Skip to contentFree 30 minute call with Pali

Engineering

How I engineer production software

I design and build production software to one written standard: validate every input on the server, isolate each tenant’s data in the database, keep money exact, ship schema changes as migrations, and test the riskiest logic automatically. Each case study shows its architecture and quality figures, measured from the source repository rather than estimated.

What do the numbers say?

Products live
10
Automated tests and checks
2,740
Schema migrations
1,189
Commits
3,971

Summed from the engineering block of each public case study. Products without a measured figure are left out, not counted as zero.

What standard does every build follow?

  • Validate on the server

    Every input is checked again on the server, with zod schemas on the web apps. The interface is never trusted.

  • Isolate every tenant

    Each row is scoped to its organisation or household and enforced by row-level security in the database.

  • Nothing hardcoded

    Prices, limits, roles and settings live in config or data, so a business change is not a code change.

  • Money is exact

    Amounts are stored as integer sen or fixed-point decimals. Never floating point.

  • Schema changes are migrations

    Database changes ship as numbered, reviewed migrations that run the same way in every environment.

  • Test what can hurt

    Payroll is tested against official tables, ledgers against balance invariants, payments and isolation by suite.

  • Privacy by default

    PDPA consent before data is stored, field-level encryption for identity numbers, export and erasure built in.

  • Verify, then trust

    Payment webhooks are signature-checked on the raw body; licence keys are signed and verified offline.

Which products show this in practice?

Each row links to the full case study with architecture, data, security and quality detail.

Which regulated environments has Pali worked in?

The role is stated plainly: some of this work was design only, some was design and build.

  • PERKESO

    Design

    Public sector, social security

    Solo designer of the national Employment Insurance portal

  • TNB (myTNB)

    Design

    National utility, regulated tariff

    Solo designer of the RP4 tariff experience, with Accenture

  • MIDF Invest

    Design

    Securities trading

    UI/UX design lead on the retail trading platform

  • Hong Leong Bank

    Design

    Banking

    Founding design team of the HLB Connect app

  • Roche

    Design

    Pharmaceutical

    Senior UI/UX designer, design system for a data product

  • Orbit HR

    Design and build

    Statutory payroll

    KWSP, PERKESO, EIS and PCB calculations, designed and built

  • Orbit Finance

    Design and build

    Accounting and tax

    Double-entry books with LHDN MyInvois e-invoicing and SST-02, designed and built

  • Payung

    Design and build

    Insurance distribution

    Branded comparison apps for licensed agents, designed and built

When is Pali the wrong choice?

I am one senior lead working with an AI agent team, and I review every decision myself. That suits founders, SMEs and product teams who want a product designed, built and shipped in weeks. It does not suit a programme that needs 20 engineers on day one or a dedicated platform team. For that, hire an agency or build an in-house team; I can still lead product and design inside it.

Frequently asked questions

Yes, for products a single senior lead can own end to end. Every build follows the same written standard: server-side validation, tenant isolation in the database, exact money, migrations and automated tests on the riskiest logic. The figures on each case study are measured from the source code.

Each record carries its organisation or household, and the database enforces that scope with row-level security policies: 522 of them on UrusPro, 278 on MSDI. The interface hiding data is never the only guard.

Each product has automated tests on its riskiest logic: payroll against official tables, ledgers against balance invariants, payments and data isolation. Several run in CI on every push, and each milestone ends with a smoke test of the real app.

You do. The code and the IP are yours once each invoice is paid, and every product is built on standard tools so another team can take it over.

Yes. Shipped products implement KWSP, PERKESO, EIS and PCB payroll with tests against the official tables, LHDN MyInvois e-invoice submission, SST-02, HRD Corp claims and PDPA consent, export and erasure.

Want something like this built?

Get a price in two minutes, or talk it through on a free call.