03 · OPERATE ENTERPRISE OPERATIONS · CONFIDENTIAL WORK PROJECT
AIMARA, AI Assisted Aftersales Operations Platform
A secure mobile operations environment for realtime communication, cases, calls, records and AI assisted messaging.
- Role
- Software & app developering across client, backend and security layers
- Platform
- Android · Ionic Angular + Capacitor · FastAPI · Supabase
Confidential work project · screens use anonymised demo data

The problem
Aftersales operations run on sensitive conversations, cases, calls, records and decisions that ordinary chat apps neither govern nor protect.
My contribution
Client side product engineering across the Ionic Angular app and its FastAPI/Supabase backend: realtime messaging, channel governance, dashboards, calls integration and the device security layer.
Core stack
- Ionic Angular
- Capacitor
- FastAPI
- Supabase
- WebSockets
- Agora
Proof it works
The supplied working build demonstrates login, governed channels with three privacy tiers, realtime chat, approval workflows, an operations dashboard and starred-message recall, with security services (biometrics, app lock, root detection, privacy screen, encrypted storage) wired through the client.
What it is
Context
AIMARA is an operations environment for teams whose day runs on conversations that matter: aftersales cases, scheduled calls, records and the decisions around them. It brings chat, calls, tasks and records into one governed mobile workspace.
It is a confidential work project. Everything shown here uses anonymised demo data, and the write up sticks to what the supplied build and code demonstrate.
What made it hard
The challenge
Operational chat is not consumer chat. Messages relate to cases and records; destructive actions need approvals; some channels must hide member identities even from each other; and the device itself is part of the threat model.
The engineering challenge was to keep all of that governance from suffocating the experience, the app still has to feel like fast, ordinary messaging while every action passes through roles, approvals and security services.
The experience
A walk through the product
All names, organisations and message content in these screens are synthetic. Sensitive text was replaced in pixels, not blurred.

01
Entry is deliberately narrow: admin accounts are provisioned, not self registered, and the client confirms its server binding on the login screen.

02
Governance starts at creation: three channel privacy tiers, Standard, Low Privacy with stable anonymised handles, High Privacy with end to end encryption, plus automatic archiving.

03
The list is triage, not history: Unread and Unreplied filters, archive state and lifecycle notices keep operational load visible.

04
In Low Privacy channels the app's own anonymisation shows members as stable handles, identity control as a product feature, not an afterthought.

05
The dashboard turns conversation into operations: upcoming and overdue calls, tasks and scheduled messages, each tied to a channel and an assignee.

06
Starred messages give operators recall, key commitments resurface without scrolling through history.
What I built
The work, lane by lane
Interface
- Channel list with unread/unreplied/archive triage, rich chat surface, dashboard, social feed, and user & department management screens
- Approval driven flows for block, unblock, edit, delete, freeze, unfreeze and channel deletion
- Document viewing for PDFs and Office files inside the app
Realtime & communication
- WebSocket driven messaging with editing, deletion, forwarding, reactions, labels and favourites
- Scheduled messages and channel lifecycle notices rendered inline
- Agora powered calls with tokens minted server side; call notes, status and scheduled calls on the dashboard
Backend & data
- FastAPI services behind the client; Supabase for data and auth with row level security foundations
- Resumable uploads via the tus protocol for unreliable mobile networks
- Push notifications through Firebase Cloud Messaging
AI assistance
- Language detection and multilingual translation services in the client
- AI paraphrasing of drafts, modelled and typed end to end
- An AI Safe Mode that reviews and polishes outgoing messages, with a review/edit/cancel window before anything is published
- Audio transcription for voice content
Security engineering
- Biometric sign in and application locking
- Encrypted local storage; root and jailbreak detection; privacy-screen protection against overlays and screenshots
- Server side document redaction and forensic image/PDF watermarking
- Post quantum encryption groundwork in the backend
Engineering decisions
Decisions and their trade-offs
Real decisions cost something. Each of these names its price.
01Privacy tiers as a channel property
Rather than one global privacy switch, every channel is created as Standard, Low Privacy (members appear under stable anonymised handles) or High Privacy (end to end encrypted).
Trade-offThree behaviour sets to test everywhere identity appears, accepted, because sensitivity genuinely varies per conversation, not per company.
02Approvals on destructive actions
Blocking, edits, deletions, freezes and channel removal route through approval workflows instead of executing instantly.
Trade-offSlower in the moment than consumer chat, the point. In an operations record, an unreviewable delete is a liability.
03Archive as preservation, not disposal
Channels auto archive on a schedule and can be reactivated; the history is preserved and the state change is announced inside the conversation itself.
Trade-offMore lifecycle states in the client, but the audit story stays intact and nothing silently disappears.
04A review window in front of AI
Safe Mode never publishes on its own: polished messages sit in a pending window where the sender can edit or cancel before anything leaves the device.
Trade-offA deliberate pause in the send flow, chosen so AI assistance never becomes AI authorship in a compliance sensitive channel.
05Treat the device as hostile
Biometric lock, encrypted storage, root detection and privacy-screen protection run in the client, because in field operations the phone itself is an attack surface.
Trade-offExtra friction on compromised devices by design; the security layer is capability gated so legitimate devices stay smooth.
Under the hood
How the system holds together
One governed loop: the Ionic Angular client talks to FastAPI over REST and WebSockets; Supabase holds identity and data behind row level security; Agora carries live calls with server minted tokens; and the AI services sit behind a human review window. Device security services wrap the whole client.
Deeper technical notes
- Client services are cleanly separated in Angular, chat, dashboard, cases, records, users, language, agora, websocket, resumable upload, each a typed injectable, which is what kept a feature set this wide navigable.
- Uploads use the tus resumable protocol so a dropped connection resumes instead of restarting, the difference between usable and unusable on field networks.
- The security layer is composed of independent Capacitor services: native biometrics, app lock, encrypted storage, jailbreak/root detection and privacy screen, failures degrade specific capabilities rather than the whole app.
- Server side, redaction and watermarking run in the FastAPI layer so originals never round trip to the client unprotected; a post quantum encryption module is present as groundwork.
- Cloud deployment configuration (containers, infrastructure as code and SIEM groundwork) exists in the repository; its values are intentionally not reproduced anywhere on this site.
Gallery
Every screen, up close
All names, organisations and message content in these screens are synthetic. Sensitive text was replaced in pixels, not blurred.
Quality, privacy, accessibility
Evidence of care
- Anonymisation on this page is pixel replacement with synthetic content, never blur, which can be reversed.
- Nothing from the project's infrastructure, endpoints, keys, identifiers, Terraform values, appears on this site.
- Feature claims follow the supplied working build and code first; capabilities confirmed by the product owner but absent from this slice are described as product features, never demonstrated as proof.
- The client's security posture is layered: authentication, biometric lock, encrypted storage, device attestation and screen protection are separate services, so one failure does not disable the rest.
Where it stands
Outcome and current proof
- The supplied build demonstrates provisioned login, governed channel creation with privacy tiers, realtime chat, triage, dashboard operations and starred recall.
- The codebase carries the full service architecture, chat, cases, records, users, language, calls, uploads, security, as typed Angular services against a FastAPI/Supabase backend.
- No customer names, deployment scale or usage figures are claimed; this is a confidential work project.
Technologies
Chosen for reasons
- Ionic Angular + Capacitor
- a mature enterprise client framework with native device bridges for the security layer
- FastAPI
- typed Python services for messaging, media, redaction, watermarking and push
- Supabase (Postgres + RLS)
- relational data and auth with row level security as the tenancy foundation
- WebSockets
- live message delivery and presence
- Agora
- production grade realtime voice with server minted, expiring tokens
- tus resumable uploads
- media transfer that survives field network drops
- Firebase Cloud Messaging
- push delivery on Android
For your project
What this experience enables
- Operations and field service apps where chat, tasks, calls and records are one workflow
- Secure messaging with governance: roles, approvals, archives and audit friendly lifecycles
- Realtime dashboards driven by the same events as the conversation
- AI features deployed responsibly, assistance with a human review window, not auto publishing
- Mobile security engineering: biometrics, encrypted storage, device attestation, screen protection