Back to all work Fintech client engagement

A financial-wellness platform, from MVP to production

I led a team of three to design, build and launch a web platform that helps South Africans get out of expensive debt, understand their money and work towards owning a home.

Role
Full-stack developer and lead
Team
Me and two developers
Timeline
2026, live in October 2026
Stack
React, TypeScript, Node.js, Supabase, Vercel

The client, product name and commercial details are withheld.

The problem

Many South Africans are stuck paying high interest on unsecured debt. The client wanted a platform that shows people where their money goes, finds quick savings, helps them unlock cash from a home or car they already own to settle expensive debt, and moves them towards qualifying for a home loan.

They needed a working MVP in production so a pilot group could use it and give feedback before the full launch.

What we built

  • Guided onboarding in five steps: personal details, debts, income, assets and separate POPIA consents.
  • A debt register covering creditor, balance, instalment and credit-life cover, with a table on desktop and cards on mobile.
  • A quick-wins engine that spots arrears to clear, unnecessary credit-life cover and overpriced debt, and estimates the monthly saving.
  • Cash-unlock calculators for home re-advances, further bonds, refinancing and car finance, with eligibility rules and lead capture.
  • Personalised repayment plans with an admin review step before users see them.
  • An AI money guide that answers finance questions, called only from the server so keys never reach the browser.
  • An admin dashboard with role-based access, showing sign-ups, onboarding completion and plans waiting for review.
  • Credit report integration through a bureau partner's API, gated on consent and built with mock and test modes.

How it works

Platform architecture GitHub Actions checks every pull request before Vercel deploys. The React app calls Vercel serverless functions, which use a shared core package and talk to Supabase and to external services for AI, payments, email and credit reports. GitHub Actions lint, type-check, 70+ unit tests and build on every pull request, then Vercel preview or production Web app React and TypeScript Vite, Tailwind CSS React Query, Zustand, Zod Serverless API Vercel functions, Node.js Shared core package for business rules and tests Supabase PostgreSQL with row-level security on every table Auth: email, Google OAuth External services, called only from the server OpenAI: money guide Paystack: subscriptions Resend: email Credit bureau, with consent

Business rules live in one platform-agnostic package that both the API and the test suite import, so a rule is written once and tested once. Staging and production run on separate databases, and every branch gets its own preview deployment.

Security and privacy

  • Row-level security on every table, denied by default, with anonymous access removed.
  • AES-256-GCM field-level encryption for SA ID numbers, and hashed IP addresses in audit logs.
  • Append-only consent and audit logs, with each POPIA consent recorded separately rather than bundled.
  • Secrets kept on the server, strict security headers (Content-Security-Policy, HSTS, X-Frame-Options) and rate limiting.
  • Soft credit enquiries only after consent, cached for 30 days so the client is never billed twice.
  • OWASP Top 10 controls documented, plus a pre-launch checklist covering penetration testing, MFA and data residency.

Problems I solved

A migration that would have broken production

A duplicated, auto-generated database migration would have failed on a fresh production build. I consolidated everything into one transactional setup script, ran it against an empty database, and confirmed it matched staging: 24 tables, 26 policies and row-level security on every table.

Keeping test data away from real users

The credit-bureau integration runs on mock data until live credentials arrive. I added a production guard so mock data can never reach a real user, with tests that enforce it in CI.

Recovering the team's Git workflow

After an accidental push to main and diverging branches, I merged the work cleanly, removed leftover low-code platform files, repaired a corrupted lockfile and moved the team to pull requests with branch protection.

A bug that broke typing in every form

A modal focus issue stopped users typing in forms across the app. I fixed it at the source, then led a responsive pass over about 20 screens, checked with Playwright at phone, tablet and desktop sizes.

Going live

I wrote and ran the go-live runbook: production database build, auth URLs, custom email delivery, publishing the Google sign-in consent screen, environment variables, smoke tests and a rollback plan.

Outcome

  • Live in production since October 2026, with a pilot group giving feedback before the full launch.
  • Every pull request passes lint, type-checks, 70+ unit tests and a production build before it can merge.
  • I built the operating-cost and break-even model the client used to set subscription pricing.
  • Live credit-bureau access is waiting on production credentials. The guard keeps mock data out until then.