zsty.us

Before / After · Case Study

Global Merchant Processing — security audit → frontend rebuild (client engagement)

A friend's company in the merchant-processing space — name and domain held back until the client signs off on public attribution. The work started as a passive security audit of the current frontend. The audit surfaced serious vulnerabilities that warranted an end-to-end rebuild rather than a patch pass. The rebuild is in flight on the same operator stack used across the rest of the portfolio.

When a passive audit surfaces serious holes in a friend's frontend, the right move is rebuild — not patch.

The story

Problem · Insight · Build · Outcome.

  1. 01 · Findings

    Passive audit surfaced serious frontend security holes.

    Standard pre-engagement scan turned up issues that went beyond what a patch sweep would responsibly address. Findings shared privately with the client; not published while the rebuild is in flight.

  2. 02 · Decision

    Rebuild, not patch.

    With a friend's business on the line, the honest call was a full frontend rebuild on the operator's modern stack rather than a fix-and-pray sweep. Client agreed; engagement opened.

  3. 03 · Build

    In flight on the operator stack.

    Same Next.js + TypeScript strict + Drizzle/Neon + Vercel stack used across the rest of the portfolio. Customer-facing flows rebuilt first; admin + data migration follows. Detailed scope held pending client sign-off on public attribution.

  4. 04 · Pending public attribution

    Public case study unlocked when the client signs off.

    When the client confirms what's safe to publish — name, domain, sector, before/after screenshots — this entry flips `pendingApproval: false` and lands the full case study. Until then it's reachable only by direct URL with `noindex,nofollow`.

Stack

What it ran on. What it runs on now.

Before

  • Vendor-controlled frontend with disclosed vulnerabilities
  • Findings withheld pending client sign-off

After

  • Next.js (App Router)
  • TypeScript strict
  • Drizzle ORM + Postgres (Neon)
  • Operator-owned hosting (Vercel)
  • Compliance-aware copy + disclosures

What changed

Grouped by what kind of system shipped.

Each claim ships with concrete evidence — env vars, table names, cadence chips. No marketing fluff.

Agent backbone

Audit-first engagement model

The work started with the same passive-scan pattern used to qualify other prospects: surface what's broken or risky before pitching a fix. The findings on this site were severe enough that a patch pass wasn't appropriate — a rebuild was the honest recommendation.

Design

Frontend rebuild on the operator stack

Rebuild keeps the company on its own brand surface but rehosts the customer-facing flows on the operator's modern, source-controlled stack — Next.js with TypeScript strict, Drizzle/Neon for data, Vercel for hosting. Removes the classes of frontend issues that drove the original findings.

Retention

Client-confidential until shipped

Name, domain, and the specific vulnerabilities are withheld from this public entry while the rebuild is in flight. Publishing them now would publicly advertise an unpatched surface against a friend's business.

← All rebuilds

Global Merchant Processing — security audit → frontend rebuild (client engagement) — zsty.us