Proof from real work

What was unclear before, and what state I’ve been responsible for since.

Four different starting points. For each case you can see what I found, what I decided, and what changed.

Four selected cases

Four different reasons to hire someone. Not four versions of the same website.

Crystal Coast Pressure Wash website
01
  • New website
  • Local SEO
  • Ongoing care

Crystal Coast Pressure Wash

Static Astro site for a pressure washing company in Jacksonville, North Carolina: a local SEO architecture of service and location pages, clean schema markup, and an accessible foundation tested against WCAG 2.2 AA. Built in fall 2025 and cared for since.

Visit the live site →
Situation:
A local service business with an active Google profile but no structured website underneath it. Local search had nothing solid to rank.
Implemented:
A new static site with service and location pages, JSON-LD schema, internal linking, and zero axe errors across all pages. Ongoing technical and SEO care since launch.
Result:
The main keyword moved from position 22 to around 6, with several top placements for service and location searches and roughly seven times the organic clicks.

Boundary: The rankings and clicks are measurable and mine to show. What they turn into commercially happens on the client’s phone line, not in my numbers.

Kindbridge Health website
02
  • Healthcare
  • Long-term partner

Kindbridge

Ongoing technical responsibility for the web properties of a US mental health platform since 2021: maintenance, security reviews, and technical advice on architecture decisions.

Visit the live site →
Since 2021:
Websites, security, maintenance, and technical consulting for the agreed systems, under one ongoing arrangement.
Found:
A critical vulnerability in a third-party system I was asked to review, documented before patient data was affected.
Result:
Stable evolution without permanent firefighting, and one accountable technical contact for every web question.

Boundary: The reviews are structured, but they are not a formal penetration test, not an ISO or SOC 2 audit, and not a HIPAA certification. Those are separate qualified fields.

Wheat Free Mom website
03
  • Recipe platform
  • Relaunch

Wheat Free Mom

Relaunch of a large US recipe site: performance cleanup, automated image handling, and a reorganized hosting foundation under hundreds of recipe pages.

Visit the live site →
Situation:
A content-heavy recipe site grown over years. Images, scripts, plugins, and hosting had hardened into a technically heavy foundation.
Implemented:
A full relaunch: automated image processing, cleaned-up code, removed plugin weight, a caching concept, and an optimized hosting environment.
Result:
Images, code, caching, and hosting were reorganized into a base that can carry the site’s hundreds of recipe pages going forward.

Boundary: Without an archived before-and-after report I don’t publish a specific performance number, and without released source data no ranking or lead figures.

HESON product catalog website
04
  • B2B catalog
  • Custom web app

HESON

B2B product catalog for a German industrial manufacturer: 1,818 localized product records, 11 dynamic filter categories, full-text search, and an inquiry system instead of a cart.

Visit the live site →
Situation:
A fully built conventional online store never launched. B2B sales needs qualified inquiries, not a consumer checkout.
Implemented:
A static catalog with a self-hosted CMS: 606 SKUs per language across German, English, and French, 11 filter categories, full-text search, and an inquiry basket.
Result:
Complex B2B product data is searchable, filterable, and inquiry-ready, delivered as fast static pages instead of a heavy shop system.

Boundary: This is intentionally not a full ecommerce system. Product maintenance runs through the CMS, not a classic PIM.

More references

Compact, by type of work.

Security reviewed

  • Healthcare security review Critical vulnerability · CVSS 10.0 A third-party healthcare chatbot was marketed by its vendor as HIPAA compliant. The review tested the implementation instead and found a critical CVSS 10.0 vulnerability, documented and escalated before patient data was affected. Now a monthly review process.
  • Healthcare vendor takeover review Agency code reviewed Review of an agency-built intake and scheduling flow handling sensitive health data: risky data storage, plaintext credentials, tracking in the form flow, and accessibility gaps were documented and prioritized by risk.

Long-term care

Websites and visibility

Which of these looks most like your situation?

Don’t tell me the service you think you need. Tell me what’s unclear, and I’ll tell you whether it calls for an investigation, a defined project, or a specialist job.

Response

I read every inquiry myself and reply personally.

Four required details: name, email, current situation, and privacy consent.

This form is delivered via form.taxi, a form service with servers in the EU.