Founder, Architect & Sole Engineer.
Shipping since 15 January 2025 at formaos.com.au
What was wrong
NDIS, healthcare and care providers carry their compliance obligations across spreadsheets, shared drives and email. Evidence goes stale, audits turn into a scramble, and no one can prove who changed what or when. The brief was one system that holds controls, evidence, incidents, corrective actions and NDIS claiming for many isolated tenants at once — with the identity, billing and audit guarantees an enterprise security review actually checks for.
What I built
I architected and built FormaOS end to end on Next.js 16, React 19 and Supabase, with the data model carried by 258 SQL migrations and row-level isolation between tenants. Identity runs on SSO/SAML with SCIM provisioning and MFA. Billing sits on Stripe with entitlement-drift detection that reconciles what a tenant pays for against what they can reach. Every state change writes to an append-only, tamper-evident audit hash-chain, so a record's history can be verified rather than trusted.
Where it landed
FormaOS runs in production at formaos.com.au. Regulated providers operate their compliance programme from one system: controls and evidence stay current, incidents track to closure, and the audit hash-chain gives reviewers a verifiable record. Designed, built and operated by one engineer.
- API routes
- 283
- SQL migrations
- 258
- automated tests
- 467
- compliance frameworks
- 13
Built with Next.js 16, React 19, TypeScript, Supabase / RLS, Stripe, SAML / SCIM, Playwright, OpenTelemetry.
