# AltaCode — complete site content Source: https://altacode.eu Tagline: Digital ecosystems, built to last. Contact: hello@altacode.eu · WhatsApp +31 6 86 21 21 80 Domains: altacode.eu · altacode.ma · altacode.nl Regions: Europe and North Africa AltaCode builds custom digital ecosystems for operations-heavy companies: one platform connecting inventory, logistics, supply chain, finance, internal operations, and client management, built around how a business already runs. It replaces the stack of disconnected tools rather than adding to it. Deepest specialism: horse transport and live-animal logistics across Europe, including CMR and TIR documentation, customs, veterinary records and welfare compliance. # Page: Home ## Hero Horse transport & live-animal logistics software · Netherlands + Morocco Digital ecosystems, built to last. We build the platforms that move living animals across Europe: transport documentation, veterinary records, border compliance, corridor planning and driver apps that still work with no signal. Three of them are in production. The same platform runs inventory, supply chain, finance and client management, because it is all one operation. - Modules: 6 · one core - Compliance: EU VAT · CMR / TIR - Regions: .eu · .ma · .nl ## 01 · The pile Your inventory is in one system. Your accounting is in another. Your logistics team uses WhatsApp. And somehow this is normal. We built AltaCode because we've been inside operations like yours, patching together tools that were never designed to work together, watching data get lost between systems, and rebuilding the same reports every Monday morning. So we stopped patching. And started building. What companies run today, and the module that replaces it: - stock_final_v7_REAL.xlsx (Shared drive · 4 conflicting copies) → replaced by INV · Inventory Management - Accounting package, disconnected (Data re-entered by hand, twice) → replaced by FIN · Financial Management - WhatsApp group: “DISPATCH 🚚” (Truck status buried in 300 messages/day) → replaced by LOG · Logistics & Transport - Paper CMRs and customs folders (Glovebox of truck 3, somewhere near the border) → replaced by LOG · Transport documentation - Purchase orders over email (“RE: RE: FW: updated order (3rd attempt)”) → replaced by SCM · Supply Chain & Procurement - Staff planning on a whiteboard (Photographed every Friday, argued every Monday) → replaced by OPS · Internal Management - Client history in someone's head (Leaves the building when they do) → replaced by CRM · External Relations ## 02 · The answer Not another tool to add to the pile. The platform that replaces the pile. One data model. One login. Six modules that share the same records. When a delivery is confirmed, stock moves, the invoice is issued, and the client sees it in their portal. No exports, no re-typing, no Monday-morning reconciliation. ## 03 · Inside the platform: six modules, one system of record ### INV — Inventory Management Real-time stock control across multiple warehouses. Automated reorder thresholds, batch tracking, expiry dates, serial numbers, and full audit trails. Tags: Multi-warehouse, Batch tracking, Audit trails, EU compliant ### LOG — Logistics & Transport Fleet tracking, route optimization, driver scheduling, digital delivery confirmations. International transport documentation: CMR, TIR, and customs declarations for cross-border operations. Tags: Fleet tracking, Route optimization, Cross-border, CMR / TIR ### SCM — Supply Chain & Procurement Purchase orders, supplier management, goods receiving, and landed costs. Demand planning tied directly to live stock and sales, so procurement runs on data instead of guesswork. Tags: Purchase orders, Supplier scorecards, Demand planning, Landed costs ### FIN — Financial Management Full financial cycle: quotation, invoicing, payment tracking, reconciliation, expense management. P&L statements, balance sheets, cash flow reports. EU VAT compliant across all member states. Tags: Invoicing, Reconciliation, VAT compliant, Real-time reporting ### OPS — Internal Management HR, staff scheduling, task assignment, project tracking, document management, and performance reporting. Multi-branch, multi-department, with role-based access and approval workflows. Tags: HR & scheduling, Task tracking, Role-based access, Multi-branch ### CRM — External Relations & CRM Full client lifecycle, from first contact to contract, delivery, and long-term account management. Partner portals, client-facing dashboards, automated communications. Tags: Client lifecycle, Partner portals, Automated comms, Account management These six modules are a starting point, not a menu. AltaCode builds complete digital ecosystems. If your operation needs something that doesn't exist in any catalogue, that is exactly what we build, at whatever size it has to run: PostgreSQL with replicas and partitioned data where the volume demands it, caching and queues so nothing waits on a long job, and all of it hosted inside the EU unless you want it somewhere else. ## wAI: the operation engine It does not write you a paragraph. It gives you the record. wAI is the operation engine built into every AltaCode platform. It is not a chatbot and it is not an assistant you have to prompt. It sees a document, understands what kind of operation it belongs to, and returns values: fields, dates, identifiers, results, already shaped to drop into the system that needs them. - Sees: Scanned passports, certificates, lab reports, invoices, handwritten notes, photographs taken in a yard. Multi-page, multi-language, poor lighting, bad angles. - Understands: What the document is, which operation it belongs to, and which of its details actually matter under the rules that govern that operation. - Returns structure: Not prose. Typed, structured data: every field named, every value placed, ready to be written into stock, transport, finance or compliance without anyone re-typing it. - Defers: It proposes and a person confirms. It cannot mark anything compliant on its own, and where it is unsure it says so instead of guessing. Every record remembers whether a machine or a person put it there. The judgement that carries legal or financial weight stays in deterministic code, identical for everyone and impossible to influence from a browser. wAI does the reading, the recognising and the structuring, which is the part that used to cost your team its mornings. ## 04 · How we work ### PH.00 — Map We sit inside your operation: warehouse floor, dispatch desk, accounting inbox. We map how work actually moves, not how the org chart says it does. Deliverable: a complete map of your flows, systems, and the gaps between them. ### PH.01 — Build One data model for stock, money, and movement. Modules built around your flows, your documents, your approval chains, migrated from spreadsheets and legacy tools without stopping the business. Deliverable: your platform, live, with your data in it. ### PH.02 — Run You run the company on one platform. We keep building with you: new branches, new countries, new modules on the same foundation. Deliverable: a system that grows with the business, not against it. ## 05 · Track record The software that moves living animals across borders. 20,000+ horses moved · 42 destination countries · 3 continents · 9 organizations · 1 architect ### Koekkoek Int. Horse Transport B.V. B.V. · Netherlands · koekkoekinthorsetransport.nl Runs the daily operation of a European horse-transport company: bookings, trip planning, drivers and trucks, border paperwork, and invoicing. Managed from the office and from the road. ### Horse E.T. B.V. B.V. · Netherlands · horse-et.com Manages horses flying between continents. Each horse's passport, vaccinations, health records, flight planning, and everything that has to be ready before departure. ### Lorys B.V. B.V. · Netherlands · lorys.nl The bridge between the road company and the air company. Hand-overs, shared paperwork, and clean settlement between the two, with a complete history of every step. ### Bled's Blend SA SA · Morocco Manages the whole licensed operation: the land, biomass supply and demand, regulatory obligations, and international clients. Every batch traceable from field to finished product. ### Terranoid B.V. B.V. · Netherlands / Morocco Extraction laboratory. Receiving raw material, processing, lab work, and finished product batches, each one tracked and ready for inspection. ### Med&Ark Services SARL SARL · Rabat, Morocco · medark.ma International horse transport from Morocco, working under its Dutch parent company. Quotations, trip planning, service execution, and customer records in one place. ### Moroccan Handmade Luxury SARL SARL · Morocco Clients preview handmade furniture in their own home through augmented reality, while the workshop keeps stock and orders under control in real time. ### Moroccan Youth Diplomats NGO · Morocco · youthdiplomats.ma The digital home of Morocco's largest youth-diplomacy community: members, programs, partners, and delegations across eight countries. ### Moroccan Youth Cultural Organizations NGO · Morocco · myco.ma Membership, events, and program management for Morocco's youth cultural organizations. ## 06 · Direction Directed by Wail Ettouil. Every AltaCode platform is architected by the engineer who built the systems above: road transport in the Netherlands, air freight across continents, regulated supply chains in Morocco. One person accountable for the architecture, end to end. No hand-offs, no outsourcing, no telephone game between sales and engineering. - Role: AI & Data Engineer / Solutions Architect - Base: Tangier, Morocco ⇄ Amsterdam, Netherlands - Depth: Sole architect of the platforms above. Over 1.5 million lines of code and 13,700+ commits, built and run single-handedly - Field: Live-animal logistics · supply chain · finance · regulatory compliance - AI / Data: Systems that read passports, health papers, and invoices and turn them into clean records, with no manual re-typing - Trust: Every action logged and traceable · each partner sees only their own data · works offline in the field - Languages: Arabic · English · French · Dutch - Also: Founder & President, Moroccan Youth Diplomats · youthdiplomats.ma ## Contact Book a free consultation One hour. You walk us through how your operation runs today, and we tell you honestly what it would take: which parts a platform should replace first, roughly what that costs, and whether it is worth doing at all. No deck, no obligation. Serious builds then start with a paid Architecture & Scope study, because nobody should quote a platform blind. Email: hello@altacode.eu WhatsApp: +31 6 86 21 21 80 (https://wa.me/31686212180) Instagram: @altacode.eu (https://instagram.com/altacode.eu) Domains: altacode.eu · altacode.ma · altacode.nl # Page: Websites Fixed-price websites for companies in Europe and Morocco. All prices exclude tax: clients in Morocco pay 20% TVA on top, clients anywhere else are invoiced with no tax as an export of services. ### Presence — €790 / 8,500 MAD, excluding tax Live in 5 to 7 days. Best for: Local businesses, practices, freelancers. - 4 to 6 pages - Mobile-first and fast - Contact form straight to your inbox - Google Business Profile set up - Basic SEO and page titles - One language Includes twelve months of the Care plan, hosting and domain. ### Business — €2400 / 26,000 MAD, excluding tax Live in 2 to 3 weeks. Best for: Established companies that need to be found. - 8 to 15 pages - A CMS, so you edit the text yourself - Two languages - Blog or news section - Analytics and Search Console - Full technical SEO - Lead forms and downloads Includes twelve months of the Care plan, hosting and domain. ### Commerce — €5400 / 58,000 MAD, excluding tax Live in 4 to 6 weeks. Best for: Shops, bookings, anything taking money online. - Everything in Business - Webshop or booking system - Online payments - Stock and order management - Customer accounts - Multilingual - Hooks into your invoicing Includes twelve months of the Growth plan, hosting and domain. ## Above a website Two options exist above a website, priced differently because they are different work. Both are requested through the main site rather than this price list. ### Applications — from €6,000 excluding tax One job, done properly, with real functionality behind it. - Client or partner portals - Booking and scheduling systems - Dashboards and reporting tools - Internal tools that replace a spreadsheet How it is priced: Fixed price, quoted after one call once the scope is clear. Usually 3 to 8 weeks. ### Platforms — quoted, not listed The system the company runs on. Several connected modules, one data model. - CRM and client lifecycle - ERP, stock, purchasing and finance - Transport and logistics management - Regulated traceability and audit trails How it is priced: Priced on complexity and architecture, never from a list. Starts with a paid Architecture & Scope study, two to four weeks, which maps your operation and ends in a firm price for the build. ## In every package - Hosting, domain and SSL for the first year - Twelve months of the care plan, included in the price - Two rounds of revisions - A handover call where we show you how to run it - Your files and database are yours, always ## Not included - Writing your copy, photography, translation - Third-party costs: payment gateway fees, premium licences, stock images - Advertising budget - New pages or features after launch, which are quoted separately at a reduced rate for plan clients ## Care plans ### Essential — €29 / 320 MAD per month, excluding tax Keep it online and safe. - Hosting, domain, SSL - Daily offsite backups - Security and dependency updates - Uptime monitoring, we fix outages - Monthly report - Response within 3 business days ### Care — €59 / 650 MAD per month, excluding tax Everything in Essential, plus a hand each month. - 45 minutes of changes each month - Response within 1 business day - Basic analytics reporting ### Growth — €149 / 1600 MAD per month, excluding tax For sites that need to keep getting better. - 3 hours of changes each month - Same-day response - Full analytics and Search Console reporting with commentary - SEO monitoring and fixes - Quarterly review call ## How a website build works ### 01 Brief You fill in a short form: pages, text, images, logo, colours. We confirm the fixed price and the date it goes live. Nothing starts until the brief is complete, because waiting on content is what makes projects late. ### 02 Build We design and build it. You watch it take shape on a private link rather than waiting weeks for a reveal. ### 03 Revise Two rounds of changes, included. Tell us everything at once in each round and this takes days rather than weeks. ### 04 Live We deploy it, connect analytics, submit it to Google, and show you how to edit it. Your care plan starts and we keep it running. ## Website questions **Is a week realistic?** For Presence, yes, once your text and images are with us. The build is fast because we are not inventing a system each time. What makes small websites late is almost always waiting for content, which is why we ask for it up front. **What do I need to give you?** Your logo if you have one, the text for each page, any photos you want used, and an idea of sites you like. If you do not have text yet, say so and we will quote writing it separately. **Can I edit it myself?** On Business and Commerce, yes. You get a CMS and a handover call. On Presence the pages are fixed, and small changes are covered by your care plan. **Who hosts it?** We do, as part of the care plan. It keeps everything fast and lets us fix problems before you notice them. If you ever leave, you take a full export of the site and database with you. **Are the prices really fixed?** Yes. The price on this page is the price you pay for that scope, no hourly surprises. If you ask for something outside the scope mid-build we tell you what it costs before doing it. **Do the prices include tax?** Prices are shown excluding tax. Clients in Morocco are invoiced with 20% TVA on top. Clients anywhere else are invoiced with no tax, as an export of services. **What if I need something more complicated?** Then you have two options above a website, both further down this page. Applications start at €6,000 and cover one clear job done properly: a portal, a booking system, a dashboard. Platforms are the system a whole company runs on, and they are quoted rather than listed, after a paid Architecture & Scope study. Both are requested through the main site. Describe what you are trying to do and we will tell you honestly which one you need, including if the answer is the €790 site. # Page: Horse transport software Horse transport software, built by people who have been inside the trucks. Software for companies that move horses: by road across Europe, by air between continents, and through the stables in between. Not stable management with a transport tab bolted on. The transport is the system. - Horses moved: 20,000+ - Destination rulesets: 42 countries - Continents: Europe, Africa, Asia - Data: Held in the EU ### One horse. One record. Everywhere it goes. Every horse that passes through the operation exists once, not once per department. Identity, UELN, microchip, passport, studbook and owner in one place, and against it the whole history: every journey, every stay, every box it stood in, every vaccination, every blood result, every document ever issued for it. - Ask where a horse has been and what it is currently cleared for, and get an answer in one screen rather than three phone calls - The record follows the animal between road and air, and between companies, without either company seeing the other's business - Passports and lab reports read by machine and turned into fields, so nobody retypes a microchip number at midnight - Nothing is deleted. Corrections leave a trail, because with live animals the history is the evidence ### Orders, journeys, corridors, drivers, trucks. The operational core: bookings turning into planned journeys, journeys turning into loaded trucks and booked flights, and everyone from the planner to the driver at a border working from the same record. - Multi-horse orders across multiple pickup and delivery points, outbound legs and the way back - Corridor planning across Europe, with rest stops and welfare timing treated as constraints rather than notes - Driver apps that work with no signal, because a border crossing at six in the morning is exactly where coverage fails - Live vehicle positions from the trackers fitted to the trucks, not from a phone in someone's pocket - Third-party hauliers handled as first-class partners rather than an exception ### The paperwork decides whether the horse travels. A horse crossing a border is a regulatory object before it is cargo. The platform holds what each destination actually requires and checks every animal against it before anyone books transport. - 42 destination rulesets compiled from official export requirements, covering quarantine days, required tests, vaccination windows and which certificate the movement travels on - Blood results judged against the destination's own thresholds and methods, including repeats that must be spaced a set number of days apart - Vaccination histories rebuilt from printed dates and interpreted per destination, because the same dose is a valid booster in one country and an orphan primary in another - CMR, TIR and customs documentation, veterinary certificates and European movement records, kept with the journey they belong to - Where no state-to-state agreement exists, the private arrangement route is maintained country by country and kept under review ### Interactive 3D stable maps, box by box. For operations with real facilities: a working three-dimensional map of the buildings, not a list of box numbers. Click a box and see the horse in it, how long it has been there and when it leaves. Built for large yards, and used daily in facilities running dozens of boxes across multiple barns. - Live occupancy across every barn, with arrivals and departures visible before they happen - Check a horse in or out at the yard on a phone or a kiosk, capturing its passport at the same time - Quarantine handled at barn level: mark one horse and the barn follows, and it clears itself when the last horse leaves - Suited to the large stabling operations across the Gulf, where import quarantine and long stays make box-level accuracy a commercial question - Every movement between boxes recorded, which is what an inspector asks for ### Analytics that answer operational questions. Not a dashboard of vanity charts. The numbers an operations director actually asks for, drawn from the same records the work runs on, so they are current rather than assembled at month end. - Which routes run on time, which slip, and where in the corridor the time is lost - Occupancy and turnover per barn, and what a stay actually costs to deliver - Compliance exposure: which horses are approaching an expiring test or a lapsing vaccination before it becomes a cancelled flight - What was transported against what was invoiced, matched automatically instead of reconciled by hand - Client-facing reporting, so an owner sees their own horses without anyone assembling a spreadsheet ## Where it runs - Europe: Road transport across the Union under European welfare regulation, cross-border documentation and movement certification. Dutch warmbloods to competition yards, stallions to stud, sport horses between shows. All data held inside the EU, which for regulated animal transport is a requirement rather than a preference. - The Gulf: Doha, Dubai, Abu Dhabi, Riyadh, Manama, Kuwait City and Muscat. Racing and endurance seasons, Arabian horse shows, bloodstock arriving for sales, and the large stabling facilities that receive them. Import permits, health certification and quarantine handled per country, including markets with no standing bilateral agreement. - Africa and beyond: The Morocco to Europe corridor by road and sea, operated under a European parent. Beyond that, wherever the rules allow: Japan, Hong Kong, the Americas, South Africa and Australia, each with its own protocol held in the platform. # Case study: Koekkoek Int. Horse Transport B.V. https://altacode.eu/work/koekkoek · European road transport, live animals · B.V. · Netherlands · koekkoekinthorsetransport.nl We did not replace the spreadsheet. We turned it into the company's operating system. This is not an application. It is a platform: native apps on iPhone and Android, desktop builds for Mac and Windows, installable web apps, and browser panels, each shaped for the person using it and all reading the same records. The office plans. Drivers work from a phone at a border at six in the morning. Clients book and follow their horses. Someone at the barn checks an animal in. Two partner companies abroad see their slice. Delivered as: iOS native, Android native, macOS desktop, Windows desktop, Installable PWA, Web panels. - Delivered as: Native, desktop, PWA, web - Used by: Office, drivers, clients, partners - Data: Held in the EU - Built in: 15 months, one architect ## Before The spreadsheet was not the problem. It was the evidence. A transport company of this size runs on a planning spreadsheet, a stack of paper, a phone, and the memory of whoever has been there longest. That is not incompetence. It is what happens when no software on the market matches the work, so people build the missing system themselves out of whatever is to hand. The planners' sheet encoded real knowledge: which rows were the outbound run and which the way back, which jobs still needed something, expressed in colour and shorthand everyone in the office understood and no software did. The usual answer is to declare the spreadsheet obsolete and make everyone learn a new system. That throws away the one thing that was working, and it is why so many of these projects are quietly abandoned six months after go-live. We began the other way round, inside the operation: on the dispatch desk, in the office, alongside the drivers, learning how the work actually moves before deciding what to build. ## What was built One platform, five connected systems, every device. - The smart spreadsheet: The planners' Excel sheet, rebuilt as a live part of the platform. Several people editing at once, the same colours and shorthand they always used, and every row now connected to a real order rather than sitting in a file on someone's desktop. - Ordering: Transport orders from clients, agents and the office, in one book, with the horses, locations and documents that belong to each one. - Planning: Journeys assembled from those orders, outbound and return legs, corridors across Europe, trucks, trailers and drivers assigned against them. - Dispatch: What is moving today, who is driving it, which horses are aboard and what still has to happen before it leaves. - Invoicing: The financial side attached to the movement that produced it, so what was transported and what was billed are the same record rather than two accounts to reconcile. - Stays and the barn: Horses arriving, stabled and departing, with the building itself drawn in three dimensions and check-in handled at the yard rather than at a desk. - Apps for the people doing the work: Drivers get a native phone app built for a border crossing at six in the morning. The office gets desktop and web. Clients get their own portal. Partners abroad get a controlled window. Same records underneath all of it. - Regulatory records: Movement certification, veterinary and health documents, customs and export dossiers, kept with the transport they belong to instead of in a separate folder nobody updates. ## The hard part The spreadsheet became the front door to everything else. Keeping the sheet was the easy half of the decision. The hard half was wiring it into the rest of the company, so that a row is not a note about work, it is the work. A line on that grid now reaches an order, a planned journey, a dispatched truck and an invoice. Change it in one place and the operation moves with it. That is the difference between a spreadsheet the software tolerates and a spreadsheet the software runs on. Several people edit it at the same time and their changes merge properly rather than the last person to save winning. That is genuinely difficult to get right, and it holds up under the load of a working dispatch desk where everyone is in the sheet at once on a Monday morning. On top sits a planning agent that reads a hand-arranged block of rows and proposes a structured journey from it. The parts that must be exact are decided by rules, not by a model: which rows are the return leg, which jobs are unfinished, read from the colours and shorthand the office already uses. And it never writes anything by itself. It proposes, a person applies, and only then does a journey exist. The same restraint governs document reading. Passports and orders are read by machine, the interface shows where the machine was unsure, and a person confirms before anything becomes a record. None of it could interrupt trading. The company moved horses every day this was built, so every change had to apply itself safely to a live system, and nothing ships unless the whole platform passes its checks first. A broken release means a driver at a border with no paperwork. ## Where it stands One platform now runs the operation end to end, delivered as native iPhone and Android apps, desktop builds for Mac and Windows, installable web apps and browser panels, each shaped for the person using it. Security is structural rather than bolted on. Staff sign in with passkeys and biometrics instead of passwords, the mobile apps verify they are genuine before they are trusted, sessions are bound to the device that created them and refuse to work if that check fails, access is separated into four levels, and every action is written to an append-only trail that would rather fall back to the server log than lose an entry. The native apps pin their connection so it cannot be silently intercepted, even on a hostile network at a border. The platform has been through a formal security audit with a tracked remediation list. All data is held inside the EU, which for a company moving animals across European borders under European regulation is not a preference but a requirement. There is one accessibility detail worth naming because it says what kind of system this is: a colour-blindness mode that swaps red and green for blue and vermillion, so staff who cannot rely on colour can still tell completed from cancelled, or invoiced from not. Fifteen months and roughly 300,000 lines, built and maintained by one architect, while the company never stopped running. Security layers: Passkey or biometric, App attestation, Device-bound session, Role separation, Append-only audit, EU-hosted data. Platform & engineering: Native iOS (Swift), Native Android (Kotlin, Java), Cross-platform desktop (Flutter), Progressive web applications, PostgreSQL with read replicas, Caching and background queues, Real-time collaborative editing, wAI operation engine, Passkeys and device attestation, EU-hosted infrastructure. # Case study: Horse E.T. B.V. https://altacode.eu/work/horse-et · Intercontinental equine air transport · B.V. · Netherlands · horse-et.com A horse crossing a border is a regulatory object before it is cargo. Flying a horse from the Netherlands to Qatar, Japan or Mexico is not a logistics problem with paperwork attached. It is a regulatory event that happens to involve an aircraft. The destination decides whether the animal may travel at all. This is a platform, not an app: native mobile apps, desktop builds, installable web apps and browser panels, all working from one understanding of each horse and what the receiving country requires of it. Delivered as: iOS native, Android native, macOS desktop, Windows desktop, Installable PWA, Web panels. - Delivered as: Native, desktop, PWA, web - Destinations: 42 rulesets - Vaccine data: Official register - Data: Held in the EU ## Before The rules exist. They are just not in a form a system can check. Every country that admits horses publishes its own veterinary protocol, and the Dutch authority publishes what an exporter must do to satisfy it. Those requirements are real, precise and legally binding. They are also spread across dozens of versioned documents, written for humans, and revised without announcement. So in practice an operations team reads a document to decide whether one particular horse, with one particular vaccination history and one particular set of lab results, may fly to one particular country on one particular date. Done by hand, under time pressure, for every animal, that is exactly where mistakes live. A booster that is actually an orphan primary under the destination's definition, or a blood sample drawn two days outside its window, means a horse that does not travel and a client who has already paid for the flight. And the movement is not isolated. It has to land correctly inside the European certification systems, so the transport and the certificate have to agree with each other, not merely coexist. ## What was built One console from stable to landing. - Regulatory engine: Import and export requirements for 42 countries, compiled from 44 official source documents into rules the system applies itself. Quarantine days, required tests, vaccination windows and which certification route the movement takes. - Blood test evaluation: Results judged against the destination's own thresholds, understanding that some diseases are proven by antibody level and others by absence of the agent, that one test method has several names, and that some countries demand repeats spaced a set number of days apart. - Vaccination intelligence: A dose history rebuilt from printed dates and then interpreted per destination, because the same injection is a valid booster under one country's rules and an orphan primary under another's. Roles are not fixed properties of a dose, they depend on where the horse is going. - Medicines authority link: Vaccine products resolved against the official European medicines register, reading active substances and veterinary classification codes to work out which diseases a product actually covers. Authoritative data rather than a guess from a brand name. - Passport scanning: Multi-page horse passports read by machine: name, UELN, microchip, sex, date of birth, and every printed vaccination row, across four languages. - Operation Room: The export dossier per horse: the complete passport, lab reports, gelding certificate where required. Everything the state vet needs in order to certify the movement, in one place, with what is still missing stated plainly. - Certification routing: Which certificate the movement actually travels on, decided per destination: the intra-Union route through the European trade control system, a bilateral national protocol, or a one-off certificate arranged for that shipment. - Flights and manifests: Shared and charter flights with air waybills, consignees and grooms. A live manifest showing loading, wheels-up, landing and customs clearance, with per-horse readiness. - Stables and quarantine: 71 boxes across six barns on a 3D facility map, with quarantine handled at barn level: mark one horse and the barn follows, and it clears itself when the last horse leaves. - Ground dispatch: Road legs from stable to airport, where a third-party haulier is a first-class option rather than a fallback, and a truck can carry horses from different clients as long as they share a flight. ## The hard part Not every country has an agreement. Those are the interesting ones. Destinations do not all work the same way, and the system has to know which world it is in before it can judge anything. Inside the EU and the wider European area, a movement travels on the intra-Union certificate and goes through the European trade control system. For a third country with a bilateral agreement in place, there is a published national protocol and the requirements are known in advance. Those two cases are the comfortable ones. Then there are the countries with no state-to-state agreement at all. There the movement proceeds on a private arrangement between the company and the authorities on each side: an import permit obtained from the destination, and a one-off certificate issued for that shipment rather than drawn from a standing protocol. There is no published rulebook to compile, so those routes are maintained deliberately, country by country, and kept under recurring review because the terms change and an out-of-date assumption there is worse than no assumption at all. Encoding that tiering is the difference between a system that answers easy questions and one an operations team can actually rely on. Most compliance tools quietly assume every destination has a rulebook. Most of the world does not. Underneath it, the horse is understood before the journey is planned. Identity, vaccination history and lab results are resolved into a regulatory picture first, so the question is never 'can we get this animal on a plane' but 'is this animal permitted to enter, and what is still missing'. Reading a passport is a job for a machine. Judging whether a horse may travel is not. The whole system is built on that distinction. wAI, our operation engine, reads scanned passports and lab reports and returns structured records: identity, microchip, every printed vaccination row, every lab result, as fields rather than prose. It never writes a record directly. Each extraction is a proposal a person confirms field by field, and every record carries whether it came from the engine or a human hand. The compliance judgement itself is deterministic code, not a model. Blood results and vaccination timelines are evaluated in plain server-side logic precisely because a pass or fail must be identical for every member of staff and impossible to influence from a browser. Anything ambiguous returns 'verify' rather than a false pass. There is one adversarial check on top, and its design is the part worth stealing. A model is shown only the items the deterministic engine has already passed, and is allowed exactly one kind of answer: do you trust this, or not. It cannot mark anything as compliant. So a hallucinating model can add caution, never remove it. Caution only moves upward. One more safeguard: once a horse's export preparation begins, the ruleset for that order is frozen. If a rule file is edited afterwards, an animal that was compliant yesterday cannot silently become non-compliant halfway through its preparation. ## Where it stands Exports, imports, quarantine and veterinary certification are coordinated from one console, with the regulatory question answered before a flight is booked rather than discovered at a border. The rule library is not a static copy of a document. The official requirement data was traced back to its source and pulled in wholesale, then audited country by country against the originals, which found and removed false blood-test requirements across seventeen destinations. Wrong requirements are not harmless: each one is a test a client pays for and a horse endures without cause. Vaccine knowledge is read from the official European medicines register rather than pattern-matched from a brand name, so a product's disease coverage comes from its registered composition. Where a product is unknown, the system says so instead of assuming. Delivered across every surface the work happens on: native apps on iPhone and Android, desktop builds for Mac and Windows, installable web apps for the yard and the airport, and browser panels for the office. Files are never exposed directly. Passports, certificates and lab reports are served through the platform behind authentication, so a document cannot be reached by guessing a link, and every action is written to an append-only trail. All data is held inside the EU, which for movements governed by European veterinary regulation is a requirement rather than a preference. Built without dependence on third-party frameworks, so there is no upstream project whose decisions can break a system this company depends on, and nothing ships unless the whole platform passes its checks first. Security layers: Passkey sign-in, Role separation, Documents behind auth, Frozen rulesets, Append-only audit, EU-hosted data. Platform & engineering: Native iOS (Swift), Native Android (Kotlin, Java), Cross-platform desktop (Flutter), Progressive web applications, PostgreSQL, Regulatory rule engine, wAI operation engine, Official European medicines register, EU-hosted infrastructure. # Case study: Med&Ark Services SARL https://altacode.eu/work/medark · Horse transport, Morocco corridor · SARL · Rabat, Morocco · medark.ma How do you give a sister company access to your systems without giving it the keys? Med&Ark runs the Morocco to Europe corridor for the Koekkoek network. To do its job it needs live access to horses, stays, orders and health certificates held by its Dutch parent. It must not be able to see anything else, and it must never touch the parent's database or log in as a person. - Access: Scoped to one slice - Every request: Signed three ways - Data: Held in the EU - Languages: French and English ## Before The easy answers were all wrong. Give the Moroccan team a login to the Dutch system and you have handed a separate legal entity an account inside your business, with whatever that account can reach. Give them a database connection and it is worse. Copy the data over nightly and they are working from yesterday while a horse moves today. The requirement was narrow and firm: Med&Ark sees the Morocco-relevant slice of the parent's operation, live, and nothing else. Not by agreement or good behaviour, but because nothing else is reachable. ## What was built Two applications and one carefully drawn seam. - Public site: The corporate site in French and English, choosing language by where the visitor is, with the road corridor, air network, stables and services, and a quote form that feeds the operations app directly. - Operations console: The staff application: horses, stays, orders, health certificates and the Morocco export documents, in French, with role-separated access. - Morocco exports: The one record type Med&Ark owns outright, created and edited on its side and written back to the parent, with print-ready output. - Stable map: The parent's barn layout rendered in Med&Ark's own console, with a box lighting up when a stay it is allowed to see occupies it. - Quote pipeline: Leads captured on the public site, worked through contacted and closed, answered with a branded reply, and pushed up to the parent when the job belongs to the wider network. - Activity feed: A reverse audit showing what the parent's staff did to the records Med&Ark shares, so both offices see the same history. ## The hard part Specify the contract first, then build against it. The integration was designed before it existed. Med&Ark's client, its mirror tables, its authentication and its screens were built first against an honest empty state, and the API contract was written from the consuming side and handed to the parent as a specification. Mock data was explicitly forbidden, so nothing was ever demonstrated working against something imaginary. Every request carries three independent proofs: a bearer key, a signature over the method, path, timestamp and body, and a second detached signature made with a private key that never leaves the server. If any signing material is missing the client refuses to send, rather than falling back to something weaker. Writes are constrained on both sides by an explicit list of fields that may be changed, and edits carry the version they were based on, so two offices touching the same export produce a conflict rather than a silent overwrite. Keeping the two sides in step without hammering the parent is handled by a checksum. Each resource exposes a hash, and the mirror is only refreshed when the hash stops matching. Nothing is polled for its own sake. And when the parent is unreachable, the console does not break. It serves the last known state, tells the user plainly that it is degraded and when it last synced, and carries on. In an operation moving live animals, an honest stale answer beats an error page. ## Where it stands A separate company in a different country works inside the exact slice of its parent's operation that its job requires, in real time, without an account, a database connection or a single unnecessary record. Files never pass through a browser holding a key: passports, stay documents and certificates are proxied through Med&Ark's own backend, so the credential stays on the server. The public site was built to be found as well as read, with structured data, a full French and English content tree, and a brief written specifically for AI crawlers. Access is protected the way the data deserves: sessions bound to the device that created them, a stay-signed-in scheme that stores only a hash rather than anything reusable, and a strict content policy that forbids inline scripts outright. The parent's data stays inside the EU throughout. Security layers: Bearer key, Request signature, Detached signature, Field whitelist, Version check, EU-hosted data. Platform & engineering: Progressive web applications, PostgreSQL, Signed machine-to-machine integration, Cryptographic request signing, Optimistic concurrency control, Device-bound sessions, EU-hosted infrastructure. # Case study: Lorys B.V. https://altacode.eu/work/lorys · Shared operations layer · B.V. · Netherlands · lorys.nl Two companies, one journey, no shared database. A horse leaving a Dutch stable for the Gulf travels by truck and then by plane. That is one journey to the client and two companies in reality. Lorys is the layer where those two businesses meet: freight hand-overs, the paperwork that follows the horse, and the money between them. Neither company can see into the other. - Companies: 2, kept separate - Access: One-way, scoped - History: Immutable - Data: Held in the EU ## Before The obvious answer was the wrong one. Koekkoek moves horses across Europe by road. Horse E.T. flies them between continents. A single client journey routinely uses both: a truck to the airport, a flight, then another truck at the far end. To the horse owner that is one booking. Between the two companies it is a hand-over, a stack of documents that has to travel with the animal, and an invoice to settle afterwards. The obvious fix is to plug the two companies' systems into each other. It is also the fix that causes damage for years. Direct integration means each company's primary application has a permanent door into the other's, every schema change becomes a negotiation between two businesses, and nobody can answer the question that eventually gets asked: exactly which of my records can they see? These are independent companies. They cooperate on some journeys and compete for nothing, but they are not one organisation, and their data should never behave as if they were. ## What was built A third system that neither company owns. - Freight hand-overs: The moment a horse passes from road to air, or back, recorded once as a shared event rather than twice in two systems that later disagree. - Shared workflows: The steps both companies need to see on a joint journey, without either of them gaining sight of the rest of the other's operation. - Financial transactions: What one company owes the other on each shared movement, captured as it happens instead of reconstructed from invoices at month end. - Reconciliation: Both sides settling against the same record of what actually moved, so a disagreement becomes a lookup rather than an argument. - Permission-scoped access: Each company reaches only its authorised segment. Not by convention or good manners, but enforced, so the boundary holds when someone new joins or a script misbehaves. - Immutable audit trail: Every action recorded in a way that cannot be quietly rewritten later. When two companies share liability for a live animal, the history has to be worth something. ## The hard part The architecture decision was the whole project. The engineering that mattered here happened before any feature was built. Connecting two companies is a data-ownership question wearing an integration costume, and getting it wrong is expensive in a way that only shows up two years later. So Lorys was built as a boundary rather than a bridge. Each company's own platform stays sovereign and unmodified. What crosses between them crosses through Lorys, where access is one-way and scoped: a company can see and write only the operational segment it is authorised for, and nothing else exists as far as it is concerned. That decision buys three things. Tenant isolation is structural rather than promised, so neither company is trusting the other's discipline. Either side can change its internal systems freely, because nothing external depends on their shape. And the awkward question, who is allowed to see what, has a precise answer that can be shown to a partner, an auditor or an insurer. It also means the shared history is neutral ground. Neither company hosts the record of their joint work, so neither can be accused of editing it. ## Where it stands Two independent companies run joint journeys as a single operation, while each keeps full ownership of its own data. The hand-overs, the shared paperwork and the settlement between them all live in one place both can trust, precisely because neither controls it. Commercially the same structure lets Lorys be the single face a client deals with, stable to stable, road and air, while behind it the separation stays absolute. Because the shared record is where two companies' liability meets, it is held inside the EU and written so that history cannot be quietly revised. Neither party has to take the other's word for what happened. The pattern generalises well beyond horses. Any two businesses that cooperate on part of a workflow and must not see the rest of each other have this problem, and most of them solve it with a direct integration they regret. Security layers: Scoped access, One-way flow, Tenant isolation, Immutable history, EU-hosted data. Platform & engineering: Permission-scoped access, One-way data flow, Tenant isolation, PostgreSQL with immutable audit logging, Reconciliation engine, wAI operation engine, EU-hosted infrastructure. # Page: Wail Ettouil — portfolio Wail Ettouil, AI & Data Engineer / Solutions Architect. Based between Tangier, Morocco and Amsterdam, Netherlands. I build the systems companies actually run on. Not apps, not tools. Operating platforms for businesses with trucks on the road, animals in transit, stock on shelves, and regulators at the door. I learn an operation from the ground up, then I build its digital twin, and I stay until the whole company runs on it. - Code shipped: 1.5M+ lines - Commits: 13,700+ - Organizations: 9 - Base: Tangier ⇄ Amsterdam - LinkedIn: https://linkedin.com/in/wail-ettouil ## Where it started My first language was C. Pointers, memory, segfaults: the unfriendliest possible introduction to computers, and I loved it. Then I discovered HTML and realized every web page is just code someone else wrote, which means it can be changed. My first real project, at an age I won't defend, was trying to strip the ads out of websites I had no business visiting. It worked. Sometimes. That instinct never left: see a system, take it apart, understand why it was built that way, rebuild it better. It just moved from web pages to companies. Somewhere along the way I stopped asking how does this website work and started asking how does this business work: where does the truck go, who signs the paper, where does the money actually move? On the side, I learned how logistics systems work from the people who run them, and built the blueprint I still use today for digitalizing companies of 100+ staff: sit with every role, learn the operation from the ground up, then teach it back to them inside a system built around how they already work. ## The road ### 2021 — A real-estate internship in northern Morocco Nord Sakan. My first time writing code that ran a business process for strangers: a rentals-and-sales platform with a back office the agents actually used. Small system, big lesson: software only matters if the person behind the desk trusts it. ### 2022 to 2024 — Luxury furniture, in your living room Through the right contacts, a handmade-furniture house (MHL) took a chance on me. I put their catalogue into clients' homes through a phone camera, augmented reality before I knew to call it that, and put their workshop's stock and orders under real-time control. Two years of learning how craftsmen, showrooms, and inventory actually behave. ### April 2025 — The internship that became an ecosystem A final-year internship at Koekkoek International Horse Transport in the Netherlands. Three months to prove myself. I never really left. I immersed myself in the European horse-transport system from inside the trucks: CMR papers, TIR carnets, veterinary documents, border regulations, corridor planning, driver scheduling, stable operations. Fifteen months and 2,700 commits later, a 280,000-line platform ran the company: orders, routing, invoicing, paperwork, and live GPS tracking of drivers and horses. Built by one person: me. ### Nov 2025 — Legal cannabis, fully traceable Morocco legalized regulated cannabis production, and Bled's Blend needed every gram accountable across land, biomass, supply and demand, and international clients, with Terranoid running extraction in the lab. I built the traceability platform: from seed to finished product, every batch tracked, every step ready for the regulator. Offline-first, because farms don't have fiber. ### 2026 — The ecosystem grows wings Med&Ark brought the horse-transport model to Morocco under its Dutch parent. Horse E.T. took it to the sky: intercontinental air transport, where a single horse can be worth more than the aircraft hold it flies in: passports, vaccines, blood tests, airway planning, partner airlines. And between road and air I built Lorys, a neutral shared layer where two companies cooperate on hand-overs and settlement without ever seeing each other's private data. ### Now — AltaCode Everything I learned in one practice: digital ecosystems for operations-heavy companies: logistics, live-animal and high-asset transport, supply chains, and finance, with AI where it earns its keep and security designed in from day one. Direct. No hand-offs. I learn your operation, then I build it. ## Disciplines ### AI & smart data analysis I don't do AI demos. I put models to work inside operations, where being wrong costs money. - Document intelligence in production: horse passports, veterinary papers, and invoices read by machine and turned into clean structured records, with no re-typing - Fine-tuned models where generic ones fail: domain language, domain documents, domain decisions - Forecasting and planning on live operational data (demand, stock, routes), not on last quarter's export - TensorFlow, PyTorch, OpenCV, NLP, chosen per job and never for the badge ### Data modeling & scale Before a line of interface code, I design the model: one version of the truth for stock, money, and movement. - Audit-first schemas: every record knows who touched it, when, and why - PostgreSQL where the workload is heavy, MySQL and MariaDB where it is not. The engine follows the problem, not fashion - Growing past one database: read replicas, partitioned tables, Redis for the hot path, queues so long jobs never block a person - Models that survive growth: multi-warehouse, multi-branch, multi-company from day one - If the model is right, the features are easy. If it's wrong, nothing else matters ### Cybersecurity I design systems that assume the network is hostile and the insider is curious. - Sign-in with passkeys and biometrics, the way banks do it, not passwords on a sticky note - Every partner sees exactly their slice and nothing else. Enforced boundaries, not promises - Tamper-evident history: actions are logged in a way that silent editing breaks visibly - Cryptography and offensive-security research background (Al Akhawayn University program, CertForge) ### Software engineering 1.5M+ lines in production, 13,700+ commits, and the discipline to keep it all running. - Offline-first field apps: a driver at a border crossing with no signal still gets his paperwork - Native iPhone and Android apps where the web isn't enough: biometrics, chip scanners, background GPS - Laravel, Django, Node, Next.js, Vue, Swift. Full stack means the whole stack, not most of it - One platform, every surface: native iOS and Android, macOS and Windows desktop builds, installable web apps, browser panels - Sole maintainer of systems companies depend on daily. Uptime is personal. ### Solutions architecture The hardest problems aren't in the code. They're in who is allowed to see what, and which system owns the truth. - Three companies, one shared operations layer (Lorys): cooperation without exposure - Neutral boundaries instead of direct integrations: each company keeps ownership of its own data - Multi-tenant platforms with real isolation, gateways, and controlled read/write pipelines - Ecosystems designed to grow: new branch, new country, new module, same foundation ### Web development The public face and the daily workhorse: websites, portals, and progressive apps people actually use. - Corporate sites, client portals, and dashboards that non-technical staff open every morning - Progressive web apps that install like native and work like native - Augmented reality on the open web: furniture in your living room through a phone camera - Fast, accessible, responsive, and measured rather than assumed ### SEO & digital marketing A platform nobody finds is a shelf ornament. I build the visibility layer too. - Corporate web presence with analytics and content workflows built in from launch - Technical SEO as engineering: structure, speed, and semantics search engines reward - Measurement before opinion: what gets tracked gets improved - Launched and grew digital presence for companies from zero ## Where I go deepest ### Logistics & live-animal transport Living cargo doesn't wait. Welfare rules, rest stops, veterinary checks, temperature, timing. I build systems that treat an animal as what it is: the most demanding shipment there is. ### High-asset transport A single competition horse can be worth more than the truck it rides in. Chain of custody, documentation, insurance-grade records. Nothing moves without a trail. ### GPS & geolocation Live tracking of drivers, vehicles, and animals across borders: positions on the map, arrival estimates that mean something, and history you can replay when a client asks what happened. ## Notable projects ### CertForge (Security research) A defensive research project from cryptography work at Al Akhawayn University, demonstrating certificate-validation weaknesses when an attacker controls network infrastructure, documented alongside its mitigations. The site explains it interactively: how certificate verification is supposed to work, what happens when the network belongs to an attacker, why the trust-store assumption is the real weak point, and how pinning, certificate transparency, mutual authentication and strict transport policy close it. Includes live-computed RSA signing and verification, Diffie-Hellman key agreement, a real AES round with the S-box derived from GF(2^8) inversion, and the arithmetic of a man-in-the-middle holding two valid session keys. Conducted in a controlled lab environment for penetration-testing education, with no operational tooling. ### BioNest Technology (Medical platform, side project) A medical records platform with two obsessions: help doctors read images faster, and make it impossible to quietly rewrite a patient's history. Led a team of four, personally responsible for the security architecture and the record integrity model. Four models assist: a medical language model tuned on clinical text, breast-cancer imaging assessment, tuberculosis and pneumonia screening from chest X-rays, and three-dimensional recognition for Alzheimer's indicators. None of them diagnose; they flag, rank and explain, and the doctor decides. Records are chained so that each entry's seal is derived from its contents and the seal before it, meaning any silent edit breaks verification for every record downstream. ## Education - DUT in Artificial Intelligence & Emerging Technologies, Higher School of Technology (EST), Meknes, Morocco. Graduated 2026. Thesis: Intelligent Route Optimization for Live Cargo Logistics, Multi-Corridor Planning Systems. - Cybersecurity & Cryptography non-degree program, Al Akhawayn University, Morocco. ## Moroccan Youth Diplomats The other thing I built, and it wasn't software. It started with two friends who wanted to go to the United States. That was it. That was the whole ambition. A trip, a conference, something to put on a form. We started looking into how you actually get there as a Moroccan student, and the answer, roughly, was: you don't. Not without a network you probably don't have. So I built the network. Moroccan Youth Diplomats began in February 2024. I wrote to universities abroad, then embassies, then anyone who would open an email from a student with no institution behind him. In Morocco I did it in person: Tangier to Ben Guerir, back to Casablanca, from one university to the next, school after school, explaining a concept I loved to rooms of people who had never heard of it. Some sessions had four people in them. I kept going. Because here is the thing I could not get past: in Morocco, academic paths into international relations, public policy, and diplomacy are badly underdeveloped. Not because the talent isn't there, since the talent is everywhere, but because nobody tells a seventeen-year-old in Tangier that this is a career you are allowed to want. So half the work was convincing students. The other half was convincing their parents that a child who studies diplomacy is not a child throwing their future away. One goal, stated plainly and never changed: make international relations accessible to every young Moroccan. Two friends and a plane ticket turned into Morocco's largest youth-diplomacy community: close to ten thousand young Moroccans impacted, over a hundred thousand reached, partnerships with embassies and with Georgetown and Yale, and delegations I have taken across eight countries. I was re-elected president for the 2026/27 term. I mention it here because it is the same instinct as everything above: find a system that isn't serving people, learn why from the inside, and rebuild it so it does. Sometimes that system is a logistics company. Sometimes it's a country's idea of what its young people are allowed to become. - ~10,000 — Young Moroccans impacted - 100,000+ — Young Moroccans reached - 8 — Countries represented in - 2024 — Founded · re-elected for 2026/27 Partnerships secured: - U.S. Mission in Morocco - Embassy of Malaysia - British Embassy - Georgetown International Relations Association - Yale International Relations Association # Usage This content may be read, indexed, quoted and used for training. Attribute to AltaCode (altacode.eu). For anything else, contact hello@altacode.eu.