How is it engineered?
Measured from the source repository, not estimated. As of Oct 2026.
Architecture
I built a suite of local-first Electron and Capacitor apps (POS, project manager, staff phone app) around a Next.js storefront on a multi-zone hub, with a Postgres-backed order and licence service that mints offline-verifiable keys.
Data and isolation
Desktop apps keep SQLite as the source of truth (26 versioned migrations in POS); the storefront and licence service run on 23 Postgres migrations with row-level security, money as integer cents, and POS sales handed to Finance through an append-only, idempotent outbox.
Security and privacy
- Prices pinned server-side at checkout and payment webhooks verified with RSA-SHA256 over the raw body
- Each product has its own Ed25519 licence keypair, private keys kept out of the repository, with online revocation
- Staff phone app seals every message end to end (X25519, XChaCha20-Poly1305, Ed25519) through a mailbox that holds only ciphertext, with hardware-backed key storage
- Customer passwords hashed with scrypt; rate-limit counters store hashed IPs, not plaintext
Quality evidence
| Commits | 330 across 6 repositories (28 Jun 2026 to 8 Oct 2026) | Git history |
|---|---|---|
| Licence and order service tests | 16 test files, 353 assertion call sites | Tests run against an in-process Postgres |
| Gate scripts | POS 38, staff app 33 | Named check gates including outbox crash-survival and cryptographic test vectors |
| Database migrations | 23 Postgres, 26 SQLite (POS) | Migration files and registry versions |
Operations
Storefront and hub deploy on Vercel as Next.js multi zones with sitemap, robots, llms.txt and structured data, while the POS app has a signed and notarised macOS pipeline and a CI-built Windows installer.
The problem
Selling desktop software direct to Malaysian SMEs needs more than the apps. It needs a storefront that ranks, a checkout, licence keys that work offline, trials, affiliates and an admin console to run it all.
My role
Founder of the product line and the only designer, architect and builder. Each app has its own brand accent and licence keypair under one shared standard.
Approach
- Role-based apps that work alone or together. Finance, HR, Marketing, Assistant, POS, Staff, Project and Assets, each usable standalone and syncing when enabled.
- One storefront, many zones. orbitsuite.io plus per-product zones built as Next.js Multi Zones, sharing one Organization schema graph for search.
- A commerce spine built in-house. Order intake, a CHIP gateway integration, licence minting with signed claims, trial keys, affiliates, bulk licence issuing and an admin console.
- Search built in. BM and English locale routes, comparison pages and an e-invoice landing page aimed at what Malaysian owners search for.
- A standard that compounds. A 1,063-line build standard with a 123-entry ledger of real defects, so every new app starts from the lessons of the last.
Outcome
orbitsuite.io and its Finance, HR, Marketing and Assets zones are live, with the admin console at admin.orbitsuite.io. Orbit HR, Orbit Marketing, Orbit Doc and Orbit Affiliate shipped as Developer ID signed and notarized macOS releases. CHIP payments still run in simulate mode.


