HW
All work

Case study · Multi-tenant SaaS · In production

Testudo

An ISO 9001 quality management platform, built from the first screen to production.

Visit testudo-pro.com
Role
Sole developer
Company
Maxula Consulting
Period
Apr 2026 - Present
Status
In production

The product

Two screens from a demonstration workspace: the dashboard and the process map every company starts from.

https://app.testudo-pro.com
Testudo dashboard: quality indicator charts
https://app.testudo-pro.com
Testudo process map: management, operational and support processes

The problem

A company certified ISO 9001 has to prove, at every audit, that its quality system is alive: documents are approved and up to date, non-conformities are analysed and closed, actions are followed, risks are assessed, indicators are measured.

Most companies run this on spreadsheets, shared folders and email. Testudo replaces them with one platform where every record has an owner, a workflow, a history and its links to the others.

My role

I am the only developer on the application. The team describes what the product must do, step by step, and I turn each step into working software: interface design, front end, API, database, tests, deployment and the server it runs on.

The AI assistant, QualiBot, is the one part I built with a colleague.

What I built

01

Twelve connected modules

Documents, audits, non-conformities, action plans, risks and opportunities, indicators, training, suppliers, customers and surveys, context, equipment checks and records. Any record can be linked to any other, and each link reads in both directions.

02

Multi-tenant with isolated data

One platform serves many companies, with each company's data isolated at the database level. A new customer workspace is provisioned and kept up to date automatically.

03

Role-based access, down to the record

Permissions per person and per module decide who can see and do what, down to a single record. Every rule is enforced by the API, not only hidden in the interface.

04

Real time by default

When one user changes something, every other user sees it without reloading, through WebSockets and targeted cache invalidation.

05

Reporting in two languages

Generated PDF sheets, Excel exports, performance reports with charts, and management review decks in PDF and PowerPoint, all in French or English.

06

An assistant that acts

QualiBot uses retrieval (RAG) to answer from ISO 9001 knowledge and the company's own documents, and can act in the product, for example by taking the user to the right screen.

Architecture

A React application talks to a NestJS API behind a reverse proxy. The API works with PostgreSQL, object storage for files and a separate Python service for AI. Everything runs in Docker on a server I set up and maintain.

Browser

React 19 · TypeScript · React Query · Tailwind CSS

Reverse proxy

Traefik · HTTPS

API

NestJS · TypeORM · REST + WebSockets

Database

PostgreSQL · data isolated per customer

Files

Object storage · PDF generation

AI service

Python · FastAPI · RAG · LLM

Quality and delivery

automated tests across the API and the application
1,600+automated tests across the API and the application
versioned releases shipped to production
120+versioned releases shipped to production
languages across screens, PDFs and exports
2languages across screens, PDFs and exports
modules sharing one design system
12modules sharing one design system

Beyond unit tests, guard tests read the source code and fail the build when a project rule is broken, so a mistake is caught before it ships. Browser scripts replay real user journeys before each release.

Stack

React 19TypeScriptViteReact QueryTailwind CSSNestJSTypeORMPostgreSQLWebSocketsPuppeteerPythonFastAPIDockerTraefikJestVitestPlaywright

Other case studies

Need something like this built?

I can take a product from the first screen to production, or join an existing team.