Skip to content
All projects
Lawz

Case study · Flagship project

Lawz

Real Estate & Car Showroom Management SaaS

The first product of my startup Lawz — a multi-tenant SaaS I designed, built and launched entirely on my own. It is in use by 2 real offices.

Visit lawz-sy.com(opens in a new tab)

Role
Solo — end to end
Status
In use by 2 offices
Type
Multi-tenant SaaS
Stack
NestJS · Vue 3 · PostgreSQL · Supabase

01

The problem

Real-estate offices and car showrooms need one place to manage their listings and client requests — without ever seeing each other’s data, and on a plan that fits their size.

What the product had to handle

  • An isolated workspace for every office or showroom.
  • Listings for both properties and vehicles, with dynamic attributes.
  • Matching properties to client requests, and filtering by Syrian cities and districts.
  • Subscription plans that limit growth without ever locking an office out of its own data.

02

My role

I built Lawz entirely solo, as the first product of my startup. That means every layer: the data model and the NestJS API, the Vue 3 frontend, the test suites, the security work and the production launch.

  • Backend & API
  • Frontend
  • Database
  • Storage & images
  • Testing
  • Security
  • Launch

03

Architecture

Lawz architectureOffice users and the super-admin use a Vue 3 web app. It calls a NestJS API over HTTPS. The API handles authentication with rate limiting, tenant isolation, subscription limits, listings and matching, the image pipeline, and soft delete. It stores data in PostgreSQL on Supabase and images in Supabase Storage.Office usersOffices & showroomsSuper-adminCreates office accountsVue 3 web appFrontendHTTPSNestJS APIOne API for every tenantAuth · rate limitingTenant isolationSubscription limitsListings & matchingImage pipelineTrash · soft deletedataimagesPostgreSQLSupabase PostgresObject storageSupabase Storage
Office users and the super-admin use the Vue 3 web app, which talks to a single NestJS API. The API enforces tenant isolation and plan limits, stores data in PostgreSQL and sends processed images to object storage — keeping the app tier stateless.
  • One API, many tenants

    Every office and the super-admin go through the same Vue 3 app and a single NestJS API.

  • Stateless app tier

    Uploads live in object storage (Supabase Storage), not on the app server.

  • Managed data layer

    PostgreSQL and file storage both run on Supabase.

04

Key decisions & challenges

  1. 01

    Tenant isolation, verified

    Each real-estate office or car showroom is its own isolated tenant. One office seeing another’s data would break its trust in the product, so rather than trusting the isolation I verified it with end-to-end tests.

  2. 02

    Plan limits that never hold data hostage

    Three tiers — Basic (30 listings), Pro (100) and Max (300+). The limits had to be enforced without locking anyone out: an expired subscription blocks new listings but keeps login and viewing, and downgrading below current usage blocks new adds but keeps every existing listing.

  3. 03

    An image pipeline built for privacy and speed

    Listing photos can carry location metadata. Every upload — several images at a time — goes through a pipeline that strips EXIF / GPS data, resizes the image, converts it to WebP and creates thumbnails.

  4. 04

    Dynamic attributes for properties and vehicles

    Properties and vehicles carry dynamic attributes, alongside property-to-request matching and filtering by Syrian cities and districts.

  5. 05

    Safety nets by default

    Soft delete with a trash bin, per-route rate limiting on auth endpoints, and dedicated security audits.

  6. 06

    Shipping alone with confidence

    With no team to review changes, the test suites act as the safety net.

05

Results

  • 2real offices using Lawz
  • 3subscription tiers
  • 380+backend unit tests
  • 330+frontend tests
  • 14e2e tests