Portfolio

What We've Built

Every tool on queldrex.com was designed, engineered, and deployed by Queldrex. This is what we build for clients.

Six live systems — SaaS products, subscription infrastructure, security tools, admin panels. All built in TypeScript on Next.js 16, deployed on Vercel, with Redis, Stripe, and Resend.

Full-Stack SaaS Product

AI Visibility Scanner Platform

View live →
sunrise-plumbing.comCRITICAL
35/100
llms.txt✗ Fail
Schema.org✗ Fail
robots.txt✓ Pass
Next.js 16TypeScriptRedis/UpstashStripeResend

A 14-signal automated scanner that checks how visible any business is to ChatGPT, Perplexity, Google AI, and other AI search engines. Includes Stripe checkout, PDF report generation, email delivery, and a full admin triage system.

  • Scan completes in under 30 seconds, report delivered within minutes
  • Dynamic OG image generation — every result is shareable on Twitter/LinkedIn
  • Full admin panel with TOTP 2FA, IP lockout, and attack alerting
Subscription SaaS

AI Visibility Monitor + Subscription System

View live →
Monitor Active$79/mo
Jan
52
Feb
61
Mar
67
Apr
74
Next.js 16Stripe WebhooksRedisResendCron Jobs

A $79/month recurring subscription product with magic-link authentication, monthly automated rescans via Vercel cron, score history tracking, and email alerts when scores drop more than 5 points.

  • Full Stripe webhook integration — checkout, cancellation, payment failure handling
  • Passwordless auth: magic links with 15-minute expiry, one-time use tokens
  • Automated cron jobs rescan all active monitors monthly and email alerts
B2B SaaS Dashboard

Agency Multi-Client Dashboard

View live →
Agency Dashboard8 / 25 scans
client-a.com
82A
client-b.com
61C
client-c.com
44D
Next.js 16RedisStripeTypeScript

A $99/month agency product where users manage AI visibility scanning for up to 25 client domains from a single dashboard. White-label PDF reports let agencies deliver branded results directly to their clients.

  • Magic-link authentication — no passwords, no OAuth complexity
  • Quota system: 25 scans/month with real-time usage tracking per agency
  • White-label output — client-facing reports never show Queldrex branding
Developer Tools

Security Tool Suite (3 Tools)

View live →
Security ScanScore: 58/100
SQL InjectionCRITICAL
XSS RiskHIGH
CORS ConfigMEDIUM
Next.js 16TypeScriptOWASP PatternsOpenAPI Parser

Three real-data security analysis tools: Vibe Coding Security Shield (14 OWASP Top 10 pattern checks on AI-generated code), API Schema Drift Scanner (OpenAPI spec comparison), and Database Migration Safety Checker (SQL risk analysis with line-level findings).

  • Zero external API dependencies — all analysis runs server-side in pure TypeScript
  • Line-number accurate findings with code snippets for every detected issue
  • Severity scoring: Critical / High / Medium / Low with remediation guidance
Security Data Tool

Real-Time Threat Intelligence Feed

View live →
Live Threats↻ Live
185.220.x.xEmotet
malware.net/dLoader
91.108.x.xQakbot
Next.js 16URLhaus APIFeodo TrackerTypeScript

Live cyber threat intelligence sourced from URLhaus and Feodo Tracker — two of the most trusted public threat feeds. No API keys required. Parses, normalizes, and displays threat indicators in real time.

  • No API subscription required — uses public free threat intelligence sources
  • Real-time feed: malware URLs, C2 botnet IPs, threat types, confidence scores
  • First 10 entries free, gated behind Pro plan for full access
Internal Admin Tool

Admin Triage System with 2FA

Admin Panel● Authenticated
Scans12 pending
Build Requests3 new
Feedback7 unread
Next.js 16RedisTOTP (custom)AES-256-GCM

A full-featured admin panel managing incoming scan requests, DFY applications, feedback, build requests, and tool requests. Built with zero third-party auth dependencies — TOTP is a pure TypeScript implementation, session tokens stored in Redis with 4-hour TTL.

  • Pure TOTP implementation — no library, no vendor dependency
  • AES-256-GCM credential encryption with per-record IVs
  • IP lockout after 5 failed login attempts, with email attack alerting at 3

Our Standards

How we build everything.

The same standards we apply to every Queldrex product — applied to every client build.

TypeScript only

Every project is fully typed. No JavaScript drift, no runtime surprises.

Zero fake data

All tools and systems use real APIs and real data. Nothing is mocked in production.

You own the code

Full source delivery. Deploy anywhere. No vendor lock-in, ever.

Vercel-native

Next.js App Router on Vercel with Redis, Stripe, and Resend as needed. Fast, scalable, no ops overhead.

Ready to build something like this?

Custom tools · Automation systems · AI integrations · SaaS products · Internal dashboards

Fixed-price projects. Fast turnaround. No agency overhead.