Strategy is a slide until someone builds it. We design the system — and build it too.
Onyx Grid delivers architecture-led engineering for the systems regulated enterprises can't afford to get wrong — cloud platforms, agentic AI, and Zero Trust security, built by engineers who've owned production at scale.
Onyx Grid SIA · Riga, Latvia · EU-wide engagements · Senior engineers only
# architecture-manifest.yaml — every engagement, from the first commit schemaVersion: 1 principles: security: designed-in # Zero Trust, not a review gate cloud_cost: owned # the year-two bill, not the demo ai: governed # auditable, human-in-the-loop delivery: architects_write_code: true junior_bench: none handoff_and_disappear: false
Most software problems aren't technical — they're architectural
Teams don't fail because they lack good engineers. They fail because nobody owns the system end to end — and the industry numbers show it.
Fragmented Ownership
Digital transformations fail to deliver expected outcomes — cloud, security, and AI run as separate workstreams with separate vendors, and nobody is accountable for how they fit together.
Stalled AI Adoption
Of AI projects will be abandoned through 2026 for lack of AI-ready data and implementation strategy. Pilots pile up; few reach production because nobody designed for reliability, cost, and governance from day one.
Security Bolted On Late
Average cost of a data breach. Security and compliance treated as a review gate at the end — not a design constraint from the start — is expensive to fix and easy to avoid.
Cloud Spend Without Cloud Discipline
Of cloud spend is reported as waste. Migrations ship, but nobody owns cost, right-sizing, or architecture evolution afterward — the bill quietly grows every quarter.
“The person who designs the system should be able to build it too.”— The principle Onyx Grid is built on
From cloud foundations to agentic systems — one team, one architecture
Four disciplines that are usually kept in separate silos, because in practice they're one problem. We embed as architects and engineers — not as a slide deck, not as a subcontracted team you never meet.
Cloud & Platform Engineering
Azure and AWS architecture, Kubernetes, event-driven systems, FinOps discipline — cost review, right-sizing, reserved capacity. We design for the bill you'll get in year two, not just the demo.
AI & Agentic Systems
Production-grade LLM integration: RAG pipelines, MCP-based agent architectures, local and API-based model strategy, human-in-the-loop design. We ship agents that are governed, not just clever.
Security-First Architecture
Zero Trust by default — mTLS, OAuth2/OIDC, IAM, policy enforcement, defence-in-depth. Security as an architectural property, not a checklist at the end.
Computer Vision & Edge AI
Model training through quantization and edge deployment — real-time inference on constrained hardware, not just cloud GPU demos.
From assessment to long-term ownership
Four stages, one continuous relationship. We rarely hand off and disappear — most engagements evolve from assessment into embedded delivery.
Discovery & Assessment
- Architecture and codebase review
- Feasibility analysis of target state
- Risk and cost modelling
- Incident history and operational reality — before proposing change
Embedded Architecture
- Solution architecture owned end-to-end
- ADRs and governance that scale with the team
- Reference implementations, not just diagrams
- Direct work with your engineers, not around them
Build & Ship
- Production-grade PoCs and MVPs
- Security and cost built in from the first commit
- CI/CD, observability, and operational readiness
- Hands-on delivery, senior engineers only
Ongoing Partnership
- Architecture review cadence
- Technical advisory as your platform evolves
- Available for the next hard problem, not just the last one
Built for teams who've been burned by "strategy without delivery"
| Capability | Typical Vendor | Onyx Grid |
|---|---|---|
| Who designs vs. who builds | Separate teams, separate accountability | Same architects write the code |
| AI delivery | Slide decks and demos | Production PoCs, governed and shippable |
| Security | Reviewed at the end | Designed in from day one |
| Cloud cost | Someone else's problem post-launch | FinOps owned as part of the architecture |
| Engagement model | Fixed scope, then gone | Embedded, evolves with the platform |
| Domain fluency | Generalist consultants | 25+ years in regulated, high-stakes systems |
Systems we've owned, not just advised on
Validated delivery — anonymised where engagements are under NDA, verifiable via LinkedIn.
Led cloud migration architecture for leading European and Latvian financial institutions — spanning 50+ services across multiple geographic regions in highly regulated environments.
Designed and delivered Zero Trust security architecture — identity, mTLS, policy enforcement — for critical financial market infrastructure.
Architected a low-latency trading platform matching engine that attracted direct investment from a major European stock exchange group.
Led engineering organisations of up to 65 people through cloud and microservices transformation for a Baltic banking group.
Delivered production AI/ML pipelines — from dataset through fine-tuning, quantization, and edge deployment.
ZTeasy — Zero Trust for AI agents and internal APIs
We're building a production system that solves a problem most companies haven't hit yet: how do you let AI agents call internal systems without breaking your trust model?
ZTeasy is a Zero Trust policy gateway that authenticates and authorises AI agents exactly like any human or service caller — no shortcut tokens, no backdoor access. Policy-driven, fully auditable, built for regulated environments where "the model did it" is not an acceptable answer to a compliance question.
The open-source reference implementation is free to use. Hardened, extended versions are built for clients with specific compliance and scale requirements — get in touch if this is a problem you're facing.
# zte-policies.yaml — agents get exactly what policy allows agentMcpToolCalls: - id: agent-support-read-only effect: ALLOW source: client:support-agent target: crm.get_customer - id: agent-support-no-delete effect: DENY target: crm.delete_* # deny always wins — no match, no exception
Where architecture discipline matters most
Financial Services
Banking, capital markets, insurance, payments — systems where downtime and security failures have regulatory consequences, not just reputational ones. Our home turf for 25+ years.
Regulated Enterprise
Any organisation where compliance, auditability, and data governance shape the architecture, not just the paperwork.
Scaling Tech Companies
Teams that have outgrown their early architecture and need it rebuilt without stopping the business.
Senior-led. AI-augmented.
Onyx Grid is a small, deliberately senior practice — the principal architect leads every engagement directly, amplified by AI tooling and a trusted network of specialist engineers.
Principal on every engagement
Architecture is led directly by the founder — no account managers between you and the person doing the work, no hidden subcontracting chain.
AI-augmented delivery
AI agents handle research, analysis, code scaffolding, and documentation — under senior review, every time. The throughput of a team, the judgment of a principal.
Trusted specialist network
Vetted senior engineers brought in per engagement when scale demands it — under direct supervision. No junior bench, ever.
Dmitrijs
Solution Architect & Founder25+ years delivering complex distributed systems in regulated environments — capital markets, banking, and insurance. Owns architecture end-to-end: from discovery and design through production-grade PoCs, governance, and delivery — hands-on, leading by example.
Let's talk about the system you're trying to fix
Whether it's a stalled AI initiative, a cloud migration that's lost its architecture, or a security posture that needs to be designed in rather than bolted on — we start with a conversation, not a proposal template.