01 Platform
Four systems. Ours to build, ours to run.
Software we wrote, deployed and run.
02 The four systems
What each one actually looks like.
Real capture. Taken in dev mode on mock fixtures. The app says so in a banner inside the frame.
Outreach engine and ops console
Finds the lead and sends the first email within daily caps. Replies and follow-ups wait for a person to approve.
Drawn, not captured. Every route holds real client traffic behind that client's own login. Figures shown are sample values.
Client analytics portal
Your traffic, behind your own login. Separation is a database rule, not a filter in the chart.
Drawn, not captured. Live project and invoice data sits behind authentication.
Client portal and admin console
Projects, invoices, change requests and chat. One app, two sides of a role gate.
Drawn, not captured. This one has no interface: it is the endpoint under the enquiry forms we build for clients.
Lead-capture API
Validate, screen, write, notify. Success only once the row exists.
03 Our own products
We ship under our own name too.
Not client work. Products Fluxaro owns, builds and runs.
LoreRoad
A road-trip co-pilot. It surfaces the history, the landmarks and the strange local legends along your route exactly as you reach them, and reads them aloud so the driver never looks down. Free trip to try, then Basic or Family.
www.loreroad.comBurrin
Work management for small studios. Tasks, the planner, documents and the conversation held as one record, so delivery never depends on one person remembering it. Personal space free, team spaces paid.
04 Security posture
Written down, rather than implied.
Behaviour in the code, not a certification.
- Tenant isolationRow-level security in Postgres, so separation is a database rule rather than an application convention.
- Choke-pointOne access function every read passes through, which keeps the isolation reviewable in a single place.
- SecretsServer-only API wrappers. No analytics key, service key or provider token ships in a client bundle.
- Script policyPer-request nonce-based CSP. An inline script without this request's nonce does not run.
- Rate limitingLogin attempts limited by IP address and by email address, backed by Upstash.
- InputZod schemas at every external boundary. Nothing untyped reaches a query.
- Account surfaceNo public sign-up route. Accounts exist because the studio created them.
- Auth responsesGeneric errors on failed sign-in, so the form cannot be used to discover registered addresses.
- Model riskGenerated replies never send unattended. A person approves in a chat loop.
- Threat mapsAn OWASP Web map, an OWASP LLM map and a security document, kept in the repository with the code.
- Response headersHardened on the static builds as well, not only the applications. Clarity ships them.
05 Next
Bring us the system behind the site.
Portals, dashboards, consoles, endpoints. Tell us where the data lives and who may see it.