Independent technical audit of a live bilingual React, Node.js and PostgreSQL platform, covering security, permissions, store isolation, QR, loyalty, database migrations, RTL interfaces and deployment readiness. Review and report only—no production change
Budget / Salary$250–750
TypeFreelance project
LocationRemote
Posted2 hours ago
Senior Technical Auditor for I am looking for an experienced senior full-stack technical auditor to conduct an independent review of an existing bilingual Saudi offers and loyalty platform called Chance Plus.
The platform is currently live and deployed in production. This is not a new development project and I am not requesting a rebuild. The initial task is strictly to review, test and report on the existing implementation before onboarding the first real store.
Technology stack:
TypeScript
React and Vite
Node.js and Express
PostgreSQL
Drizzle ORM and database migrations
REST APIs and OpenAPI
Progressive Web App (PWA)
GitHub, pull requests and CI/CD
DigitalOcean App Platform and Managed PostgreSQL
Arabic and English interfaces, including RTL support
Platform structure:
Customer application
Platform administrator interface
Store and branch management
Store manager and employee roles
Store-created offer workflow
Administrator offer review and approval
QR-based offer validation and redemption
Forsa Loyalty digital card and points ledger
Multi-store and multi-branch permissions
Audit logs and financial records
External POS integration layer, currently disabled and excluded from the pilot
Required technical review:
Code and architecture
Review the structure and quality of the existing code.
Identify defects, fragile implementation, duplication and maintainability risks.
Verify that the frontend, API, database schema and generated API documentation are consistent.
Confirm that production builds and type checks pass.
Authentication and security
Review authentication, sessions, cookies and account access.
Review API input validation and error handling.
Check for exposed secrets, insecure configuration and dependency risks.
Review common web security risks relevant to the platform.
Confirm that authorization is enforced by the server and not only by the interface.
Roles, permissions and data isolation
Verify customer, administrator, store manager, branch manager, QR validation employee and offer manager permissions.
Confirm that one store cannot access another store’s employees, offers, branches, transactions or loyalty activity.
Confirm that employees cannot operate outside their assigned branches.
Test direct API access and attempts to bypass interface restrictions.
Verify administrator protection and important permission audit records.
Store employee management
Review the employee invitation and acceptance workflow.
Test invitation cancellation, expiration, duplicate acceptance and simultaneous cancel/accept requests.
Verify employee activation, suspension, role changes and removal.
Confirm privacy and isolation between stores and branches.
Store offer management
Review creating and editing offer drafts in Arabic and English.
Test branch selection, prices, discounts, quantities, dates and usage limits.
Verify submission to the platform administrator.
Verify approval, rejection and revision requests.
Confirm that unapproved offers cannot appear to customers.
Test offer status transitions and duplicate or excessive redemption prevention.
QR and transaction workflow
Test QR generation, validation, redemption, expiration and cancellation.
Confirm that the same offer or transaction cannot be redeemed more than permitted.
Test branch restrictions and unauthorized validation attempts.
Review concurrency and race-condition protection using a disposable database.
Do not send real authentication codes or create test records in production.
Forsa Loyalty
Review the customer’s digital loyalty card, membership number and secure QR.
Test points earning, transaction and daily limits, duplicate prevention, expiration and reversals.
Confirm that reversing points creates an auditable reverse movement rather than deleting history.
Verify that each store sees only the loyalty activity it generated.
Confirm that one store cannot view the customer’s activity with another store.
Apple Wallet, Google Wallet and external loyalty integrations are not part of this review unless separately agreed.
Database and migrations
Review the schema and all relevant migrations.
Perform migration up-and-down testing on a disposable PostgreSQL database.
Identify destructive, irreversible or data-loss risks.
Review backup, restore and rollback procedures.
Do not test migrations against production.
Confirm that the production backup strategy is suitable before future releases.
Arabic, English and responsive interface
Test Arabic RTL and English LTR interfaces.
Test mobile and desktop layouts at representative screen widths.
Test current versions of Chromium, Firefox and WebKit/Safari where practical.
Check forms, tables, navigation, mixed Arabic/English content, overflow and accessibility.
Confirm that switching languages does not cause material layout instability.
Deployment readiness
Review GitHub workflow and CI/CD configuration.
Review DigitalOcean deployment configuration at a read-only level.
Check health endpoints, runtime errors, logging and monitoring.
Confirm whether the current live platform is ready for a controlled pilot with the first real store.
Required deliverables:
Executive summary and overall readiness decision.
A clear recommendation: ready for pilot, conditionally ready or not ready.
A prioritized findings report divided into:
Critical launch blockers.
High-priority corrections.
Medium-priority improvements.
Optional future improvements.
Areas verified as working correctly.
Evidence for every reported issue.
Exact steps to reproduce each defect.
Affected file, endpoint, screen or database area.
Security impact and practical business impact.
Recommended correction without implementing it.
Test results and coverage gaps.
Migration and rollback findings.
Final pilot-readiness checklist.
A separate fixed-price and timeline proposal for correcting confirmed issues, if corrections are required.
Rules and restrictions:
Review and testing only during this initial project.
No production code changes.
No pull-request merge or deployment.
No production database writes or test records.
No sending emails, SMS messages or authentication codes from production.
No changes to DigitalOcean, GitHub settings, permissions, secrets or firewall rules.
No access to production secrets unless separately justified and approved.
Use local or disposable test environments wherever possible.
Any production inspection must be read-only and separately authorized.
The auditor must keep the source code and business information confidential.
The code may not be copied, reused, sold, shared or used in another project.
Any future correction or deployment requires separate written approval.
Required experience:
Strong professional experience with TypeScript, React, Node.js, Express and PostgreSQL.
Proven experience auditing and continuing code written by other developers.
Strong knowledge of application security and REST API security.
Experience with role-based access control and multi-tenant SaaS platforms.
Experience with multi-store and multi-branch data isolation.
Experience testing race conditions and database-backed concurrent operations.
Experience with PostgreSQL migrations, rollback, backup and recovery.
Experience with automated API, integration and end-to-end testing.
Experience with GitHub pull requests, CI/CD and DigitalOcean or similar cloud platforms.
Experience with QR redemption, coupons, loyalty programmes or transaction systems is strongly preferred.
Experience testing Arabic RTL and responsive interfaces is strongly preferred.
When applying, please answer all of the following:
Provide examples of relevant React, Node.js, TypeScript and PostgreSQL projects.
Describe your experience auditing an existing developer’s code.
Describe a multi-tenant permission or data-isolation issue you previously found.
Explain how you would test cross-store and cross-branch access.
Explain how you would test QR redemption and loyalty points for duplicate or concurrent requests.
Describe your migration, rollback and backup review process.
Confirm your experience with Arabic RTL and responsive browser testing.
Provide an example or anonymized sample of a previous technical audit report, if available.
Confirm that you accept the confidentiality and no-production-change requirements.
Provide a fixed total price and delivery time for the review only.
Important:
Generic applications that do not answer the ten questions will not be considered. The selected auditor will initially receive controlled access to the source code and documentation. Production access is not included by default.a Live React, Node.js and PostgreSQL Multi-Tenant Platform
The platform is currently live and deployed in production. This is not a new development project and I am not requesting a rebuild. The initial task is strictly to review, test and report on the existing implementation before onboarding the first real store.
Technology stack:
TypeScript
React and Vite
Node.js and Express
PostgreSQL
Drizzle ORM and database migrations
REST APIs and OpenAPI
Progressive Web App (PWA)
GitHub, pull requests and CI/CD
DigitalOcean App Platform and Managed PostgreSQL
Arabic and English interfaces, including RTL support
Platform structure:
Customer application
Platform administrator interface
Store and branch management
Store manager and employee roles
Store-created offer workflow
Administrator offer review and approval
QR-based offer validation and redemption
Forsa Loyalty digital card and points ledger
Multi-store and multi-branch permissions
Audit logs and financial records
External POS integration layer, currently disabled and excluded from the pilot
Required technical review:
Code and architecture
Review the structure and quality of the existing code.
Identify defects, fragile implementation, duplication and maintainability risks.
Verify that the frontend, API, database schema and generated API documentation are consistent.
Confirm that production builds and type checks pass.
Authentication and security
Review authentication, sessions, cookies and account access.
Review API input validation and error handling.
Check for exposed secrets, insecure configuration and dependency risks.
Review common web security risks relevant to the platform.
Confirm that authorization is enforced by the server and not only by the interface.
Roles, permissions and data isolation
Verify customer, administrator, store manager, branch manager, QR validation employee and offer manager permissions.
Confirm that one store cannot access another store’s employees, offers, branches, transactions or loyalty activity.
Confirm that employees cannot operate outside their assigned branches.
Test direct API access and attempts to bypass interface restrictions.
Verify administrator protection and important permission audit records.
Store employee management
Review the employee invitation and acceptance workflow.
Test invitation cancellation, expiration, duplicate acceptance and simultaneous cancel/accept requests.
Verify employee activation, suspension, role changes and removal.
Confirm privacy and isolation between stores and branches.
Store offer management
Review creating and editing offer drafts in Arabic and English.
Test branch selection, prices, discounts, quantities, dates and usage limits.
Verify submission to the platform administrator.
Verify approval, rejection and revision requests.
Confirm that unapproved offers cannot appear to customers.
Test offer status transitions and duplicate or excessive redemption prevention.
QR and transaction workflow
Test QR generation, validation, redemption, expiration and cancellation.
Confirm that the same offer or transaction cannot be redeemed more than permitted.
Test branch restrictions and unauthorized validation attempts.
Review concurrency and race-condition protection using a disposable database.
Do not send real authentication codes or create test records in production.
Forsa Loyalty
Review the customer’s digital loyalty card, membership number and secure QR.
Test points earning, transaction and daily limits, duplicate prevention, expiration and reversals.
Confirm that reversing points creates an auditable reverse movement rather than deleting history.
Verify that each store sees only the loyalty activity it generated.
Confirm that one store cannot view the customer’s activity with another store.
Apple Wallet, Google Wallet and external loyalty integrations are not part of this review unless separately agreed.
Database and migrations
Review the schema and all relevant migrations.
Perform migration up-and-down testing on a disposable PostgreSQL database.
Identify destructive, irreversible or data-loss risks.
Review backup, restore and rollback procedures.
Do not test migrations against production.
Confirm that the production backup strategy is suitable before future releases.
Arabic, English and responsive interface
Test Arabic RTL and English LTR interfaces.
Test mobile and desktop layouts at representative screen widths.
Test current versions of Chromium, Firefox and WebKit/Safari where practical.
Check forms, tables, navigation, mixed Arabic/English content, overflow and accessibility.
Confirm that switching languages does not cause material layout instability.
Deployment readiness
Review GitHub workflow and CI/CD configuration.
Review DigitalOcean deployment configuration at a read-only level.
Check health endpoints, runtime errors, logging and monitoring.
Confirm whether the current live platform is ready for a controlled pilot with the first real store.
Required deliverables:
Executive summary and overall readiness decision.
A clear recommendation: ready for pilot, conditionally ready or not ready.
A prioritized findings report divided into:
Critical launch blockers.
High-priority corrections.
Medium-priority improvements.
Optional future improvements.
Areas verified as working correctly.
Evidence for every reported issue.
Exact steps to reproduce each defect.
Affected file, endpoint, screen or database area.
Security impact and practical business impact.
Recommended correction without implementing it.
Test results and coverage gaps.
Migration and rollback findings.
Final pilot-readiness checklist.
A separate fixed-price and timeline proposal for correcting confirmed issues, if corrections are required.
Rules and restrictions:
Review and testing only during this initial project.
No production code changes.
No pull-request merge or deployment.
No production database writes or test records.
No sending emails, SMS messages or authentication codes from production.
No changes to DigitalOcean, GitHub settings, permissions, secrets or firewall rules.
No access to production secrets unless separately justified and approved.
Use local or disposable test environments wherever possible.
Any production inspection must be read-only and separately authorized.
The auditor must keep the source code and business information confidential.
The code may not be copied, reused, sold, shared or used in another project.
Any future correction or deployment requires separate written approval.
Required experience:
Strong professional experience with TypeScript, React, Node.js, Express and PostgreSQL.
Proven experience auditing and continuing code written by other developers.
Strong knowledge of application security and REST API security.
Experience with role-based access control and multi-tenant SaaS platforms.
Experience with multi-store and multi-branch data isolation.
Experience testing race conditions and database-backed concurrent operations.
Experience with PostgreSQL migrations, rollback, backup and recovery.
Experience with automated API, integration and end-to-end testing.
Experience with GitHub pull requests, CI/CD and DigitalOcean or similar cloud platforms.
Experience with QR redemption, coupons, loyalty programmes or transaction systems is strongly preferred.
Experience testing Arabic RTL and responsive interfaces is strongly preferred.
When applying, please answer all of the following:
Provide examples of relevant React, Node.js, TypeScript and PostgreSQL projects.
Describe your experience auditing an existing developer’s code.
Describe a multi-tenant permission or data-isolation issue you previously found.
Explain how you would test cross-store and cross-branch access.
Explain how you would test QR redemption and loyalty points for duplicate or concurrent requests.
Describe your migration, rollback and backup review process.
Confirm your experience with Arabic RTL and responsive browser testing.
Provide an example or anonymized sample of a previous technical audit report, if available.
Confirm that you accept the confidentiality and no-production-change requirements.
Provide a fixed total price and delivery time for the review only.
Important:
Generic applications that do not answer the ten questions will not be considered. The selected auditor will initially receive controlled access to the source code and documentation. Production access is not included by default.a Live React, Node.js and PostgreSQL Multi-Tenant Platform
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.