All work

Payments platform

Project Ledger

A secure payments backend for an invoicing product, built so money is never counted twice.

Built with
Node.js, PostgreSQL, Docker, AWS
Outcome
Over $2M processed with no double payments or breaches.
Project Ledger artwork
$2M+processed
Zerodouble-spends
100%audit pass

The problem

A fintech invoicing system had concurrency bugs during bulk payout runs. Without cryptographic idempotency keys, the same payout could be credited twice or replayed by an attacker.

What I did

I designed a strict double-entry ledger in PostgreSQL with serializable transactions, so every movement of money balances. Public webhooks got sliding-window rate limits, services authenticate each other with mutual TLS, and the Node.js backend runs in containers on AWS ECS with defenses against the OWASP Top 10.

The result

The system has processed more than $2,000,000 in payments with no double-spends and no security breaches. It passed an external penetration test on the first attempt and kept 99.98% SLA adherence.