Case Study
Cybersecurity Platform

Project Purpose
A next-generation cybersecurity platform built to give security teams complete, real-time visibility across their entire attack surface. The goal was to consolidate threat detection, vulnerability scanning, and incident response into one unified, intelligent workspace — cutting mean time-to-response from hours to minutes.
Collaborators
Ahmed Mostafa
(Backend Engineer)
Sara Rashed
(UI/UX Designer)
Tools & Technologies
Key Features
Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.
Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.
Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.
Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.
Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.
Row-Level Security enforced at the PostgreSQL driver layer ensuring multi-tenant data boundaries.
Custom D3-based rendering pipeline built for token-level visual styling and 60fps interaction speed.
App Screens
Core Feature
The command centre — every active threat visible at a glance. Data refreshes every 3 seconds via WebSocket without a full page reload, keeping the UI snappy even under heavy load. Charts are built with a custom renderer for full token-level control over colours and spacing.
Vulnerability
Drill into any asset across any time range with a filtering system that composes like code — stack filters, compare exposure windows, and export to CSV without leaving the view. The query engine behind it was the single hardest engineering problem on this project.
Incident Response
Teams configure YAML-based playbooks and the platform auto-triggers actions on alert conditions — isolating endpoints, revoking tokens, notifying Slack. Built on a serverless edge runtime for sub-200ms trigger latency.
Problems & How We Solved Them
Real-time alerts causing UI jank at high event rates
At peak load (~600 events/sec) the UI was re-rendering on every WebSocket message, causing visible frame drops. We moved all data aggregation to a Web Worker off the main thread, batched updates into 300ms windows, and switched chart renders to requestAnimationFrame — dropping jank from 38% of frames to under 2%.
CVE database queries timing out on large date ranges
Queries spanning 90+ days were hitting 7–10 second response times. We introduced a TimescaleDB hypertable for time-series data, added composite indexes on (tenant_id, timestamp), and pre-computed hourly rollups in a background job. Most queries now return in under 350ms.
Multi-tenant data isolation at the query level
Early implementation used application-level filtering — one missed WHERE clause could leak data across tenants. We switched to PostgreSQL Row Level Security policies enforced at the DB driver level, so isolation is guaranteed regardless of what the application layer does.
Outcomes
0
Threat detection time
0
Lighthouse score
0
Active users at launch
0
Client satisfaction