Engineering notes
What we actually run into building web applications and AI automations - stack decisions, real project costs, and the bugs we keep finding in other people's code.
Every article here comes out of a project that was paid for. There are no roundups, no listicles, and nothing rewritten from somebody else's post. When a piece describes a failure, it is one that happened on our own work or on a client system we were brought in to fix, and the fix is included.
The recurring subjects are the ones that keep costing money: credentials that end up somewhere they should not be, systems that report success while doing nothing, legacy backends nobody wants to own, and the question of whether an AI project needs retrieval, fine-tuning, or a better prompt. Written for the person who has to make the call, not for a search engine.
Smart-UI is a software development agency in Merida, Spain, with an engineering centre in Kharkiv. We build web applications in React, Next.js, Node.js and Python, and AI automation systems, for clients in the UK, US, EU and Australia. If an article describes a problem you recognise, get in touch and we will tell you what it usually takes to fix.
Hiring developers in the EU: employ or contract?
A client could not hire locally, not because nobody was available, but because the commitment was hard to reverse. Two years on, how the contracted team works.
Website audit checklist: what a full pass finds
We ran the audit on our own site: thirty pages, thirty with a fault. What six dimensions turn up, and the one habit that found every one of them.
How to hire for a legacy stack nobody wants
The code was not the hard part. Finding one senior engineer to own an old .NET backend was, and what fixed it was the job description, not the pay.
How to add tests to legacy code with no tests
You cannot retrofit coverage as a project. Characterisation tests, where the first twenty go, and why a reproducible build comes before any of them.
Why revalidatePath does not update your page
revalidatePath returns 200 and nothing changes. That failure and three more that report success: a 404 served as 200, schema for absent content, dropped metadata.
A leaked API key: how it is found and what it costs
A key leaked, was found within hours, and sent five million emails on a client reputation. What the attack looked like, and why nothing alerted anyone.
Legacy .NET modernisation without a rewrite
What to do when a business-critical system runs on old .NET, the people who wrote it are gone, and a rewrite is not an option. The order of work.
RAG vs fine-tuning: which one you actually need
Most projects reach for RAG before they need it. When retrieval earns its place, when fine-tuning does, and the three questions that settle it.
Is NEXT_PUBLIC_ safe? Find API keys in your bundle
NEXT_PUBLIC_ is not a security setting. How secrets reach a Next.js bundle, a 30-second check that finds them, and the fix that holds.