Dorico Dynamics LDA · Maputo, Mozambique
Engineering critical systems for finance, compliance, data, and workforce operations.
We build auditable software products and deliver cloud, migration, and engineering services for organisations operating under real constraints.
Engineering characteristics our repositories demonstrate
Each item below describes an implementation choice visible in the codebase. None of them is a certification, a guarantee, or a service level.
Go and Rust services, TypeScript interfaces
Production-oriented Go and Rust services behind Next.js and React operational interfaces.
Tenant-aware PostgreSQL domains
PostgreSQL-backed tenant and financial domains, with Redis used for bounded coordination and caching.
Contract-first APIs
REST and OpenAPI, protobuf, and gRPC/Connect contracts define service boundaries before code.
GitOps delivery
Kubernetes, Helm, Argo CD, structured CI gates, and rollback assets across multiple repositories.
Observability by default
OpenTelemetry instrumentation with structured request and correlation identifiers.
Deterministic where it matters
Compliance, accounting, planning, and migration logic is rule-driven and explainable rather than model-driven.
Five products, built around auditability
Products explain what we build. Services explain how we work with clients. The two are kept separate on purpose.
Portfolio structure: Dorico Dynamics
Products
- InfraNotes
- Attesta
- InfraShift
- VoltaHR
- HoyoAI
InfraNotes and Attesta share selected trust integrations: ledger controls, reporting, and document integrity. No other integration line is drawn, because shared technology is not integration.
Services
- DevOps & Cloud
- Cloud Migration
- Custom Software Development
- Technical Consulting
- Available by assessment · staged delivery
InfraNotes
Financial operations, planning, and accounting
Bring spend, budgets, vendors, projects, payroll, assets, grants, accounting, reconciliation, and reporting capabilities into a common tenant-aware platform, delivered in approved stages.
Explore InfraNotes - Controlled rollout
Attesta
Deterministic compliance and auditable evidence
Evaluate versioned rules, submit, organise, and review evidence, issue signed attestations, track remediation, and monitor drift through an auditable compliance workflow.
Explore Attesta - Controlled pilot
InfraShift
Controlled database migration and verified full backups
Plan, execute, resume, and validate database migrations; create encrypted full backups; and rehearse full restores into a new or empty same-engine database across PostgreSQL, MySQL, SQL Server, and MongoDB.
Explore InfraShift - Core available · selected capabilities in preview
VoltaHR
Workforce operations with tamper-evident governance in preview
Bring people operations, time, leave, payroll workflows, recruiting, and preview-stage tamper-evident overtime governance into one multi-tenant platform.
Explore VoltaHR - Controlled availability
HoyoAI
Governed AI for software delivery and GitOps
Review exact code revisions, apply repository policy, produce auditable findings, and build toward controlled GitOps change workflows without surrendering human approval.
Explore HoyoAI
Availability labels describe how each product is delivered today. They are not general-availability or production-readiness statements.
Principles that recur across the portfolio
These are recurring design decisions, not blanket guarantees. Where a boundary applies to specific workflows only, the product page says so.
Deterministic controls
Explicit rules, versioned mappings, and reproducible evaluation, so a decision can be explained and re-run rather than trusted.
Tenant isolation
Explicit tenant, role, scope, and entitlement boundaries, including forced PostgreSQL row-level security in the VoltaHR workforce core.
Contract-first integration
OpenAPI, protobuf, gRPC and Connect contracts, event schemas, and gateway-level domain ownership instead of one undifferentiated backend.
Audit evidence
Append-only logs, immutable document versions, hash chains, evidence packs, and reproducible evaluations recur across products.
Observability and delivery
Probes, telemetry, structured logs, rate limits, circuit breakers, CI gates, and documented rollback paths.
Operator-owned change
Consequential change stays with a human. InfraShift cutovers and HoyoAI delivery boundaries both require operator go/no-go, and selected Attesta and ledger paths fail closed.
How we work with clients
Four engagement families, scoped around demonstrated engineering work.
DevOps & Cloud
Delivery platforms built for repeatable change.
Container platforms, GitOps delivery, observability, release controls, and operational safeguards.
Learn moreCloud Migration
Migrations planned around evidence, reversibility, and cutover control.
Dependency assessment, staged migration paths, validated outcomes, and operator-owned go/no-go.
Learn moreCustom Software Development
Domain software engineered for operational depth.
Tenant-aware platforms and backend services with explicit contracts, durable workflows, and auditability.
Learn moreTechnical Consulting
Architecture and delivery decisions grounded in implementation.
Architecture review, delivery risk, regulated workflows, data migration, and modernisation choices.
Learn more
What the systems actually do
Designed workflow models drawn from the architecture documents. Where an end-to-end environment test has not been supplied, we describe them as designed rather than proven.
InfraNotes
Expense to budget to ledger
An approved expense consumes budget, posts to the general ledger, and feeds reconciliation and reporting through tenant-aware services rather than a single backend.
Attesta
Rule to evidence to attestation
A versioned rulepack evaluates submitted evidence deterministically, produces a reproducible result, and issues a signed attestation with chain verification.
InfraShift
Analyse, rehearse, validate, cut over
Derive a dependency-aware plan, copy schema and data with bounded concurrency and resumable checkpoints, validate counts and constraints, then hand cutover to an operator.
VoltaHR
Preauthorised overtime to tamper-evident record
Overtime is preauthorised, linked to attendance, reviewed bilaterally, and written to an append-only hash-chained event log with daily Merkle roots.
Numbers we can source
Each figure below names its own boundary. We do not publish latency, throughput, uptime, or adoption figures, because no current evidence supports them as product claims.
- Database engines supported by InfraShift
- 4Database engines supported by InfraShift
Scope: PostgreSQL, MySQL, SQL Server, and MongoDB.
- Directed bulk-migration routes
- 16Directed bulk-migration routes
Scope: Exercised in the InfraShift qualification dated 14 August 2026 against commit 7bdbac9, in that environment only.
- Customer-facing products
- 5Customer-facing products
Scope: InfraNotes, Attesta, InfraShift, VoltaHR, and HoyoAI.
- Website languages
- 2Website languages
Scope: English and Portuguese, with equivalent scope and limitations in both.
Who these systems are designed for
Areas the portfolio is designed to serve. These are designed audiences, not evidence of current customers.
Financial services and finance teams
Ledger, AP/AR, reconciliation, close, consolidation, and reporting workflows, with deterministic controls where a decision has to be explainable.
InfraNotes, Attesta
Government and public services
Tenant-aware platforms, auditable evidence, and operator-owned change for organisations that answer to external review.
Attesta, InfraNotes, InfraShift
NGOs and grant-funded programmes
Donors, funds, grant lifecycle, conditions, restricted budgets, disbursements, reporting, and MEAL workflows.
InfraNotes
Workforce-intensive organisations
People operations, attendance, shifts, leave, payroll workflows, recruiting, and tamper-evident overtime governance in preview.
VoltaHR
Project, engineering, and asset-heavy operations
Project costs, billing, revenue recognition, portfolio analytics, procurement, fixed-asset lifecycle, inventory, and incidents.
InfraNotes
Regulated and audit-sensitive technology teams
Compliance evaluation, evidence packs, chain verification, governed code review, and controlled database migration.
Attesta, HoyoAI, InfraShift
How we describe our own work
Every claim carries its scope
Capability statements name the product, environment, and workflow they apply to. A deployment manifest is not evidence of live traffic.
We publish limitations
Each product page lists what is not implemented, disabled, or unverified. A clear boundary is more useful than an absolute.
Humans own consequential change
Cutovers, merges, deployments, and approvals stay with named operators in the workflows where we say so.
Tell us what you are trying to build or migrate.
We respond with a scoped technical view of the work, the constraints we see, and what we would need to verify first.

