02
AI-built software
Software I designed and shipped using AI as my on-demand engineering team — marked honestly by stage. A suite of live systems delivered for an enterprise client, and two independent founder ventures: an early-stage care SaaS, and Sentinel, a security platform live in production with invite-only users.
Deployed · early testing
Founder · Independent venture
Care SaaS Product
A multi-tenant care-records SaaS for the care sector
An independent, multi-tenant SaaS I'm building for the care sector as founder — a ground-up rebuild of the care record as a product other providers can subscribe to, rather than a single-tenant tool. It's deployed on managed cloud hosting and in early testing, built by directing AI against my own architecture and everything I learned shipping live systems for a real care provider.
- Founder-owned — product vision, system architecture, and roadmap are mine, built independently of any client engagement.
- True multi-tenancy — each provider's data is isolated at the database by row-level security, with the isolation proven by an automated tenant-isolation test suite that runs on every build.
- Full SaaS machinery — self-serve organisation sign-up, role- and permission-based access, subscription billing, and an operator control plane with audited, logged support access.
- NHS-interoperable — NHS number verification (PDS) and GP-record retrieval (GP Connect) built in, sandbox-ready ahead of formal NHS onboarding.
- AI-built, continuously shipped — a React / TypeScript front end on a Supabase backend with serverless functions, deployed to the cloud on every change; directing AI models against precise specs to move at startup speed.
Early-stage product, deployed and in testing. Independent of the Ashlotrimcare client work below.
Live & in use
Client engagement · Architect & builder
Enterprise Care Systems — Suite of 3 Live Apps
AI-built business systems for Ashlotrimcare Ltd, a CQC-approved care provider
Engaged independently to modernise how Ashlotrimcare runs, I used AI as my on-demand engineering team to design and ship three live business systems — replacing paper, spreadsheets, and manual processes across care delivery, hiring, and staff operations.
- Care records app (single-file JavaScript PWA) — a full digital care record: medications with MAR charts and round-based administration, care plans, risk assessments, daily notes and NEWS2 observations, body maps, safeguarding and incident logging, staff rota and clock-in — installable and offline-capable, with automatic office escalation the moment a medication dose is missed.
- Recruitment portal — streamlines candidate intake and hiring workflows for the provider.
- Rota & payroll system — automates staff scheduling and pay, removing manual, error-prone processes.
- Enterprise-grade foundations — authentication and row-level security designed around UK GDPR and care-sector data-protection principles across all three.
Delivered as independent client/contract work. Compliance framing: designed around UK GDPR and CQC principles; not independently certified/audited.
Live · invite-only (pre-launch)
Founder-engineer · Independent venture
Sentinel
Authorization-first security & launch-readiness platform for SMB and BaaS apps
A security platform I architected and shipped as sole founder — I defined the system logic and security model, and directed AI as my on-demand engineering team to build it. Sentinel finds the access-control and backend-misconfiguration flaws that quietly leak data in modern "backend-as-a-service" apps — the failures a generic scanner misses — and gives founders a clear go/no-go verdict before they ship. It runs in production as a full multi-tenant SaaS.
- Deep BaaS authorization testing — dedicated engines for Supabase (row-level-security bypass), Firebase, GraphQL, and Appwrite that probe the real ways these backends leak other users' data, not just generic web checks.
- A full assessment suite — external scanning with live CVE data, BaaS-aware code (SAST) analysis for CI/CD, load and integration testing, and one combined go/no-go "Go-Live" verdict that folds them together.
- Authorization-first by design — proof-of-ownership gating, encrypted secrets, a full audit trail, and destructive checks off by default, so it fits a professional (CREST-style) engagement rather than "point a scanner and go."
- Engineered as a real SaaS — database-per-tenant isolation, subscription billing, a background job queue, TOTP multi-factor auth, automated backups, and an admin control plane — built with zero external runtime dependencies and backed by 150+ automated tests.
- Shipped end-to-end, solo — product, security engineering, full-stack build, and live deployment (Docker + automatic HTTPS) all owned independently.
Live in production and feature-complete; currently invite-only ahead of commercial launch. Built as a force multiplier for security testers, not a replacement — and not independently audited/certified.