Skip to content

[Platform]

The parts that earned their place.

The engineering behind what we build: edge runtimes, databases that hold authority rather than the client, and test suites pointed squarely at the trust boundary. Different products reach for different tools — these are the ones that earned their place.

Stack summary
  • EdgeCloudflare Workers
  • AuthorityPostgres + SQLite
  • CoordinationDurable Objects
  • CryptoAES-256-GCM, jose
  • TestsVitest + E2E

Edge runtime

Cloudflare Workers & Pages

Every product deploys to Cloudflare — Mangofold serves its web export from Pages, FamilyFolds runs on Workers with a Durable Object per household. One account, one set of logs, one bill.

  • Workers
  • Pages
  • KV
  • Response Store

Compute

Durable Objects & Queues

Coordination belongs in a single writer, not in hopeful concurrent requests. FamilyFolds runs one FamilyCoordinator per household and reconciles its ledger events into D1 through an idempotent queue consumer.

  • Durable Objects
  • Queues
  • Cron triggers
  • D1

Authority

Postgres & SQLite as the source of truth

Authorisation is never delegated to a client. Mangofold expresses membership, roles and blocking as row-level security policies in Supabase Postgres; FamilyFolds writes an append-only ledger into D1.

  • Row-level security
  • Append-only ledger
  • Composite foreign keys
  • Migrations

Privacy

Encryption and blind indexes

bottlemail encrypts recipient addresses with AES-256-GCM and looks them up through a peppered HMAC-SHA256 blind index, so the server can route a message to an inbox it cannot read.

  • AES-256-GCM
  • HMAC blind index
  • Zero-knowledge design
  • Signed URLs

Verification

Tests aimed at the boundary

The interesting failures in a multi-tenant app happen at the trust boundary. Mangofold ships 188 row-level-security assertions and a 21-test end-to-end suite to hold that line.

  • Vitest
  • E2E suites
  • zod at boundaries
  • Deploy dry-runs

Operations

Boring on purpose

Retries that survive a flaky push response, cron sweeps that reconcile without double-counting, health endpoints, and strict security headers. Nothing here is interesting, which is the goal.

  • pg_cron retries
  • Health endpoints
  • Strict headers
  • Observability

[Request path]

How a request flows.

A single request through a Grallumae product, end to end.

  1. 01

    Request

    Cloudflare terminates the request at the nearest edge and applies the strict header set before anything executes.

  2. 02

    Verify the actor

    The edge function verifies the caller's identity and resolves their membership. Unverified calls never reach the database.

  3. 03

    Authorise in SQL

    Row-level security policies decide what this actor may read or write — regardless of what the client asked for.

  4. 04

    Return the minimum

    Responses project named columns only. There is no code path that serialises data the caller was not entitled to.

A modified client gains nothing at step 03, because it never supplied the answer.

[The stack]

Technologies, in use.

Everything we run, and where it earns its place. Nothing on this list is aspirational.

LayerTechnologyUsed in
EdgeCloudflare WorkersFamilyFolds
Static hostingCloudflare PagesMangofold
Application frameworkExpo / React NativeMangofold
Application frameworkNext.jsbottlemail, this site
Application frameworkFlutterFamilyFolds
Primary databasePostgres (Supabase)Mangofold
Embedded databaselibSQL / SQLitebottlemail
CoordinationDurable ObjectsFamilyFolds
CoordinationSupabase RealtimeMangofold
Serverless functionsDeno Edge FunctionsMangofold
QueuesCloudflare QueuesFamilyFolds
Object storageSupabase Storage / R2Mangofold, FamilyFolds
AuthenticationSupabase Auth, OIDC + JWKSMangofold, FamilyFolds
Cryptographynode:crypto, josebottlemail, FamilyFolds
Build & deliveryEAS OTA updatesMangofold
TestingVitest, Playwright, hand-rolled suitesAll

[Principles]

What we will not compromise.

The engineering positions we hold across every product, whatever the stack underneath happens to be.

Never trust the client

If a permission decision can be influenced by a value the caller supplied, it is the wrong place to make that decision. It belongs in a policy or in server code.

Never ship a claim you cannot test

Every status label, limit and number on this site was read out of the code. When something is unfinished, the page says so.

Never collect what you do not need

The best privacy feature is the field that does not exist. Our products store as little as the feature requires and no more.

Never make failure silent

Push retries through a cron sweep, queue consumers reconcile idempotently, and the safety layer refuses rather than degrading quietly.

[Where each one uses it]

Each product, and its stack.

The same primitives, assembled three different ways.

Live

Mangofold

Expo SDK 57 · React Native 0.86 · TypeScript · NativeWind / Tailwind

Building

FamilyFolds

Flutter · Dart · Material 3 (customised) · Cloudflare Workers

Archived

bottlemail

Next.js 14 · React 18 · TypeScript · Tailwind CSS

Building

Slateberry

Kotlin 2.3 · Jetpack Compose · Material 3 · Firebase Auth

Building

Fivefold

Vanilla JavaScript (ESM) · Node.js build tooling · Capacitor 8 · JSON content pipeline

Building

My Mini Cafe

Godot 4.7 · GDScript · 3D (orthographic camera) · Godot Resources (.tres data)

[Get in touch]

Want this stack working for you?

We build on this stack for other teams too — migrations, hardening, or taking an idea from zero to deployed.

Taking on select projects for 2026