NASEBANAL Stack
The technologies NASEBANAL currently adopts, and how the set has changed. NASEBANAL provides consulting to its clients with these technologies as its core. The NASEBANAL Stack is reviewed as the business environment and technology landscape shift, and every change is recorded on this page.
Current Constituents
Listed by implementation layer: programming, middleware, managed services and development tooling. Just as the constituent stocks of the Dow Jones Industrial Average are periodically reviewed and replaced, the NASEBANAL Stack swaps its constituent technologies to match the business environment and technology landscape. Each technology name links to its official site.
Programming13 technologies
Languages, frameworks and libraries used to implement
| Category | Technology | What we use it for |
|---|---|---|
| Languages | TypeScript | The common language across frontends, APIs, the CLI and the SDK |
| Python | AI, machine learning, image recognition and FastAPI backends | |
| Web & Backend | Next.js | Web frontend framework, deployed to Cloudflare Workers via OpenNext |
| React | UI library, shared by web and mobile | |
| Tailwind CSS | Styling for web frontends | |
| FastAPI | Python API framework (REST, GraphQL and MCP) | |
| Mobile | Expo (React Native) | Foundation for the iOS and Android mobile app |
| AI, ML & Vision | PyTorch | Deep-learning framework (underlies YOLO) |
| YOLO (Ultralytics) | Object detection and pose estimation on images | |
| OpenCV | Image pre-processing | |
| TensorFlow / Keras | Deep-learning model development | |
| scikit-learn | Machine learning and evaluation metrics | |
| pandas | Data aggregation and preparation |
Middleware13 technologies
Infrastructure software that runs beneath the applications: gateways, messaging, identity, data and monitoring
| Category | Technology | What we use it for |
|---|---|---|
| AI / API Gateway | Kong Gateway | API gateway (routing, authentication, switching the backend to a mock) |
| agentgateway | MCP gateway for AI agents (builds MCP tools from an OpenAPI contract) | |
| Messaging | Apache Kafka | Event streaming that buffers writes asynchronously |
| Identity & Access | Keycloak | Open-source identity provider (issues JWTs) |
| Secrets Management | HashiCorp Vault | Secrets management and dynamic database credentials |
| Database | PostgreSQL | Open-source relational database |
| MySQL | Open-source relational database | |
| Observability | OpenTelemetry | Collection of traces, metrics and logs (OTLP) |
| Prometheus | Metrics collection and alerting | |
| Loki | Log aggregation | |
| Tempo | Distributed trace storage | |
| Grafana | Dashboards for metrics, logs and traces | |
| MLOps | MLflow | Machine-learning experiment and model tracking |
Managed Services27 technologies
Cloud, SaaS and AI services we use with the operations left to the provider (listed by kind of service, not by vendor)
| Category | Technology | What we use it for |
|---|---|---|
| Compute | Cloudflare Workers | Runtime for the APIs and the Next.js frontends |
| Google Cloud Run | Runtime for containerized APIs | |
| Google Kubernetes Engine | Managed Kubernetes | |
| Data & Storage | Cloudflare D1 | Serverless SQLite-based database |
| Cloudflare R2 | Object storage for attachments and other files | |
| Google Cloud Storage | Storage for files and models | |
| Google Cloud SQL | Fully managed relational databases (MySQL, PostgreSQL and others) | |
| Google BigQuery | Data warehouse for large-scale analytics | |
| Network & Security | Cloudflare Rules | Edge rules such as redirects |
| Cloudflare WAF | Web application firewall | |
| Cloudflare API Shield | API protection | |
| Cloudflare DDoS Protection | DDoS mitigation | |
| Cloudflare Turnstile | Bot protection for forms | |
| Cloudflare Access | Zero Trust access control | |
| Cloudflare Gateway | Zero Trust secure web gateway | |
| Cloudflare WARP | Zero Trust device client | |
| Cloudflare App Launcher | Zero Trust application launcher | |
| LLMs & AI Agents | Cloudflare Agents (Remote MCP) | Foundation for AI agents and remote MCP servers |
| Claude (Anthropic) | The LLM at the core of the AI agents and of AI coding (Claude Code) | |
| Google ADK | AI agent development framework (Agent Development Kit) | |
| Google Antigravity | Agent-first development environment (agentic IDE) | |
| Authentication | Auth0 | Authentication shared by every app |
| Payments & Email | Stripe | Payments |
| Resend | Email delivery | |
| Monitoring | New Relic | Uptime monitoring and log retention |
| Source Hosting | GitHub | Source hosting, issues and package distribution |
| GitLab | Source hosting and issue tracking |
Development, Quality & Ops Tooling13 technologies
Tools for infrastructure as code, CI/CD, testing and security checks
| Category | Technology | What we use it for |
|---|---|---|
| IaC & Containers | Terraform | Infrastructure as code for GitHub settings, DNS and R2 |
| Docker (Compose) | Containerization and bringing up whole setups locally | |
| CI/CD & Dependency Management | GitHub Actions | CI/CD and operational-metric posting |
| GitLab CI/CD | CI/CD on GitLab | |
| Renovate | Automated dependency updates | |
| Dependabot | Dependency vulnerability alerts | |
| Testing | Vitest | TypeScript unit tests |
| pytest | Python unit tests | |
| Playwright | End-to-end tests | |
| Locust | Load tests | |
| Contract Tests & Mocks | Specmatic | Contract tests and stubs from the OpenAPI contract (contract-driven development) |
| Microcks | API mocks built from the specification | |
| Security Testing | OWASP ZAP | Vulnerability scanning of web apps and APIs |
Try the NASEBANAL Stack hands-on
Some of the middleware and test tooling in the NASEBANAL Stack can be run and tried for real with NASEBANAL Quickstarts, our open-source toolkit.
Update History
Adoptions and retirements from the NASEBANAL Stack, newest first. Last updated:
- First published
66 technologies — Technologies already in use when this page was first published. The date each was individually adopted was not recorded.
Talk to us about putting the NASEBANAL Stack to work
From selecting and introducing these technologies to applying them in your environment, we can help.
Contact us