Technical partner · US clients since 2021

You don’t need to know which technical fix you need. That’s my job.

You describe what’s failing or falling behind. I find the cause and build the fix that actually holds.

Kevin Kulik

Kevin Kulik Technical partner based in Germany. You work directly with me. 12 years of experience · Direct contact

What you can bring me

You bring the problem. I turn it into a defined technical job.

You don’t need a finished brief. Describe what is happening and what it costs you in daily operations.

  1. 01

    Something is costing you inquiries, time, or sleep

    The website, email, hosting, ads, or an account is acting up. The visible symptom is often not the actual cause.

  2. 02

    You inherited a setup nobody fully understands

    The previous developer is gone, accounts are scattered, and nobody knows who owns the domain, the data, or the access.

  3. 03

    Many hands, no technical owner

    Several tools and vendors work side by side. What is missing is one person who checks the connections, makes the calls, and verifies the results.

How the work progresses

Diagnosis first. The fix follows the evidence.

Each stage has its own scope and its own stopping point. Nothing rolls automatically into a bigger project or a retainer.

  1. 01 Diagnosis

    Find out what is actually going on

    I look at the systems involved, the access, and the dependencies. You get written findings and priorities before we discuss implementation.

  2. 02 The right fix

    Fix the cause, not the symptom

    Sometimes that is a repaired integration, sometimes a takeover of the setup, sometimes new tooling. The evidence decides, not a preferred product.

  3. 03 Ongoing responsibility

    One accountable owner for the agreed systems

    Routine checks, response expectations, included work, and escalation paths are defined in writing. Incidents and new projects stay separate.

  4. 04 Only if the evidence says so

    Rebuild when the foundation no longer makes sense

    A website is a tool, not the product. A rebuild is a later decision that follows the diagnosis, never the default answer.

Solved cases

Three problems. Three completely different fixes.

Crystal Coast Pressure Wash

  • Ads
  • Phone intake
  • Root cause

The ads were fine. The answering service was hanging up.

Situation:
Phone inquiries for a pressure washing company in North Carolina dropped from 10 or 11 a week to 3 or 4. Everyone assumed the ads had stopped working.
Decision:
I pulled and transcribed 13 recorded calls. The AI answering service hung up on every call that opened with "call from Google", which is exactly how the paid leads announce themselves. The numbers proved the ads were still delivering.
Result:
The working ads stayed untouched. The broken phone intake was replaced the same day. The engagement had started with a website.

Healthcare platform (US)

  • Vendor oversight
  • Verification

The vendor reported "fixed." The live test said otherwise.

Situation:
Several outside vendors work on a platform that handles sensitive data. Nobody in-house could verify whether reported fixes had actually shipped.
Decision:
Stop taking status reports at face value. I tested the code and the production behavior myself and built a connected inventory of systems, access, vendors, and deadlines.
Result:
One vendor reported an unsafe feature as removed. The live test showed it still running. Monthly verification checks run since then. "Done" means provable in production.

HESON

  • B2B catalog
  • Inquiries instead of checkout

1,818 product records in three languages, inquiry-ready

Situation:
An industrial manufacturer of steel containers. A fully built online store never launched: B2B sales needs qualified inquiries, not a consumer checkout.
Decision:
No second store. A static product catalog with a self-hosted CMS, 11 filter categories, full-text search, and an inquiry basket instead of a cart.
Result:
606 SKUs in three languages are searchable, filterable, and inquiry-ready. Later change requests moved fast: one requested feature was live within 24 hours.
Client perspective

What long-term clients say about the work.

I've worked with Kevin for over four years. What impresses me most: our website just works. No hacks, no surprises, no emergencies. When I need help, he responds within hours.

Portrait of Varadraj Godbole
Varadraj Godbole

Kevin keeps things simple and gets it done. Fast responses, clear communication, no drama. We've worked with him on multiple projects. Highly recommend.

Daniel Umfleet Kindbridge

With other developers, it was always stressful: updates, security issues, something broke. With Kevin? The website runs, I focus on my business. That's priceless.

Portrait of Cameron Adair
Cameron Adair Game Quitters
Kevin Kulik, technical partner at Contegus
Who handles the work

The person who diagnoses the problem is the person responsible for the fix.

I’m Kevin Kulik. My background is in security research and web implementation, which sounds more dramatic than it is. In practice it means I notice when something is off. US clients have trusted me with their systems since 2021, including healthcare platforms like Kindbridge.

The honest boundary: healthcare experience does not make every engagement a HIPAA audit. Legal advice, certification, and formal penetration testing are their own qualified fields.

US clients
Direct work on client systems since 2021
Working model
Remote, direct, and documented
Who you talk to
Me. There is no team behind the curtain.
About my background
Common questions

Scope, access, and working across borders.

What is free, and what becomes paid work?

I can briefly assess whether the situation fits and whether an investigation is the sensible next step. Reviewing systems, access, configuration, or vendor implementation is paid work with a written scope and deliverable.

What do you actually take over?

Only the websites, accounts, infrastructure, or vendor relationships named in the agreement. I first document ownership, access, dependencies, and risks. Stabilization and ongoing care are separate decisions after that.

How do you handle administrative access?

Access requirements are defined before work starts. Credentials are exchanged through an agreed secure method, permissions are limited where possible, and production changes are not made during an investigation unless separately authorized.

How does remote work across US time zones work?

I have worked remotely with US clients since 2021. The engagement defines contacts, async updates, decision points, and any response expectations. There is no implied round-the-clock coverage.

Is this a HIPAA audit or compliance certification?

No. I can review the technical implementation around agreed forms, access, tracking, deployment, and third-party exposure with healthcare context. Legal advice, certification, and formal compliance or penetration-testing scopes require the appropriate qualified specialists and agreements.

Can you work with a DIY, AI-built, or agency-built site?

Yes. The tool does not decide the outcome. I look at maintainability, access, data flows, dependencies, and the operational need, then recommend repair, takeover, or a rebuild only when the evidence supports it.

What does an engagement cost?

The systems, access requirements, deliverable, timing, and fixed scope are defined before paid work begins. Stabilization and ongoing care are priced separately after the findings. I do not publish an unvalidated catch-all price for different environments.

Tell me what’s going on. I’ll find out what it takes.

A few sentences are enough. A brief fit check is free; any technical investigation starts only with a defined, paid scope.

Response

I read every inquiry myself and reply personally.

Four required details: name, email, current situation, and privacy consent.

This form is delivered via form.taxi, a form service with servers in the EU.