Home/ Works
HR / Compliance

A Whistleblowing System: One-Week Prototype in Next.js + Prisma, Then Launched as PM-Led Delivery

Compliance-focused SaaS provider

We built a new whistleblowing system for enterprises on Next.js + Prisma + NextAuth + Resend. With a small team of one PM and one developer, we completed a working prototype in a week and carried it through to release in roughly five person-months.

Before / After

What changed

  • Prototype delivered
    A working build shown in one week
  • Effort
    About 5 person-months to release
  • Team
    1 developer + a team of about 10
Challenge

Challenge

A whistleblowing system has to fully protect the anonymity of the reporter while routing each report only to the right handler through a well-defined escalation flow. Who can see which report, at what stage anyone gets notified, how the logs are kept — unless these are nailed down at the design level, the trustworthiness of the service itself is at stake. Speed was also a requirement: with a single developer supported by a PM, the client wanted to get something working out early and bring stakeholders on board.

Approach

Approach

  1. 01 Mapped the lifecycle of a report and its roles (reporter, intake, handler, administrator)
  2. 02 Built a prototype in one week with Next.js (App Router) + Prisma and put a working build in front of stakeholders
  3. 03 After the prototype, refined it step by step while incorporating feedback
  4. 04 Took on requirements, prioritization, and delivery management as PM so the single developer could stay focused
  5. 05 Implemented the authentication flow with NextAuth and built in role-based access control
  6. 06 Set up secure email notifications (escalation) with Resend and error monitoring with Sentry
Key Success Factors

Key success factors

The impact of a one-week prototype
Getting a working build out early shifted stakeholder discussion from the abstract to something concrete.
PM-led delivery support
Even with a single developer, separating requirements, prioritization, and delivery management kept implementation focused.
Rigorous role design
By clearly separating the four roles — reporter, intake, handler, administrator — we secured the permission boundaries at the design level.
A modern stack choice
A full-stack combination of Next.js App Router + Prisma + NextAuth balanced development speed with maintainability.
Solution

Solution

We built it as a full-stack application on Next.js + Prisma + NextAuth, shaped a working prototype in one week, and reached release in about five person-months. The PM focused on requirements and delivery management so the developer could concentrate on implementation. We stood it up as a foundation that keeps its momentum while balancing reporter anonymity with a clear escalation flow.

Facing a similar challenge?

Whatever your industry or scale, let's start with a conversation.

Contact form
Related

Related case studies & guides

Building and Operating a Whistleblowing System with Guaranteed Anonymity

We built an intake and management system for internal whistleblowing that complies with the Whistleblower Protection Act. It balances reporter anonymity with separation of access privileges, providing a foundation that manages everything from intake to response records in one place.

ComplianceSecurity

A Statutory Recordkeeping Service for Security Companies

A service that digitizes the creation and management of the statutory records required under the Security Business Act. It brings records that tend to be handled on paper—such as guard rosters and training and instruction logs—into a single flow, from data entry to storage and output.

SaaSCompliance

Developing and Operating "Kitei Log," a Policy-Management SaaS, In-House

We develop and operate "Kitei Log," a SaaS that centrally manages the creation, revision, dissemination, and view records of internal policies, manuals, and labor-management agreements—in-house. It lets you graduate from file-name workflows and maintain a change history that stands up to ISMS and Privacy Mark audits.

SaaSCompliance

The Benefits of Migrating from WordPress to Cloudflare | AI-Native Content Operations, Speed, and SEO Optimization

The advantages of moving away from the maintenance and security burden of WordPress to a static Astro + Cloudflare Pages architecture. We cover how to build an 'AI-native' operation—one where you keep content as Markdown in Git and generative AI can run it directly—without losing display speed or SEO (in fact strengthening them), along with the key points of the migration.

Read

Preventing WordPress Defacement and Takeover | A Checklist of What to Do Today

The real intrusion routes by which WordPress gets defaced or taken over, and a priority-ordered checklist of countermeasures. We also cover the first response if you do get defaced, and the criteria for deciding whether to outsource maintenance.

Read