← Missions

Full-Stack Development Team — Multi-Tenant Lending Platform

Budget: - HOURLY / FULL_TIME ⭐ 0.00 (0) United States

next.js, react-js, typescript, postgresql, node.js, api-development, saas

Qualifications préférées

  • Localisation : Americas, Europe
  • Expérience : Expert
  • Anglais : Courant
We're hiring an experienced full-stack team to build a security-forward, multi-tenant lending platform — borrower portal and lender portal on a shared backend — and to stay on as our development team afterward. Phase 1 architecture, data model, and technical and product specifications are complete. High-fidelity Figma designs are substantially done. This is a build engagement against a finished spec, not a discovery project. You will work directly with the technical architect and product lead who wrote it. Timeline: 4–6 month Phase 1, starting immediately, with continued development expected for the right team. STACK (decided — not open for re-platforming) - Next.js 16.3.x App Router, React 19, TypeScript, Tailwind, zod. Single deployment serving both portals plus API route handlers, hosted on Railway. - Node 24 + Graphile Worker on Railway: AV scanning, transactional outbox drain, webhook processing, PDF generation, housekeeping. - Supabase-managed PostgreSQL 15, Row Level Security on every business table. We do NOT use Supabase Auth. - Supabase Storage with quarantine and clean buckets; uploads AV-scanned (ClamAV as a separate service) before promotion. - Raw SQL migrations via a one-shot pre-deploy runner, backward-compatible with the still-running previous release. - Custom email OTP auth only (no passwords in Phase 1), sessions via JWT in httpOnly cookies. - Resend with signed inbound webhooks. Managed WAF/CDN with rate limiting and a dedicated rate-limit counter store. The stack is settled, but critique within it is welcome. If you see a risk or a better pattern inside these choices, say so in your proposal. MUST-HAVE EXPERIENCE - Multi-tenant SaaS with proven data isolation patterns - Postgres RLS driven from server-side application code — propagating user and tenant identity per request without Supabase Auth (screening question) - Next.js 16+ App Router in production: server components, server actions - Financial or compliance-heavy applications where the software computed money and maintained an audit trail — lending, fintech, healthcare billing (screening question) - Production job queue operation. Graphile Worker or another Postgres-backed queue strongly preferred; Bull/pg-boss backgrounds considered. Idempotent job design. - TypeScript and zod in production; complex multi-step form handling - Git workflow with mandatory code review - AI-assisted development as standard practice: day-to-day fluency with modern AI coding tools paired with rigorous human review of everything generated. We expect AI-accelerated velocity with senior-engineer judgment, and timelines and rates that reflect modern tooling. STRONG PLUS Supabase Storage and connection pooling specifics; transactional outbox pattern; webhook signature verification; PDF generation from web apps; ClamAV or similar AV pipelines; zero-downtime raw SQL migration strategies. TEAM - Senior Full-Stack Developer (Team Lead), 5+ years — a hands-on working lead who writes production code the majority of their time while owning architecture adherence, code review, and deployment configuration. Railway/Vercel-class PaaS experience expected. There is no dedicated DevOps or PM role on this stack, and no account layer: we communicate directly with developers. - Frontend Developer — React/Next.js App Router specialist (server components, server actions). - Backend Developer — Node.js + PostgreSQL, security-focused. We will consider both agencies and a senior lead who assembles their own small team. Every individual who will write code must be named in the proposal. Named developers attend the weekly video call on camera, and the named lead's commits must appear in the trial milestone deliverables. Substituting unnamed staff is grounds for ending the engagement. SELECTION PROCESS 1. Short application (see below). 2. Shortlisted teams sign an NDA and receive a sample specification packet: scope inventory quantifying the full build, representative borrower-portal screen specs with matching designs, the complete trial-milestone specification, and our engineering standards. From this you provide a delivery approach, indicative timeline, cost range with a blended rate card, and a proposed structure for ongoing development beyond Phase 1. 3. Technical interview — live video with the named team lead and backend developer, on camera. The people interviewed need to be the people who will write the code. 4. Paid trial milestone, approx. 2–3 weeks, fixed scope: the end-to-end email OTP authentication flow, which touches RLS, the background worker, transactional email, and rate limiting. Written acceptance criteria agreed by both parties before escrow is funded. Continuation to the full build is a separate decision at our discretion. 5. Ongoing engagement through subsequent roadmap phases. We would rather invest in one team that compounds context than re-hire per phase. All trial work occurs against staging environments with least-privilege, individually attributed, revocable access. No production systems or production data are accessible during the trial. WORKING STYLE — NON-NEGOTIABLE - Agile with 2-week sprints, daily written async standups, weekly video call for planning/retro attended on camera by the named developers. - Minimum 4 hours of working overlap with 9am–5pm US Eastern. - All hourly work uses the Upwork desktop time tracker for all developers; manual time logging is not enabled. - All code lives in our GitHub organization from the first commit. Work-for-hire IP assignment. NDA required before spec access. - Code review on every pull request. Unit tests for critical business logic, integration tests for API endpoints. Faithful implementation of provided Figma designs. WCAG 2.1 AA. Latest 2 versions of Chrome, Firefox, Safari, Edge. README per service and written rationale for any architectural decision or spec deviation. - AI coding tools are expected, but client data, credentials, and specification content may not be pasted into external AI services except through tools and tiers we approve in writing. HOW TO APPLY Keep it short and specific. Begin your proposal with the word "Outbox" so we know you read this posting; proposals without it are declined without being read. No lengthy technical essays — we know you have not seen the spec yet. Written answers are a screen, not the decision; your named developers will discuss them live in the technical interview, so answer from your own experience and reference your own listed projects wherever possible. Include in your proposal: 1. Team: a simple table with name, role, years of experience, hours/week committed to Phase 1, and number of other client projects carried during this engagement. Plus one or two sentences on how long this team has worked together and on what. 2. Relevant work: 2–3 comparable projects (multi-tenant SaaS, financial or compliance-heavy apps) with links, GitHub profiles, or code samples where possible, and your specific role on each. 3. AI-assisted development: one short paragraph on which tools your team uses and how you review and validate AI-generated code for a sensitive financial application. 4. Rates: hourly rate per team member and preferred payment structure. Detailed estimates are not expected until Stage 2. 5. Questions and critique: anything you would want clarified before spec review, and any risks or improvements you see within the chosen stack. Answer the three screening questions in the fields below. Proposals close 1–2 weeks after posting.
Ouvrir sur Upwork

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Connexion