Skip to content

THE CORE WE BUILD ON

Build the product. Not the plumbing again.

Quarkino is a production-ready core — authentication, content, media, commerce, notifications, an admin panel — already built, already tested, already secure. We use it to ship client work in weeks instead of quarters. You can build on it too.

27 features. Switch on what you need, switch off what you don't.

Online store18 of 27 features on. The rest aren't hidden. Their routes stop answering.

Every project starts by rebuilding the same six weeks.

  • Sign-in
  • Password resets
  • Role checks
  • File uploads
  • Email delivery
  • An admin panel nobody enjoys building
  • Pagination, again
  • Rate limiting, again

It is the same work in every project, it is nobody's competitive advantage, and it is where the budget goes before anyone has built the thing that was actually commissioned.

Quarkino is that work, finished. Once, properly, at production quality — so the interesting part of your project starts on day one instead of week seven.

Turn one off and it disappears completely — routes, menus, dashboards.

Run in full before any change reaches the main branch.

The engine, the admin panel, and a frontend that's entirely yours.

Built to still be good in year three.

Four decisions that cost more to take late than early. We took them at the start.

01

Customise without forking

Every extension point in Quarkino is a formal registry: field types, payment gateways, discount rules, dashboard widgets, notification channels, reports. Adding your client's odd requirement means registering a definition, not editing core files. Which means the core stays clean, and next year's security fix reaches every project you've built without a painful merge.

How extensibility works
your definitionregistrya socket, not a surgeryQuarkino Corenot one file editedso next year's security fix still applies cleanly
02

Security designed in, not added later

Passwords hashed with argon2id. Sessions in HttpOnly cookies. Secrets encrypted with AES-256 and never returned by any endpoint. Permissions re-read from the database on every request and never stored in the token — so a revoked role is revoked now, not when the token expires. Card details never touch the system at all.

Read the security model
every request, checked againrole revoked between 2 and 3 ↓01requestdata02requestdata03requestrefusedpermission read from the database, never from the tokencard details are not in this picture at all
03

Quality that is measured, not asserted

Every endpoint ships with tests for the unauthenticated request, the under-permissioned request, the invalid input, the success path verified against the database, and one user attempting to reach another user's data. Every endpoint also carries a latency target measured under real load. Nothing merges without the full suite green.

How we test
changefull suitemaingreenstops hereanything redno override, no “we'll fix it after”each endpoint also carries a latency target, measured under load
04

Ready for the second brand, and the fifth

Colours, fonts, logo, text direction, default language, and the entire feature set are configured from the admin panel — no redeploy. Every installation generates its own encryption keys on first run, so two projects on the same codebase never share a secret.

White-label, explained
own keysown keysown keysone core, one codebasecolours, fonts, logo, direction, language — all configurationchanging any of it takes no redeploy

Three parts, one source of truth.

Quarkino Core

The engine.

All logic, data, security, and integrations, exposed as a documented API. No opinion about how anything looks.

Developers

Quarkino Admin

The control room.

Content, orders, media, customers, reports. Generated from the core's own metadata, so a new content type gets a working screen with no UI code.

Your team, daily

Quarkino Web

Whatever you design.

Your storefront, your site, your app, in your framework. It talks to the same API everything else does.

Your customers

One API. Serve a web storefront, a mobile app, and an internal panel from it simultaneously — all reading the same truth.

Have an idea? We'll tell you how much of it already exists.

Most briefs we receive are 80% things Quarkino already does and 20% the thing that makes the product worth building. The fastest route to a working MVP is finding out which 20% is yours.

See how an MVP comes together

What a typical brief is made of

80%

Already built, tested, secured

20%

The reason the product exists

In a typical brief, 80 per cent is already built in Quarkino and 20 per cent is the part unique to your product.

  1. 01Brief
  2. 02Configure
  3. 03Build the 20%11 days
  4. 04Launch

Six weeks is typical. Eleven days of it are usually spent on anything unique to you.

Let's build the thing you actually want to build.

Tell us what you have in mind. We'll show you how much of it already exists.

  • We reply within one working day
  • No sales sequence, no drip campaign
  • NDA before the call if you'd prefer