Your people build the apps. You keep the rules.
Contember Fabrika is a platform your company builds its own apps on, and a team that stands behind it. The platform handles sign-in, permissions, keys and deployment, so the apps your people build with AI can't get around them. We review every change before it goes live. And all of it runs in a cloud account in your company's name.
One installation per company, shared with no one.
Apps have no public address. The only way in leads through the platform.
Nothing goes live without our review and a record of the deployment.
What the platform handles
These are the parts every app gets ready-made and can't switch off. Your person with AI builds the screens and the logic of the process. Everything below is outside their reach.
One installation per company
Each company gets its own installation of the platform. It runs with one provider, in an account we set up in your company's name: Cloudflare or Zerops, or AWS if you prefer.
A single gate
Apps have no public address of their own. Every request goes through one entry point that lets in only verified users. When the access rules are missing or unclear, the door stays shut.
Sign-in with your company account
People sign in through your identity provider, for example Google, Microsoft Entra or Okta, with one sign-in for all apps. Anyone without a company account can use a password, which no admin can set or read.
Roles and permissions
Permissions are set by role, separately for each app. An app declares which roles it knows; which person gets which one is up to you. A new version of the app won't overwrite the permissions you set.
App keys and passwords
The cloud provider holds the values, not our database. Each app sees only its own. Through the platform they can be written, but never read back.
Separate environments
Testing and production live in separate environments with their own network. Whatever you try in testing can't touch production data.
A record of what happened
Sign-ins and access changes go into an audit log you can see in the console. Every deployment has its own record with a log: which version, when, and how it went.
Errors and outages
Errors from all apps are collected in one place, grouped, and can be assigned and resolved. The platform checks that apps respond, and on a new error or a sudden spike it sends an alert.
How a change gets into production
Review isn't a script ticking boxes. It's our service: someone on our side goes through every change before it's deployed. Nothing reaches production any other way.
Your person builds
On their own computer, with AI, working from the brief and the code. The AI doesn't work with your live data.
The change goes to Git
Every change has an author, a time and a description. Nothing gets copied onto the server by hand.
We review it
Before deployment we go through what changed: permissions, handling of data, anything that could open a door that should stay shut.
Deployment and report
The version goes live and leaves a record. You get a report: what changed, what we checked and how it came out.
AI and your data
The first question we hear from IT is where the data goes when AI helps build the app. The answer is short: the AI works with the brief and the code, not with your production.
The AI builds, it doesn't operate
Your person builds with AI on their own computer, working from the brief and the code. The production database sits in a private network and the apps have no public address, so building the app never touches live data. The AI only gets data if someone deliberately gives it some.
Your own AI plan
AI always runs on your own plan with the provider you choose, under your terms. We're happy to advise on picking the provider.
No training on your data
We don't train anything on your data.
What you can rely on
What we commit to, in plain words. The exact wording of the commitments is in the contract.
Without a verified sign-in, nobody gets into the non-public parts of an app.
Permissions work the way they're set. Everyone sees only what their role allows.
We keep the platform patched, continuously and without you having to ask.
When something goes wrong, we help find out what happened in the app and with the reporting you're required to do.
What we don't vouch for
What a person does with data they have permission to see. If an employee with access to the records exports them and walks off with them, the platform won't stop that. Permissions can be set tightly, but deciding who gets which role stays with you.
Regulations
An app you build yourself falls under the same rules as software you buy. Meeting them is up to you. For the part that concerns the apps, we give you the groundwork.
As soon as an app processes personal data of employees or customers, GDPR applies to it: appropriate security, regular testing, and reporting a breach to the authority within 72 hours. Review of every change and the record of deployments are part of that security.
If you fall under the Czech Cyber Security Act (No. 264/2025 Coll.), even the lower regime requires security requirements for developing and maintaining your systems, and supplier contracts that cover change management, an exit strategy and secure development (Decree 410/2025 Coll., Section 3 and Annex 2). Application security and event logging are measures you either put in place or justify leaving out. An incident with significant impact is reported within 24 hours. We help with the part that concerns your apps.
In the financial sector, DORA requires review and testing before deployment, explicitly including apps built outside the IT department. That's exactly how changes get into production here.
This isn't legal advice. Whether and how a regulation applies to you is best assessed with your lawyer or auditor; we'll gladly give them the technical details.
Questions from a security questionnaire
Short answers to what IT usually asks. The full list of 44 questions is in the prefilled questionnaire, and we're happy to fill in your own too.
Where does the data live?
In your company's cloud account, with Cloudflare or Zerops, or AWS if you prefer. Each company has its own installation and shares it with no one. Zerops is a Czech company with a data centre in Prague. With Cloudflare, we go through the region and the terms against your requirements. On AWS, we pick the region to match them.
Who has access to production?
The people you grant it to, and us to the extent needed for review, deployment and patches. Sign-ins and access changes in the platform are recorded in a log you see in the console. Access to the cloud account itself stays under your control.
How do people sign in, and what about multi-factor authentication?
With their company account through your identity provider, for example Google, Microsoft Entra or Okta. Multi-factor authentication then works the way your company has it set up for that account. Anyone without a company account, an outside contractor for example, can use a password.
What about backups and recovery?
We set up backups and recovery with you, to the extent you need: what gets backed up, how often, how long it's kept and how quickly the data has to be back. It's our service, not something the platform does on its own, so we agree on the scope when we set up Fabrika.
What happens during an incident?
The platform collects errors and alerts on new ones or on a sudden spike. We help find out what happened in the app, fix it, and put together the documents for the report you have to file.
Which AI do you use?
The one you choose, on your own plan and under your terms. It works with the brief and the code, not with live data, and nothing is trained on your data.
Who are your subcontractors?
For Fabrika you have one supplier: us. The cloud account with Cloudflare, Zerops or AWS is registered to your company, so you have that relationship directly. The AI runs on your own plan. We don't resell you either of them.
What if we part ways?
The apps' code is yours, the data and the domains are in your account. The system keeps running without us, and the next person picks it up from Git.
Go through it with our engineer.
Half an hour for your IT: where it runs, how sign-in and permissions work, how a change gets into production. Bring your questions or your security questionnaire.