Case study · Multi-tenant SaaS · In production
Testudo
An ISO 9001 quality management platform, built from the first screen to production.
Visit testudo-pro.com- Role
- Sole developer
- Company
- Maxula Consulting
- Period
- Apr 2026 - Present
- Status
- In production
The product
Two screens from a demonstration workspace: the dashboard and the process map every company starts from.


The problem
A company certified ISO 9001 has to prove, at every audit, that its quality system is alive: documents are approved and up to date, non-conformities are analysed and closed, actions are followed, risks are assessed, indicators are measured.
Most companies run this on spreadsheets, shared folders and email. Testudo replaces them with one platform where every record has an owner, a workflow, a history and its links to the others.
My role
I am the only developer on the application. The team describes what the product must do, step by step, and I turn each step into working software: interface design, front end, API, database, tests, deployment and the server it runs on.
The AI assistant, QualiBot, is the one part I built with a colleague.
What I built
01
Twelve connected modules
Documents, audits, non-conformities, action plans, risks and opportunities, indicators, training, suppliers, customers and surveys, context, equipment checks and records. Any record can be linked to any other, and each link reads in both directions.
02
Multi-tenant with isolated data
One platform serves many companies, with each company's data isolated at the database level. A new customer workspace is provisioned and kept up to date automatically.
03
Role-based access, down to the record
Permissions per person and per module decide who can see and do what, down to a single record. Every rule is enforced by the API, not only hidden in the interface.
04
Real time by default
When one user changes something, every other user sees it without reloading, through WebSockets and targeted cache invalidation.
05
Reporting in two languages
Generated PDF sheets, Excel exports, performance reports with charts, and management review decks in PDF and PowerPoint, all in French or English.
06
An assistant that acts
QualiBot uses retrieval (RAG) to answer from ISO 9001 knowledge and the company's own documents, and can act in the product, for example by taking the user to the right screen.
Architecture
A React application talks to a NestJS API behind a reverse proxy. The API works with PostgreSQL, object storage for files and a separate Python service for AI. Everything runs in Docker on a server I set up and maintain.
Browser
React 19 · TypeScript · React Query · Tailwind CSS
Reverse proxy
Traefik · HTTPS
API
NestJS · TypeORM · REST + WebSockets
Database
PostgreSQL · data isolated per customer
Files
Object storage · PDF generation
AI service
Python · FastAPI · RAG · LLM
Quality and delivery
- automated tests across the API and the application
- 1,600+automated tests across the API and the application
- versioned releases shipped to production
- 120+versioned releases shipped to production
- languages across screens, PDFs and exports
- 2languages across screens, PDFs and exports
- modules sharing one design system
- 12modules sharing one design system
Beyond unit tests, guard tests read the source code and fail the build when a project rule is broken, so a mistake is caught before it ships. Browser scripts replay real user journeys before each release.
Stack
Other case studies
Need something like this built?
I can take a product from the first screen to production, or join an existing team.