From Risky Prototype to a Platform Ready for Real Customers
Who Is 4eyez?
4eyez provides CCTV solutions for taxis and private hire vehicles. Their platform helps fleet operators manage installations, maintain compliance with council regulations, and keep their vehicles road-legal with valid certificates.
Founder Craig had a working prototype built using AI-assisted ("vibe coded") development. It demonstrated the concept well — but wasn't safe to put in front of real customers handling real data.
The Problem
The prototype worked as a demo, but had fundamental issues that made it risky to launch with paying customers:
Security Risk — Unauthorised Data Access
A flaw in how the app controlled access meant a logged-in user could potentially view or alter records belonging to a completely different customer.
Security Risk — Business Logic Could Be Gamed
Certain steps in the booking and certification process could be skipped or manipulated, leaving the business open to fraud and data integrity issues.
Legal Risk — Data Residency
Data residency requirements had not been met, creating legal exposure around where customer and driver data was stored and processed.
Growth Risk — No Analytics or Data Control
Lack of control to enrich the data set and extend with smart business analytics as the number of users grew.
Core Platform Features
Delivery Timeline
Assessment & Architecture
Security review of the prototype, threat modelling, and architecture design for the production platform.
Core Platform Build
Access control, tenant isolation, customer portal, and fleet management — the foundation of the platform.
Operations & Compliance
Booking system, certificate management, warranty tracking, ticketing, GDPR compliance, and email notifications.
Hardening & Handover
Security hardening, testing, CI/CD setup, documentation, and full handover to Craig with ongoing support.
Outcomes
Safe to Launch
The platform passed security review and is ready for real customers with proper access control and data protection.
We Locked Down Who Can See What
Every user — whether an admin, engineer, fleet manager, or driver — can now only access the information relevant to them. Customers can't see each other's data. Engineers can't touch records they're not assigned to. The system enforces this automatically, not through trust alone.
Legally Compliant From Day One
All customer and driver data is now stored in the UK, encrypted, and handled in line with UK regulations.
Full Platform Ownership
The new platform runs on infrastructure 4eyez controls entirely. There's no third-party platform to depend on, no sudden price hikes, no risk of the service being discontinued. They pay for exactly what they use — nothing more, nothing less.
Delivered in Weeks, Not Months
The entire platform — from security assessment to production-ready handover — was delivered in just 4 weeks.
"I found Henry and Andy very approachable, understanding immediately what was required for taking my 'vibed' app into the real world. I was very impressed with their understanding of what was required and delivered in time and on budget. Thank you Hyperscale"
Built Something That Needs to Become Real?
If you've got a prototype or MVP that needs security, compliance, and production readiness — we can help you get there fast.