Payments platform
Project Ledger
A secure payments backend for an invoicing product, built so money is never counted twice.
- Built with
- Node.js, PostgreSQL, Docker, AWS
- Outcome
- Over $2M processed with no double payments or breaches.
The problem
A fintech invoicing system had concurrency bugs during bulk payout runs. Without cryptographic idempotency keys, the same payout could be credited twice or replayed by an attacker.
What I did
I designed a strict double-entry ledger in PostgreSQL with serializable transactions, so every movement of money balances. Public webhooks got sliding-window rate limits, services authenticate each other with mutual TLS, and the Node.js backend runs in containers on AWS ECS with defenses against the OWASP Top 10.
The result
The system has processed more than $2,000,000 in payments with no double-spends and no security breaches. It passed an external penetration test on the first attempt and kept 99.98% SLA adherence.
Have a project like this?
Book a free call