Marketing Campaign: Why 2Run Documents Its Stack in Public
Why we are publishing our stack decisions, project retros, and security playbooks as a content campaign — and how developer-marketing turns portfolio sites into sales pipelines.
Most portfolio sites show a project, a screenshot, and a "hire me" button. That is not enough for a 2Run-tier audience — public-sector buyers in Belgium, municipalities in Turkey, GP practices in the Netherlands. They want proof that the team understands their domain, their compliance regime, and the operational reality of running software in production.
Why a content campaign, not a redesign
A redesign is a one-shot event. A campaign is a flywheel: each post compounds trust, each post opens a new keyword surface, each post makes the next one cheaper to write. Three compounding effects we measured after Q2:
- Long-tail search traffic. Posts like the Tolky real-time translation deep-dive now rank for very specific queries (e.g. "Gemini 3.5 Live WebSocket integration"). Visitors arrive already convinced of the technical credibility.
- Procurement de-risking. Public-sector RFPs in the EU often include a "describe your security posture" question. Posts on NestJS helmet config, GDPR retention, and AI prompt injection become reference material — not marketing copy.
- Inbound narrative control. When a buyer reads our reasoning before the demo call, the call becomes a conversation about fit, not a defense of basics.
The twelve posts in this wave
This drop is structured as twelve posts in three pillars:
Project retrospectives (6)
For each flagship product — Tolky, Glowniq, kinderverhaal, qnack + qnack-mqtt-print, silayolu, and the 2Run portfolio itself — we publish the architecture decisions, the trade-offs we accepted, and the production incidents that taught us the most.
How-to guides (3)
Field guides written from production experience: choosing a SaaS stack in 2026, shipping a pnpm monorepo to Docker, and optimizing 3D web performance. Each is opinionated, each cites real numbers from our own deployments.
Security and compliance playbooks (3)
The playbooks our B2B buyers actually ask for: a GDPR/SOC2/DPA checklist for B2B SaaS, a NestJS + Next.js hardening guide, and an AI prompt-injection / MCP security primer. These are the documents we wish we had on day one.
What is not in this campaign
No vanity metrics, no "10 reasons to hire us," no AI-generated filler. Every post is written by the engineer who built the system, signed with their name, and dated to a specific deploy. That is the entire strategy: be useful, be specific, and let the buyer discover the rest.
How to read this in the codebase
All twelve posts live under /en/blog/{slug}. The translations to TR, NL, FR, and DE land in parallel slugs as a follow-up wave — manual translation, not machine, because the buyer-facing audience is small enough that quality beats throughput. The interactive table of contents in the right sidebar (and the collapsible one on mobile) is generated from the markdown headings; no manual anchor list to maintain.
