Skip to content
← Portfolio

CybaVerse

Compliance SaaS. I built the web vulnerability scanner as a contract senior engineer.

Project
Web application
Date
Stack
Next.js, tRPC, TypeScript, Tailwind CSS, Hasura, PostgreSQL, Playwright

At a glance

  • Role: Contract senior full-stack engineer, August–November 2024, on an established team.
  • Stack: Next.js, TypeScript, tRPC, Hasura GraphQL, PostgreSQL and Playwright.
  • Outcome: Built scan targets, on-demand scans and result workflows with tests; contributed roughly 200 commits.
CybaVerse vulnerability scanning dashboard showing External Scanning, Web Application Scanning, and Internal Scanning modules
CybaVerse Web Application Scanning results table listing informational-severity findings from a scheduled scan

Key features

Compliance workflows

Cyber Essentials audit flows and integrations with Qualys and OWASP ZAP scanning bring vulnerability and compliance data directly into the platform. Scans are orchestrated through Windmill: tRPC routers call Windmill job endpoints to kick off Qualys external-IP scans and OWASP ZAP web-application scans, then poll and persist results back through Hasura, so organizations can track certification status alongside their actual security posture.

Marketplace and billing

The marketplace connects organizations with security service providers, and Maxio handles billing. Most client state runs through tRPC and React Query. Redux Toolkit is limited to the authenticated user and auth token rather than owning the marketplace domain.

Testing at scale

With around 20 contributors working in parallel, the project used Playwright, Cypress, and Storybook to catch regressions in a fast-moving, security-sensitive codebase.

Working in an established codebase

The project already had 2,676 commits when I joined, so consistency mattered across its roughly 518 TSX files. I followed its established conventions for tRPC procedures, Hasura permissions, and component structure instead of introducing parallel approaches.

Architecture

Scroll to see the full diagram →

CybaVerse architecture: a Next.js 13 T3 app over its own tRPC layer, backed by Hasura/GraphQL on PostgreSQL, with Zitadel SSO, Maxio billing, and a Windmill-orchestrated Qualys and OWASP ZAP security-scanning pipeline.
A T3 app over its own tRPC layer, Hasura/GraphQL data, and a Windmill-orchestrated scanning pipeline.

Frontend: Next.js 13 with TypeScript, styled with Tailwind CSS and shadcn/ui components. Redux Toolkit is limited to one session slice containing the current user and auth token. Everything else runs through tRPC and React Query.

API layer: tRPC provides end-to-end type safety across 25 routers between the Next.js frontend and backend services.

Data layer: Hasura exposes a GraphQL API over PostgreSQL. Zitadel and NextAuth handle SSO authentication.

Scan orchestration: Windmill runs the Qualys and OWASP ZAP scan jobs. tRPC routers trigger and poll the jobs over HTTP, then write the results back through Hasura.

Infrastructure: Vercel hosts the Next.js frontend and its API routes. DigitalOcean runs Hasura, Windmill, Zitadel, and PostgreSQL. Pulumi and Nix define the infrastructure so the team can reproduce each environment.

Testing: Playwright and Cypress cover end-to-end flows, while Storybook isolates and documents components during development.

Hiring for a senior full-stack role?