Case 05 / 2026
Kardia — a business system as a test piece
Own product · Texni Labs · Business software · SMB Own product
Starting point
Small companies juggle calendar, tasks, notes, reports and time tracking across half a dozen separate tools — or spreadsheets. The question behind Kardia was not only whether that can be bundled, but whether a system of this size can be built so that a third party can inspect it.
Approach
A modular monolith: FastAPI + a React 19 PWA, building blocks to switch on, connected by an AI assistant on the propose-then-approve principle — it proposes, approval is given by hand, and every approval lands in an immutable log.
Build
Tenant isolation via PostgreSQL Row-Level Security (role NOBYPASSRLS): enforced
by the database, not by discipline, with mandatory isolation tests per table. The
assistant speaks through an OpenAI-compatible interface — the same inference locally
(llama.cpp) or EU-serverless; switching provider is configuration, not a rewrite.
Operated on its own EU infrastructure: Caddy, docker-compose, auto-HTTPS, nightly
backups with a restore runbook, monitoring (Sentry, EU).
Audit
On 07/09/2026 my own code was examined like someone else’s: 1,596 automated tests green (1,239 in the backend against a live database, 357 in the frontend), 28/28 tables with enforced tenant isolation, fail-closed. The open findings are on file in priority order, not swept under the carpet.
What remains
Kardia is a test piece today: the evidence of how systems are built and inspected here. That very inspection is bookable as a service — on the Defence page.
Outcome
- 1,596 automated tests green (1,239 in the backend against a live database, 357 in the frontend), as of 07/09/2026
- Tenant isolation enforced by the database (Row-Level Security), 28/28 tables fail-closed
- AI assistant with an approval workflow — proposals, not silent changes