Skip to content

How this site is built

This site is our reference implementation

The same stack, security and discipline we sell — applied to the site you’re reading. Assembled from the project’s living architecture record.

Verified, not claimed

CI on every push · lint · audit · unit · integration · e2e
  • Layered tests: unit (logic) · 31 API integration suites against a real Postgres container · 5 Playwright e2e specs
  • Refresh-token rotation proven by test: replaying a rotated token revokes the whole session family
  • ESLint + production npm-audit gate every merge; Dependabot updates weekly
  • Integration tests run against a real PostgreSQL service container in CI, with a separate e2e job

Architecture

CLIENTAPIDATAHTTPS · httpOnly JWTSQLwebhook · APIReact SPAReact 19 · Vite · React QueryExpress API/api/v1 · routes → ctrl → modelPostgreSQL39 migrations · private RDSStripe · Anthropicpayments · AI reports
Hover or tap a component to explore its role in the system.
JWT access + refresh in httpOnly cookies · TOTP 2FA · RBAC · helmet · CORS locked · origin-check CSRF · rate limiting

Database schema

PostgreSQL with raw, numbered, forward-only migrations. UUID primary keys (gen_random_uuid()), money as integer cents, and every status lifecycle enforced by CHECK constraints that mirror the app’s status constants.

usersrefresh_tokensservicesenquiriesengagementsdeliverablesinvoicesappointmentsfeedbackproposalstender_opportunitiesengagement_milestonestime_entriesreportsengagement_risksengagement_signoffsaudit_log

Auth & JWT flow

  1. 1Login → bcrypt(12) verify → sign 15m access + 7d refresh, set httpOnly cookies
  2. 2Request → cookie sent automatically → authenticateToken verifies → req.user
  3. 3Access expires (15m) → next call 401
  4. 4Axios interceptor → POST /auth/refresh (deduped) → DB checks jti, rotates, re-issues
  5. 5Logout → refresh jti revoked server-side → cookies cleared
Try it in the Security Lab

AI-assisted reporting

env-gated

Internal and client reports can be drafted from engagement data via the Anthropic API, called server-side only — the key never reaches the browser. Generation is manually triggered, never auto-sent, and the integration is a clean no-op when no API key is configured, so dev, CI and demo environments keep working unchanged.

Docker & environments

PostgreSQL runs in Docker via docker-compose with a healthcheck and a named volume. For production, a multi-stage client/Dockerfile builds the SPA and serves it with nginx, a server/Dockerfile runs the API, and docker-compose.prod.yml wires them to Postgres. Config is validated at boot and fails fast if anything is missing.

CI/CD & cloud

Live on AWS · keyless deploys

A GitHub Actions workflow runs on every push and PR to main: install → server syntax check → ESLint → a production npm audit gate → the node:test unit suite → integration tests against a real PostgreSQL service container → client build, with a separate Playwright end-to-end job. On main, the deploy workflow re-runs that full gate, then ships behind a manual approval: it assumes an IAM role via keyless OIDC — no AWS keys stored anywhere — syncs the SPA to S3 + CloudFront, pushes the API image to ECR, and deploys it to Elastic Beanstalk, where migrations run inside the VPC before the container serves traffic and the deploy only counts if health reaches Green.