Oxwyn Studio

About Oxwyn Studio


Oxwyn is a UK-headquartered digital engineering studio delivering bespoke websites, SaaS, ecommerce and applied AI for organisations across the UK, USA and Europe. No template rental, no fabricated case studies: published pricing wherever the scope is repeatable, real contracts, and code we wrote ourselves.

Operating from
United Kingdom
Markets served
UK · EU · USA
Working hours
Mon - Fri · 09:00 - 18:00 GMT
Three studio wall clocks showing different times across our delivery regions

UK-headquartered

One senior engineer, accountable across three time zones.

The human intelligence half

Engineering and governance expertise.

The person who writes your code is also the person who has spent years on the other side of it, auditing information security programmes and deciding what evidence a regulated business has to be able to produce. That is why these builds start with the architecture decisions rather than the theme, and why the compliance paperwork exists at all.

Security architecture

Decisions made at the design stage, where they are cheap, rather than patched afterwards. It is why these builds carry no plugin library and no CMS admin panel to compromise.

Information security management

The paperwork a regulated client is asked for and usually cannot get from a web supplier: a Data Processing Agreement, a written security statement, a supplier questionnaire answered properly.

AI governance

Where a language model is allowed to touch the work and where it is not. On the X-Ray it writes one labelled paragraph from measurements it cannot alter, and that boundary is written into the code rather than into a policy nobody reads.

Offensive perspective

Reading a site the way somebody attacking it would. That is the whole reason the X-Ray reports the version numbers a site publishes about itself, because that is the first thing an attacker collects.

Certifications held by a member of our team

These are personal certifications, current and verifiable in each issuer's own public directory. They are not a statement that Oxwyn Studio is certified to any standard: a company certification requires an accredited body, an audit and a published scope, and we do not claim one. Ask and we will give you the certificate numbers.

  • CCISO

    EC-Council

    Certified Chief Information Security Officer

    Governance, risk and the management side of running a security programme.

  • CISM

    ISACA

    Certified Information Security Manager

    Information security management, incident response and risk against business objectives.

  • CEH

    EC-Council

    Certified Ethical Hacker

    How systems are actually attacked, which is what makes a defence more than a checklist.

  • SecurityX

    CompTIA

    CompTIA SecurityX

    formerly CASP+

    Enterprise security architecture and engineering rather than policy alone.

  • ISO 27001

    ISO/IEC 27001

    Lead Auditor, information security management

    How an information security management system is audited, and what evidence one has to produce. Held as a certified Lead Auditor.

  • ISO 42001

    ISO/IEC 42001

    Auditor, AI management systems

    Governance for AI systems: accountability, oversight and the records that prove both. Held as a certified auditor.

The strategy board

Five disciplines. One brief. Real answers.

Type your idea, pick a discipline, and read the actual brief Oxwyn would write before any code is touched. Findings are deterministic and reference our published pricing and stack - nothing here is generated on the fly.

Step 1 - Your idea

Step 2 - Pick a discipline

Oxwyn brief · v1

Strategy & Commercials

Pricing model, contract shape, unit economics

We pick the commercial shape - one-off build, monthly Website-as-a-Service, or hybrid retainer - and stress-test it against your margin, churn risk, and exit terms before any code is written.

Questions we ask

  • What is the cheapest version that still earns trust?
  • What does a fair exit look like at month 12, 24, and 36?
  • Where is the hidden cost - support, content, or change requests?

Artefacts

  • Pricing recommendation
  • Term-length rationale
  • 12/24/36-month cash model

Findings for “Pay-monthly local clinic website

  1. 01Commercial shape

    For "Pay-monthly local clinic website" the honest first move is the Business plan at £149/mo + £399 setup on a 24-month minimum. It covers a real 5-page site, hosting, SSL, basic SEO, and 2 minor edits/month - the floor most owners actually need without paying agency rates.

  2. 02Term length

    12 months for Starter, 24 for Business / Growth, 36 for Ecommerce. The minimum exists because we carry the build cost up-front; it is not a lock-in for its own sake. Buyout and early-cancellation terms are fixed and published before you sign.

  3. 03Margin reality

    Plans cover the website itself. Marketing - Local SEO, Google Ads, Meta/TikTok, content, email - is a separate retainer from £179/mo with a 3-month minimum. Ad spend is billed by Google or Meta directly to your card; we never mark it up.

  4. 04First action

    Sign the Business plan, lock in the 24-month foundation, and bolt on Local SEO at £249/mo only when the site is live and indexed. Re-evaluate Growth tier at month 6 if lead volume justifies it.

Deterministic brief - no model in the loop, no fabricated metrics.

Bring this brief to a call
A build under review on the studio wall screen, an empty chair in front of it

How we review

Every build is walked through together before it ships. No lone wolves, no silent merges.

The operating charter

Six rules we will not break for a sale.

Plain rules. They cost us briefs every month. We keep them anyway because the alternative is the kind of agency relationship every owner has already had once and refuses to repeat.

  1. We say the price out loud.

    Setup fees, monthly fees, minimum terms, buyout and cancellation costs are published on the page before you contact us. Published pricing wherever the scope is repeatable, a fixed written quote where it is not, and no hidden retainer floors either way.

  2. We do not invent metrics.

    If we have not shipped it, we label it Concept or Blueprint. Numbers in case material come from the actual project or a real public benchmark, not a brochure round number.

  3. We use the smallest stack that holds.

    Next.js, React, Tailwind, Postgres. No CMS rental, no plugin sprawl, no admin panel we did not write. Less surface area means fewer breaks and lower long-term cost.

  4. Security is the first migration.

    Row-Level Security, parameterised queries, secrets in env vars, UK GDPR + EU GDPR + CCPA posture set before launch - not added during a panic after a near-miss.

  5. Marketing is its own retainer.

    Build plans cover the website. Local SEO, Google Ads, Meta, content and email are separate from £179/mo with their own minimums. Ad spend is billed by Google and Meta directly to your card.

  6. You can leave.

    Buyout terms are written into every contract. After your minimum term you can take the codebase, your data, and your DNS and walk - we will hand it over cleanly.

Bring a brief, leave with a plan.

Tell us what you are building and which advisor view matters first. We will reply within one working day with a fixed scope, fixed price, and the contract terms before you commit.

Start the conversation