Skip to content
How we work

What actually happensafter you sign.

Ten stages, in this order, every time. Each one names who does the work and what you are holding when it closes — because the useful question is not how we describe our process, it is what you end up with and when.

Your journey with us begins with a shared understanding of your vision.

Five members of the iLeaf team in a stand-up around the table in the Kochi office, with a To Do / In Progress / Done board behind them
Not a diagram of the process — the process. A stand-up in the Kochi office, work on the board behind them in the three states it is ever in.

A ten-stage walkthrough · narrated

How iLeaf looks afterthe people who hire it.

Ten stages, in this order, every time — what happens at each one, who does it, and what you are holding when it closes.

About four minutes, with sound.
Four colleagues around a meeting-room table with a tablet and notes, mid-discussion

Every stage, in writing

The same ten stages, if you would rather read than watch.

01Requirement gatheringYou talk and we listen properly. Nothing is estimated, and nothing is promised, until we both agree what you actually need.
  • Understand the business goals behind the request, not just the request
  • Capture scope, goals, timelines, milestones and dependencies in a BRD
  • Identify risks and resourcing early, while they are still cheap
  • Agree how we will communicate, and confirm confidentiality under NDA

Who

Business analysts, business development, your stakeholders

What you hold

A business requirements document you have read and agreed.

02Analysis and specificationYour idea becomes a specification precise enough to build from, and you approve it before a single line of code is written.
  • Break high-level requirements into functional and non-functional specs
  • Translate your objectives into measurable deliverables
  • Propose mitigation for the risks found in stage one
  • Finalise and approve the SRS together

Who

Business analysts, technical leads

What you hold

An approved software requirements specification.

03Proposal and approvalYou get a proposal shaped to your requirement, priced openly, alongside the comparable work that shows we have done this before.
  • Present a solution shaped to your requirements, not a template
  • Show the relevant work — comparable projects, not a capability list
  • Define scope, deliverables, milestones, timelines and payment structure
  • Take your feedback into the proposal iteratively until it is right

Who

Business development, business analysts, your stakeholders

What you hold

An approved proposal with scope, timelines and costs.

04Project planningYou get named owners, dated milestones and measurable targets, so at any point you know exactly who is doing what, and by when.
  • Build a roadmap with milestones, deliverables and measurable KPIs
  • Assign roles and responsibilities by name
  • Allocate the people and infrastructure the plan actually requires
  • Set up Agile sprints or waterfall phases, whichever the work suits

Who

Project managers, technical leads, development team

What you hold

A project plan with named owners and clear milestones.

05System designYou see it before it is built. Architecture, wireframes and working prototypes, with security designed in from the start rather than added later.
  • Design the technical and architectural workflow
  • Produce wireframes, mockups and prototypes of the interface
  • Choose a stack for scalability, performance and security
  • Build in JWT and OAuth authentication by default, not later

Who

Technical architects, UX/UI designers, your stakeholders

What you hold

Validated architecture, designs and prototypes.

06DevelopmentYou see working software at every milestone, not a status report. Your feedback goes in while we build, not after we finish.
  • Build modular, scalable, maintainable code to agreed standards
  • Apply OWASP secure-coding guidelines and input validation throughout
  • Review code regularly and fold your feedback in at each milestone
  • Share progress as it happens rather than at the end

Who

Development team, technical leads, project managers

What you hold

Working modules, delivered incrementally and approved by you.

07Testing and QAYour own people sign it off. We test for function, for load and for security against international standards before it ever reaches you.
  • Test functionally, in integration, under load, and for security
  • Validate against OWASP and any standard your sector requires
  • Run user acceptance testing with your people, not ours
  • Automate what should be automated, and share the results

Who

Quality assurance, development team, your stakeholders

What you hold

A tested, secure, client-approved build.

08DeploymentYou go live with rollback ready and your team already trained. No downtime surprises, and nothing to learn after the fact.
  • Deploy to the live environment with minimal downtime
  • Have rollback and backup in place before, not after
  • Test in the live environment to confirm real performance
  • Train your team on operating and troubleshooting it

Who

DevOps, development team, project managers

What you hold

A deployed application, operationally ready.

09HandoverYou own all of it. The code, the documentation, every credential. No lock-in, and no dependency on us to keep it running.
  • Transfer the codebase, documentation and user guides in full
  • Run training sessions so your team knows the system
  • Hand over every credential — complete ownership, no dependency on us
  • Close the project against your written sign-off

Who

Project managers, development team, your stakeholders

What you hold

A complete handover package and a trained team.

10Post-deployment supportWe are still here. The people who built your system stay reachable, which is why work we delivered a decade ago is still running today.
  • Monitor, maintain and optimise once it is carrying real load
  • Fix, update and improve performance on an agreed cadence
  • Report periodically on how the system is actually behaving
  • Extend it when the business changes, since it will

Who

Support team, DevOps, your stakeholders

What you hold

A stable, monitored system — and the people who built it, still reachable.

Built in, not bolted on

These are defaults, not upgrades.

Every project gets them whether or not anyone asks, because retrofitting security into a delivered system is how most breaches start.

The iLeaf team working through a plan on the whiteboard in the Kochi office

On every build

  • JWT and OAuth authentication
  • OWASP secure-coding guidelines
  • SSL/TLS encryption in transit
  • Peer code review

Regimes we have shipped under

  • HIPAA
  • GDPR
  • ISO 27001
  • PCI-DSS
  • SOC 2
  • COPPA

Stage one is a conversation. It costs you half an hour and you keep whatever comes out of it.

Questions

What people ask about working with us.

What happens after we sign with iLeaf?

iLeaf Solutions runs ten stages in a fixed order: requirement gathering, analysis and specification, proposal and approval, project planning, system design, development, testing and QA, deployment, handover and post-deployment support. Each stage names who does the work and what you are holding when it closes.

How long does each stage take?

Duration depends on scope, so iLeaf Solutions sets milestones and KPIs during stage four — project planning — rather than quoting generic timelines that would be wrong for most projects. What is fixed is the order of the stages and the deliverable at the end of each, not their length.

Do you work in Agile or waterfall?

Either, chosen to fit the work rather than the methodology. iLeaf Solutions establishes Agile sprints or defines waterfall phases during project planning, based on how much the requirement is likely to move. Regulated builds with fixed specifications often suit phases; evolving products almost always suit sprints.

What security standards are applied by default?

Every iLeaf Solutions build includes JWT and OAuth authentication, OWASP secure-coding guidelines, SSL/TLS encryption in transit and peer code review — applied whether or not a client asks, because retrofitting security into a delivered system is how most breaches start.

Which compliance regimes has iLeaf worked under?

iLeaf Solutions has built and shipped under HIPAA, GDPR, ISO 27001, PCI-DSS, SOC 2 and COPPA. That covers clinical data, EU personal data, information security management, payment processing, service-organisation controls and children's online privacy.

What happens after the system goes live?

Stage ten is post-deployment support: iLeaf Solutions monitors, maintains and optimises the system under real load, reports periodically on how it is behaving, and extends it as the business changes. Over 200 systems built by iLeaf are still in production, maintained by the engineers who designed them.