How is it engineered?
Measured from the source repository, not estimated. As of Oct 2026.
Architecture
Next.js 16 App Router on Vercel (Singapore region) with Supabase Postgres; 50 server-action modules and 14 route handlers; six-role model where employer companies are tenants scoped by membership in Postgres policies.
Data and isolation
Postgres via 157 SQL migrations defining 124 tables, every one with row-level security and 278 named policies; money stored as integer sen across 55 *_cents columns, SST computed in basis points read from settings.
Security and privacy
- Row-level security on all 124 tables; company HR can read only employer-funded enrolments of their own company, enforced in the database policy.
- Payment webhook verifies an RSA-SHA256 signature on the raw body, then settles through a single database function keyed on the gateway reference.
- Server-side Zod validation in 44 modules, honeypot on public forms, PDPA consent required by both schema and insert policy.
- Append-only audit_logs table written by a locked-down security-definer function (62 call sites in migrations); public credential verification returns only safe fields.
Regulatory rules in code
Implements HRD Corp employer-funded enrolment and claim tracking (hrd_claims) with the HRD Corp Output Assessment reproduced verbatim in two languages, SST as configurable basis points, and PDPA consent enforced at the database; e-invoicing (MyInvois) is absent.
Quality evidence
| Commits | 289 (Jun 10 to Oct 7, 2026) | git history of the main repo |
|---|---|---|
| Schema migrations | 157 | versioned SQL migration files |
| Scripted integration checks | 84 (44 database test scripts, 40 verify scripts) | scripts run against the live schema with pass/fail assertions and fixture cleanup |
| Unit test cases | 12 in 2 files (money, authorisation) | Vitest it/test calls |
| CI gates | 5 gates on every push | GitHub Actions: secret scan, lint, typecheck, tests and production build on every push and pull request |
Operations
Deployed to Vercel in the Singapore region with a domain-alias script; errors go through one reportError rail emitting structured, stack-bearing log lines (Sentry hook present but not wired); no cron jobs or automated backup config in the repo.
The problem
MSDI had a Lovable prototype with more than 225 routes, mostly running on a mock data store. It demoed well, but it could not take a real enrolment, a real payment or issue a real credential.
My role
Design, architecture and build of the production platform, plus a macOS admin wrapper app for staff.
Approach
- A real catalogue. Programmes, certifications and MQA qualifications at MQF levels 4 to 7, RPEL and APEL, and HRD Corp claimable courses.
- End-to-end enrolment. Enrolment and payment with CHIP in integer sen, SST-aware invoices and company bulk enrolment.
- Credentials people can verify. QR-verified credentials and a digital student ID.
- The back office too. Trainer and learner operations, finance and staff modules for leave, claims, commissions, permissions and careers.
Outcome
All 10 milestones, M0 to M9, are built and verified: 6 roles, 48 pages and 0 errors, with a public Lighthouse score of 100, 100, 96 and 100.


