E. Ologunde Case file

Case file EOSection: Software I builtRef. EO-BLTBack to the case file

Built

Working software I designed and built myself: a marketplace, church web platforms, a fintech app, a private automation platform and brand sites. Each entry lists what the code actually does and the security design behind it.

01

Case studies

In plain English: software I built myself, with the safeguards in each, described without exposing private code or client data.

I design the architecture and the security model before writing code, then review what I built with a red-team pass. Every claim below comes from the project’s own code, migrations and documentation.

Pre-launch

Preppa: a two-sided home-cooked food marketplace

Preppa lets home cooks sell meals, run subscription meal plans and take bookings, while customers browse, order and pay in one app. I built the customer app, the cook workspace and an admin console as one Expo and React Native codebase that also ships to the web, on a Supabase backend with 225 versioned SQL migrations and 41 Edge Functions. Payments and cook payouts run through Stripe Connect, with automated payout reconciliation and a weekly payout sweep. Cook onboarding includes document review, and in-home cooking bookings sit behind a separate, stricter vetting step. CI type-checks every push, then replays the full migration history on a fresh Postgres and runs database regression tests. An earlier browser-only prototype, PrepDash, is where I first worked out the operator console.

Stack
Expo, React Native, TypeScript, Supabase (Postgres, Auth, Edge Functions, Storage), Stripe Connect, GitHub Actions
Status
Deployed, in pre-launch acceptance testing. Built since July 2026.
Security
Row Level Security on data tables, checked by regression tests; privileged actions re-verified server-side and a trigger blocks role self-escalation; Stripe and Mux webhooks are signature-verified; uploads are validated by their real file bytes, not the declared type; native sessions live in the OS keychain; CI scans the production web bundle for secret keys.
Live

CAC North America: organization site and admin console

The public website and admin console for Christ Apostolic Church North America, a regional church body. I built it by porting my own Salvation Center codebase (entry 03) onto a separate database schema, then replacing content page by page and adding a church directory, ministry pages, and convention schedule and archive pages. Staff manage announcements, blog posts, events, the gallery, the newsletter and store orders from an admin area, with no CMS vendor. A separate Next.js site I built for the 2026 annual convention was merged into the main site in phases and now serves a single redirect page, so old links still land. Structured data, sitemaps and canonical-host redirects are handled in code so search engines index one host.

Stack
Next.js 16 (App Router), React 19, TypeScript, Tailwind CSS 4, Supabase, Stripe, Resend, Cloudinary, Vercel
Status
Live. Built July to September 2026.
Security
Admin routes redirect signed-out users in middleware, then check an admin table on the server; Row Level Security policies in the migrations limit public reads to published rows and all writes to admins.
Live

Church websites with staff admin panels

Two live websites for local congregations, each paired with a password-protected admin area so non-technical staff can keep content current without a developer. The CAC Salvation Center site, the codebase the CAC North America site later grew from, covers service times, ministries, events, sermons and a blog, online giving, and a small merchandise store with Stripe checkout and Resend confirmation emails. Staff manage announcements, events, the gallery, prayer requests, testimonies and store orders from the admin panel. The Deeper Life Bible Church Columbia site covers services, events with search-engine structured data, sermons, beliefs, testimonies and giving links, and a scheduled job pulls in the daily devotional from an external source every day.

Stack
Next.js 16, React 19, TypeScript, Tailwind CSS 4, Supabase (Postgres, Auth), Stripe, Resend, Cloudinary, Framer Motion, Vercel Cron
Status
Both live. Salvation Center since June 2026, Deeper Life since July 2026.
Security
Admin areas are gated by Supabase Auth; Salvation Center also checks an admin table on the server and signs image uploads only for admins; Stripe webhooks verify signatures; public forms on the Deeper Life site carry a honeypot that drops bot submissions.
In development

Bagsly: a fintech savings app

A savings app where users pass identity verification, receive a deposit account from a banking-as-a-service provider, link outside banks through Plaid, and organize money into typed vaults: anytime access, scheduled auto-saves, fixed-term locks, bill savings and shared group goals. It is a pnpm and Turborepo monorepo with a Next.js web app and admin console, an Expo mobile app, and a shared TypeScript package for interest and penalty math with its own unit tests. There is no custom API server: clients read only their own rows through Row Level Security, and every money-moving operation runs in one of 42 Supabase Edge Functions that verify the session token first. Written runbooks cover money incidents, reconciliation and support.

Stack
TypeScript, Next.js 16, Expo and React Native, Supabase (Postgres, Edge Functions), Turborepo, Vitest, Playwright
Status
In development against the providers’ sandbox environments. Built since August 2026.
Security
Select-own-only Row Level Security, with writes only through server functions; new database functions get no execute grant by default; transaction status changes and fixed-term locks are enforced in the database, not just app code; idempotent webhook settlement closed a race; a nightly job reconciles balances with the bank; identity details are forwarded to the provider, not stored; withdrawals go only to Plaid-verified accounts.
In daily use

HoWz: a private automation and operations platform

A personal operations platform that runs on my own hardware. A React and Vite dashboard, served by a Node server with no runtime dependencies, brings together a scheduled job-search pipeline, a Routines page showing whether each scheduled task and backup really ran, a monitor for my sites’ availability, TLS certificates and domain expiry, and a question pane where a language model may propose changes but code validates them and nothing is written until I approve it. The job-search runs are read-only by design: they find and track postings and draft materials only from a verified profile, and they never submit a form or create an account. Real personal data stays local and out of version control.

Stack
Node.js, React 19, Vite, Vitest, GnuPG, Git hooks, Windows Task Scheduler
Status
In daily use since August 2026. Private, local-only.
Security
Nightly backups are encrypted and signed, the decryption key is kept off the machine, and restore drills prove they open; a Git leak guard blocks commits and pushes that carry private files, real figures or credential-shaped strings, and a push needs a one-time permit approved at a physical terminal; the sites monitor contacts nothing until approved the same way; the dashboard is password-gated with a Content Security Policy and HttpOnly, SameSite=Strict cookies. Each feature had independent reviews, a red-team pass and mutation-checked tests.
Live

Brand and marketing sites

Three static, multi-page sites written by hand in HTML, CSS and JavaScript, with no framework and no build step. Cyntraix is the site for my cybersecurity consultancy, with a hero video that scrubs frame by frame as you scroll, an animated network canvas, and clean-URL, long-cache hosting configuration. HoWz Studios is an editorial portfolio for my creative studio. WealthDJ is the artist site for my DJ work, with a live canvas waveform and a radio player that rotates mixes through the SoundCloud widget API. All three honor the visitor’s reduced-motion setting, and each shares one design system across its pages so a new page stays consistent without extra tooling.

Stack
HTML, CSS, vanilla JavaScript, Canvas API, Vercel
Status
Live. Built August 2026.
Security
No backend and no stored form data: contact and booking requests open the visitor’s own email client.
Research artifact

When successful checks outlive their evidence

A reproducible microservice remediation study asking when evidence used to approve a recovery action becomes stale or incomplete. The public repository includes synthetic trial data, frozen predictions, audit ledgers, Python analysis, tests, and an Overleaf manuscript draft. Fifty action trials span five development stages on the DeathStarBench social-network testbed.

Stack
Python, Docker, DeathStarBench, LaTeX
Finding
In the final eight-trial comparison, available lifecycle events and late functional rechecking each avoided the four incorrect approvals made by initial checks. Neither method outperformed the other in this cohort.
Evidence
Forty unit tests pass; five analyses and manuscript generation replay exactly. Raw records, exclusions, and SHA-256 provenance are included.
Status
Public research artifact and manuscript draft. Not peer reviewed; PDF build unverified. A bounded synthetic case study, not evidence of production safety.

Client engagements are not shown here. Repositories that hold private data or move money stay private; for those, this page describes the design rather than linking the code.