Multi-tenant SaaS, financial ERPs, real-time platforms and mobile apps, designed, shipped and operated in production. Product engineer and co-founder of CodeMines.

1,660
commits shipped since 2024
17
products in production
5
apps on the App Store and Play Store
3
years shipping products end to end

How I build

Click through a real system.

How one request can't reach another shop's data. Every node is something that exists in production code today.

More systems
where: { organizationId }Access tokenorganizationId insideTenantGuardmembership re-resolvedPermissionsGuardcatalogue, not rolesServicepasses organizationId explicitlyPrisma tenant extensionrefuses unfiltered queriesPostgreSQL 16one schema, many shops

Access token

Tenant identity lives in the token, nowhere else

The organization a caller belongs to is carried in the signed access token. Controllers never read organizationId from a request body, a header or a query string. Those are all under the client's control. If you can't forge the token, you can't claim another shop.

// Controllers derive tenant from AuthContext, never from the request.
export interface AuthContext {
  userId: string;
  organizationId: string;
  membershipId: string;
  role: Role;
  branchId: string;
  allowedBranchIds: string[];
  canAccessAllBranches: boolean;
  terminalId: string | null;      // set when a paired till fixes the branch
  permissions: Set<Permission>;
}

What I build

Four kinds of product, end to end.

Each one links to a case study where I did exactly that.

01

SaaS and web platforms

Multi-tenant products with real permission models, billing, reporting and the operational back office behind them. NestJS and PostgreSQL behind Next.js.

  • Tenant isolation enforced at the ORM
  • Permissions over roles
  • Stripe, S3, Redis, BullMQ, Socket.IO
  • Swagger, e2e tests, stable error contracts
See it in a case study
02

ERPs and financial systems

Inventory, sales, purchasing and accounting where the numbers have to reconcile. Integer money, lot costing, double-entry ledgers, append-only history.

  • Money as a value object, never a float
  • FIFO / landed-cost inventory
  • Ledgers an auditor can replay
  • Multi-currency purchasing
See it in a case study
03

Mobile apps, through store review

React Native and Expo apps that ship (maps, payments, real-time, on-device ML) and the backends they talk to. Five on the App Store and Play Store.

  • Expo / NativeWind
  • Stripe React Native, maps, push
  • Live camera and TensorFlow pipelines
  • App Store and Play Store submission
See it in a case study
04

Deployment and operations

The part after shipping. Docker images to GHCR, SSH deploys to a VPS behind nginx, GitHub Actions for CI, and runbooks as workflows so production can be diagnosed without me.

  • GitHub Actions CI/CD
  • Docker, nginx, VPS provisioning
  • Vercel for front ends
  • Diagnostics and data repair as one-click workflows
See it in a case study

Process

How a project runs with me.

Four stages, each with a concrete deliverable at the end.

The full process
  1. 01

    Discovery

    What the product has to do, who pays, what breaks if it's wrong.

  2. 02

    Architecture

    Data model, boundaries, the security model, what's deliberately out of scope.

  3. 03

    Build

    Small reviewable diffs, tests that run against a real database, written updates.

  4. 04

    Ship

    CI to a real environment, store submission, a runbook you can operate without me.

About

Co-founder of CodeMines. Engineer first.

Three years of shipping products end to end: a contract at an IPTV business, independent product work, a year at SparkTech Agency, and now CodeMines, the studio I co-founded. 1,660 commits across 81 repositories, most of it multi-tenant SaaS, financial systems and mobile apps that real businesses run on. I work in TypeScript across the whole stack, I measure before I change things, and I don't ship code I can't explain line by line.

More about me

Have a product to build, or one that needs to work better?

Two or three sentences is enough. I'll come back with what I'd do, how long it takes and what it costs.