# Credits

Almost everything here was made by other people and given away. This page names
it, because a consultancy that will not say what it runs is asking for a trust
it has not offered.

It is also the shortest honest answer to "what do you actually work with". The
list below is not a capability brochure — it is this site's own bill of
materials, and you can check every line of it from your own browser.

## What reaches your browser

Five things, and nothing else: HTML, one stylesheet, two webfonts, images, and
one small script of our own.

- **HTML**, written out in full before you asked for it. Every page is a file on
  disk, not a template assembled per request.
- **One CSS bundle**, concatenated and fingerprinted at build time and served
  with a Subresource Integrity hash, so your browser can verify it arrived
  unmodified. Inside it rides
  [neat-annotations](https://github.com/syabro/neat-annotations) by Max Syabro
  (MIT) — the hand-drawn arrows and margin notes, drawn in CSS alone.
- **The Ubuntu typeface**, by Dalton Maag for Canonical, under the Ubuntu Font
  Licence. Served from our own machine — a webfont from someone else's CDN is a
  third party watching you read.
- **The Shantell Sans typeface**, based on the artist Shantell Martin's
  felt-marker handwriting, by
  [Arrow Type](https://github.com/arrowtype/shantell-sans) / Stephen Nixon,
  under the SIL Open Font License. It writes the margin notes, is served the
  same way, and loads only on the pages that carry one.
- **WebP and PNG images**, sized at build time. The walls these pages are built
  on are photographs. Two are from [Unsplash](https://unsplash.com/license):
  [Tim Mossholder](https://unsplash.com/@timmossholder) shot the dark plaster,
  [Joe Woods](https://unsplash.com/@woods) the white brick. Three more are
  **John Snow's**, shot on a Galaxy S22 Ultra and given to this site: the pale
  plaster, the painted brick and the tiled wall. The light theme wears one of
  its four walls, drawn while the page is built, so the site is dressed afresh
  each time it is published. The licence does not ask for a credit; a page that
  names a typeface's designer should not need asking. The mark, the cog, the
  mascot in every pose you will meet it in, the portrait and the two
  overlapped photographs of our own Copenhagen office on the about page are
  ours, shot or drawn here and stripped of their metadata before they were
  committed.
- **One borrowed icon.** The Mastodon mark in the colophon comes from
  [Font Awesome Free](https://fontawesome.com/) by Fonticons, under
  [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Every other mark
  here was drawn for this site, and this one is the exception deliberately: a
  brand mark stands for somebody else's service, so an approximation redrawn to
  match our own set would be worse than an exact borrowed one. The credit sits
  on this page rather than in the file, because the build minifies its HTML and
  strips the comment the icon ships its attribution in.

One script runs on this site: ours, about a kilobyte, on the portfolio page
only, where it filters the list as you type. It talks to nobody and remembers
nothing. No cookies are set. Nothing is requested from
another company's server — no analytics, no fonts, no embedded video, no
consent banner, because there is nothing to consent to. Open your browser's
network panel and count the hosts: there is one.

## How the pages are made

- **[Hugo](https://gohugo.io/)** — the static site generator, written in Go.
  Templates, taxonomies, every language and the feeds are its work.
- **Markdown and Go templates** for the hand-written pages and the layouts.
- **[SQLite](https://sqlite.org/)** — the portfolio is not authored here. It
  lives in a multilingual CV database and is exported into this site by a Python
  script, so a fact is written once and appears wherever it belongs.
- **[Python](https://www.python.org/)** for that exporter, and for generating
  the icon set with **[ImageMagick](https://imagemagick.org/)** from a single
  drawing of the mark.

## How it is proved

There is no hosted build service; the quality gate runs on the machine the site
is written on, and every diagnostic is an error rather than a warning.

- **[vnu](https://validator.github.io/validator/)** validates the HTML,
  **[Stylelint](https://stylelint.io/)** the CSS.
- **[axe-core](https://github.com/dequelabs/axe-core)** audits every built page
  against WCAG 2.2 A and AA, in both colour schemes, and it is in the gate — not
  beside it.
- **[Puppeteer](https://pptr.dev/)** drives headless Chromium for the checks a
  validator cannot make: measured contrast, focus order, target size, reading
  measure, viewport overflow, print pagination, and a pixel-for-pixel visual
  regression via **[pixelmatch](https://github.com/mapbox/pixelmatch)**. It also
  takes the picture other sites show when a link here is shared, so that card is
  this page's own stylesheet and typeface rather than a drawing of them.
- **[Lighthouse](https://developer.chrome.com/docs/lighthouse/)** holds the
  performance budgets; **[lychee](https://lychee.cli.rs/)** checks that every
  link still resolves.
- **[Prettier](https://prettier.io/)**,
  **[markdownlint](https://github.com/DavidAnson/markdownlint)**,
  **[ESLint](https://eslint.org/)**,
  **[Ruff](https://docs.astral.sh/ruff/)**,
  **[basedpyright](https://docs.basedpyright.com/)**,
  **[yamllint](https://www.yamllint.com/)**,
  **[ShellCheck](https://www.shellcheck.net/)** and
  **[codespell](https://github.com/codespell-project/codespell)** keep the
  source honest; **[gitleaks](https://gitleaks.io/)** makes sure no secret is
  ever committed.
- **[Task](https://taskfile.dev/)** runs all of it under one name per job, and
  **[pre-commit](https://pre-commit.com/)** runs the file-level half again on
  every commit, so the gate is not something anyone has to remember.

## Where it runs

One small machine does all of it: a single-core
**[DigitalOcean](https://www.digitalocean.com/)** server with 512 MB of memory
and a 10 GB disk, standing in **Toronto, Canada**, answering at
**165.227.39.206**. That address is what DNS already hands to anyone who asks,
so printing it here saves you the lookup rather than telling you anything new.
What the machine records while it answers is on the [privacy page](/privacy/).

- **[Debian](https://www.debian.org/)** is the operating system.
- **[Caddy](https://caddyserver.com/)** answers every web request and renews
  the HTTPS certificate itself, from
  **[Let's Encrypt](https://letsencrypt.org/)**.
- **[Agate](https://github.com/mbrubeck/agate)**,
  **[Gophernicus](https://github.com/gophernicus/gophernicus)** and
  **[Tor](https://www.torproject.org/)** answer the other three: this site is
  also a Gemini capsule at `gemini://engineer.company`, a Gopher hole at
  `gopher://engineer.company` and an onion service at
  `http://engineer2ezpeji52ipphljcflzyhetvy5r6tnqubtq45nzlxxv6rsqd.onion/`. All
  four read the same folder of files, so one deploy updates all four and none of
  them can drift from the others. The onion is the only front door we could add
  without opening a port: tor dials out to introduction points, so the machine's
  open ports stay exactly as they were. The web site sends an `Onion-Location`
  header too, so Tor Browser offers it without being asked. It begins `engineer`
  because we spent the CPU hours to make it readable — a convenience, not a
  proof. The same prefix is available to anyone willing to spend the same hours,
  so compare the whole address rather than the start of it.
- **[Ansible](https://www.ansible.com/)** describes that server as code, so it
  can be rebuilt rather than remembered.
- **[Soft Serve](https://github.com/charmbracelet/soft-serve)** is the git
  server behind the Git Hub at
  [git.engineer.company](https://git.engineer.company/). This site's own source
  lives there.
- **[restic](https://restic.net/)** takes the backups off the box.
- **[Cloudflare](https://www.cloudflare.com/)** answers DNS — and only DNS. The
  site is deliberately not proxied: openness is worth more to us than the
  protection, and a proxy would put one more company between you and us.
- Mail is **[Apple iCloud](https://www.icloud.com/)**, which is why the address
  on the contact page reaches a mailbox and not a marketing platform.

## Standards it follows

- **[WCAG 2.2](https://www.w3.org/TR/WCAG22/) level AA**, guarded rather than
  claimed.
- **[schema.org](https://schema.org/)** structured data, marking only what is
  true and visible on the page.
- **[Web App Manifest](https://www.w3.org/TR/appmanifest/)**, so the site can be
  [installed as an app](/install/).
- **[RSS](/index.xml)**, **[Atom](/atom.xml)** and **[JSON Feed](/feed.json)**,
  all three carrying the full text. Two XML feeds rather than one because some
  readers take only one of the two and neither is reliably the one.
- **[RFC 9309](https://www.rfc-editor.org/rfc/rfc9309)**
  [`robots.txt`](/robots.txt), which allows everything, to search crawlers and
  AI systems alike — the writing here exists to be read, and it names the
  [sitemap](/sitemap.xml) both of them follow. There is a
  [readable index](/sitemap/) of the same pages, for anyone who would rather
  browse it than parse it.
- **[RFC 9116](https://www.rfc-editor.org/rfc/rfc9116)**
  [`security.txt`](/.well-known/security.txt), plus
  [`humans.txt`](/humans.txt), [`llms.txt`](/llms.txt),
  [`agents.txt`](/agents.txt) and [`ai.txt`](/ai.txt) for the machines that come
  asking — and [`ads.txt`](/ads.txt), which authorises nobody, because there are
  no advertisements here to sell.
- **[Gemini](https://geminiprotocol.net/docs/specification.gmi)**,
  **[RFC 1436](https://www.rfc-editor.org/rfc/rfc1436) Gopher** and
  **[Tor onion services](https://community.torproject.org/onion-services/)**:
  the same pages, served over all three at `gemini://engineer.company`,
  `gopher://engineer.company` and
  `http://engineer2ezpeji52ipphljcflzyhetvy5r6tnqubtq45nzlxxv6rsqd.onion/`, out
  of the same folder of files this page comes from — one deploy updates all
  four. Gemini and Gopher each want their own client rather than a browser; the
  onion wants a Tor client, and Tor Browser is the ordinary one. Gopher has no
  encryption layer at all, so it carries which page you read in the clear;
  Gemini encrypts that, but the network you read from still sees which address
  you asked for. Over the onion it sees neither: of the four, that is true only
  there. The address itself is the service's public key, so the circuit is
  authenticated and encrypted before a word of HTTP is spoken — the `http://` is
  correct rather than careless, and a certificate would only prove a name the
  address already proves by arithmetic.

## Check it yourself

Everything above is a claim, and the section before it names the tools we run
against our own machine — which is us marking our own homework. These are the
same questions asked by people who have never heard of us. Every link runs a
live test against this page, or the address bar of the one you are on; none of
them takes our word for anything, and none of them is ours.

- **[The W3C Markup Validator](https://validator.w3.org/nu/?doc=https%3A%2F%2Fengineer.company%2F)**
  parses this page's HTML against the living standard. It is the same engine as
  the `vnu` above, run by the W3C rather than by us.
- **[The W3C CSS Validator](https://jigsaw.w3.org/css-validator/validator?uri=https%3A%2F%2Fengineer.company%2F&profile=css3svg)**
  reads the stylesheet this page is wearing. Expect it to report errors, and
  read them before believing them: as of August 2026 it validates against a
  profile that stops short of `system-ui`, `@property`, `clamp()` in a
  `font-size` and scroll-driven animations — all four shipped in browsers, and
  all four used here. Every one of its complaints is about a feature newer than
  the validator, which is why [Stylelint](https://stylelint.io/) is the
  authority we actually hold the stylesheet to.
- **[The W3C Feed Validator](https://validator.w3.org/feed/check.cgi?url=https%3A%2F%2Fengineer.company%2Fatom.xml)**
  checks the Atom feed, and
  [the same service](https://validator.w3.org/feed/check.cgi?url=https%3A%2F%2Fengineer.company%2Findex.xml)
  checks the RSS one. It warns that most entries share a modification date, and
  that warning is correct: the dates come from git history, and most of these
  pages genuinely were written in the same few commits. We would rather show a
  warning than invent a date.
- **[The JSON Feed Validator](https://validator.jsonfeed.org/?url=https%3A%2F%2Fengineer.company%2Ffeed.json)**
  checks the third feed, which the W3C service does not cover — it predates the
  format.
- **[PWABuilder](https://www.pwabuilder.com/reportcard?site=https%3A%2F%2Fengineer.company%2F)**
  reads the manifest and the rest of what makes the site
  [installable](/install/), from Microsoft's machines rather than ours.
- **[The W3C Internationalization Checker](https://validator.w3.org/i18n-checker/check?uri=https%3A%2F%2Fengineer.company%2F)**
  reads the language and encoding declarations that make the Danish and English
  versions of this site legible to the right reader.
- **[The Schema Markup Validator](https://validator.schema.org/#url=https%3A%2F%2Fengineer.company%2F)**
  reads the structured data, and
  **[Google's Rich Results Test](https://search.google.com/test/rich-results?url=https%3A%2F%2Fengineer.company%2F)**
  says what a search engine does with it.
- **[PageSpeed Insights](https://pagespeed.web.dev/analysis?url=https%3A%2F%2Fengineer.company%2F)**
  runs Lighthouse from Google's machines rather than ours — performance,
  accessibility, best practices and SEO, with real-world data where enough
  people have visited.
- **[The Mozilla HTTP Observatory](https://developer.mozilla.org/en-US/observatory/analyze?host=engineer.company)**
  grades the security headers, and
  **[Qualys SSL Labs](https://www.ssllabs.com/ssltest/analyze.html?d=engineer.company)**
  grades the HTTPS configuration behind them.
- **[Security Headers](https://securityheaders.com/?q=https%3A%2F%2Fengineer.company%2F&followRedirects=on)**
  is a second opinion on the first of those, from someone else entirely.

What none of them can check is the accessibility claim, and we would rather say
so than let a green badge imply otherwise. **No automated tool finds more than
about a third of WCAG failures** — the rest are judgements about whether a
heading describes its section or an alt text says the useful thing, and a
machine cannot make them. The audits above are the floor, not the proof. If you
use a screen reader here and something reads wrongly,
[tell us](/contact/) — that is the report we cannot generate.

## Thank you

Every project above is maintained by people who did not have to share any of
it. If you build on this stack too, that is where your money and your bug
reports are worth most.

And if this stack reads like your kind of engineering,
[put ours to work](/contact/) *(we assemble the same for clients)*.

<https://platform.engineer.company/credits/>
