where the people advising you are asleep while you are at your desk. Compared with a supplier operating eight or ten hours away, that difference shows up daily.
On-site time is scheduled rather than continuous. We are in Dubai several times a year and we publish the dates. Visits are for the things that genuinely work better in a room: leadership sessions, architecture workshops with the whole engineering team, findings presentations, and the conversations that decide whether a piece of work happens at all. Between visits the work runs on a weekly rhythm, and nothing waits for a plane.
Contracts, invoicing in dirhams and keeping data in a UAE or Gulf region can all be arranged. Ask at scoping and we will be specific about your case rather than vague about it.
To be straightforward: we are building this practice in the UAE, not harvesting an established one. That means you get direct access to senior people and genuine attention, and it means we do not yet have a long list of UAE references. Both are true and you should weigh both.
Every engagement starts as one of these three. The call decides which, and sometimes decides none of them.
A fixed-scope senior assessment of your architecture, cloud platform, security posture, delivery model and AI exposure, ending in a prioritised roadmap rather than a report that gets filed. The usual first engagement, and the one to choose if you want to know what you are dealing with before committing to anything longer.
How the sprint worksOngoing senior technology leadership, typically one to three days a month, owning the decisions rather than the tickets. For founders without a technical co-founder, and for companies between CTOs.
How a fractional mandate worksA focused engagement for a European software company with a customer, investor or partner in the Gulf. We work through what the expansion actually demands of your platform: data residency and what it costs you architecturally, multi-region without doubling the bill, security posture translated into what enterprise buyers here expect to see, the operational model across two time zones, and which of it is genuinely required now rather than later. Usually runs as a sprint with the GCC workstream in place of one of the standard ones.
Talk it throughYou describe the situation. We tell you which of the three is the right shape, or that none of them is. No deck, and no discovery process to buy.
Usually one further conversation and access to whatever already exists: an architecture diagram, a cloud bill, a security questionnaire, a board pack. Enough to fix the scope honestly.
What is included, what is not, what we need from you, and the dates. Priced after scoping, because pricing before it would be a guess with a number attached.
Remote-first, with a live findings session, on site if it coincides with a visit.
Some engagements end there, with a roadmap your own team executes. Others continue as a fractional mandate or a build. We will tell you which we think it is, including when it is the first one.
No. Albina Lanina is our contact in the UAE and is based in Dubai. The engineering team is in Bordeaux, France. We are in Dubai on scheduled visits through the year and we publish the dates. For most advisory work that is the right shape: the decisions happen in a weekly rhythm and the workshops happen in a room. If your mandate genuinely needs someone in the building most weeks, say so on the call and we will tell you honestly whether we can serve it.
Owns the technical decisions that are expensive to reverse: architecture, platform and spend, the hiring bar, security posture, supplier choices, and what does not get built. Not a developer with a title, and not a project manager for your agency.
Sprints are fixed-scope and priced after a short scoping conversation, because the honest range depends on how many systems are in play. Fractional mandates are priced per day against an agreed monthly cadence. We publish real numbers where we can: our AED build bands and the fixed-price code audit are both on their pages rather than behind a form.
Yes to both. Data can be kept in a UAE or Gulf region. It is a hosting configuration rather than a special arrangement, so ask at scoping and we will confirm it for your case.
No. We assess security posture and readiness, and prepare you for the reviews and questionnaires enterprise buyers send. Formal certification and penetration testing are separate, specialist engagements, and we will tell you when you need one and what it involves rather than quietly doing something adjacent.
No, and we will not pretend otherwise. We advise on technology. For licensing, structuring, tax and immigration you need local professional advisers, and we are happy to say so early rather than late.
Often more useful. Reviews land better with a team than without one, because the people who know where the problems are get to say so to someone senior and external. We work with your engineers, not around them.
Then take the thirty minutes anyway. A good outcome of that call is sometimes a suggestion and no engagement.
Thirty minutes, no deck. Describe the situation and the systems already in place, and we will tell you which of the three engagements fits, what it would involve, and when the answer is that you do not need us at all.
