A vibe-coded compliance app, hardened and shipped.
Manytain is a medical equipment management and compliance platform its founder built end-to-end on Firebase — vibe-coded into a working app with a React front-end, Firestore, Auth and Cloud Functions. We designed the full marketing landing page and took the app from prototype to production: locked-down security rules, a data model built for scale, validated Cloud Functions, production email via Resend, and a real build-and-deploy pipeline — all without leaving Firebase or GCP. Now live at manytain.org.

The brief,
in three beats.
What they needed.
The founder shipped a working medical equipment management app fast by vibe-coding it on Firebase — React, Firestore, Auth, Cloud Functions, Hosting. Perfect for proving the concept, but not yet safe to put paying healthcare businesses on: permissive security rules, an ad-hoc data model, writes the client could trust too much, and email that wasn't production-grade.
How we tackled it.
We didn't rewrite — we hardened. Audited the existing build, locked down Firestore and Storage security rules, restructured collections for the queries it actually runs, moved business logic and validation into Cloud Functions, wired transactional email through Resend, and put the whole thing behind CI with preview deploys. GCP and Firebase throughout — no platform migration.
What happened.
Shipped. Manytain is now live at manytain.org — a clinical equipment registry that keeps medical devices calibrated, work orders moving, and audit evidence inspection-ready before a surveyor walks in. Secured, scalable, and deployable on every commit.
Inside the
engagement.
Audit the vibe-coded build
We read the whole app the way an attacker and a maintainer both would — mapping every data flow, every Firestore read and write, every Cloud Function. The output was a prioritised list of what was unsafe, what wouldn't scale, and what was about to break, scored so the founder could see exactly what we were fixing and why.
- Firestore & Storage rules reviewed line by line
- Client-trusted writes flagged for server validation
- Data model mapped against real query patterns
- Dependency, secret and config hygiene checked
Lock down the rules
Firestore and Cloud Storage security rules rewritten per-collection and per-role, deny-by-default, and tested against the Firebase emulator suite. Auth flows tightened so a logged-in user can only ever touch their own organisation's data.
Restructure data & functions
Collections and documents restructured for the access patterns the app actually has, with composite indexes where they matter. Business logic and input validation moved into Cloud Functions so the client can't be the source of truth. Transactional email re-platformed onto Resend.
- Schema enforced server-side, not hoped-for client-side
- Cloud Functions for logic, validation and webhooks
- Resend for verification, alerts and receipts
Ship a real pipeline
GitHub → CI → Firebase Hosting, with preview channels per pull request, a staging/production split, and environment config kept out of the client bundle. Every commit is deployable; every change is reviewable before it reaches a customer.
Full landing page design
Designed and built the complete manytain.org marketing site — dark, product-led design with a hero, feature breakdowns, interactive platform preview, role-based access section, setup flow and conversion CTA. Positioned specifically for clinical and biomedical engineering teams with Joint Commission compliance messaging.
- Full page design from hero to footer
- Product UI mockups embedded in marketing sections
- Role-based access section for Admin, Manager, Technician and Staff
- Conversion-focused CTA with demo booking flow
Evoke took the app I built and turned it into something I can actually put customers on. It's now live.
The tools
we shipped on.
Capabilities
behind this build.
Other
engagements.
— Let's make something —
Tell us what
you're building.
Trinidad & Tobago
09:00 — 17:00 AST
on business days

