Commissioned by a client in the education sector — source code under NDA
For a client in the education sector I designed and built a fully scalable, multi-tenant Learning Management System. The platform serves multiple education organisations simultaneously on a single shared infrastructure, with full data isolation per organisation and an advanced role and permission system.
The system is built end-to-end — from database architecture and security layers to API and user interface — and is running in production. The full source code is owned by the client and covered by a non-disclosure agreement, so this description focuses on functionality, architecture, and technical choices.
Key functionality
- Multi-tenant architecture with strict data isolation per organisation
- Extensive role hierarchy: super-admin, content manager, admin, teacher, student, parent
- Full course management with hierarchical structure (course → sections → units → lessons)
- Lesson-material editor with rich text, learning goals, slides, and evaluations
- Exam module with a question bank, automatic grading, assignment per class, and detailed result reports
- Class management including progress tracking per class per course
- Licence system for access control with automated expiry handling
- Materials library and document management with cloud storage
- Feedback mechanisms, audit logging, and soft-delete with retention policies
Security & compliance
- Dual authentication layer (API key + JWT)
- Row-Level Security at the database level for multi-tenant isolation
- End-to-end encryption of all business-critical data at rest (AES-256 via pgsodium) — intellectual property, personal data, and assessment data
- GDPR-compliant with separate encryption keys per data category
- CAPTCHA protection, rate limiting, IP-threat blocking, strict CORS and CSP headers
- Request-scoped database clients to prevent session leaks
Tech stack
- Frontend: Nuxt 3, Vue 3 (Composition API), Nuxt UI, TailwindCSS, Tiptap rich-text editor
- Backend: Node.js, Express.js (ES Modules), Joi validation, Winston logging
- Database: PostgreSQL via Supabase, Row-Level Security, secure views with INSTEAD OF triggers, pgsodium encryption
- Infrastructure: containerised deployment, automated cron jobs for licence expiry, log cleanup, soft-delete purge, and threat-list updates
- External integrations: Cloudflare Turnstile, AbuseIPDB, Google Analytics
Scale
Production environment with 30+ database tables, 125+ migrations, around 40 API controllers, 30+ business-logic modules, 90+ UI components, and 33 Vue composables.
My role
End-to-end responsibility for architecture, development, and delivery — database design, API design, frontend implementation, security, and deployment. Close collaboration with the client for functional alignment and iterative delivery.
