BiteSite
BiteSite lets students pre-order from their college canteen during a break and collect food at lunch instead of queueing. It is built as true multi-tenant software: every college is a tenant, and one deployment onboards any number of them without a redeploy or a separate instance.
Visit live site
The challenge
Multi-tenant software fails in two places: data leaking between tenants, and money. One college must never see another's students, menus, or orders — even if someone guesses an internal ID. And a kitchen cannot cook against an order that was never actually paid for.
What we built
Tenant scope is derived from the authenticated user's own account, never from a URL or client-supplied value, and every tenant-scoped query requires it — proven by an isolation test that runs against a real MySQL instance through the full HTTP, security, and data stack. Payment is mandatory before the kitchen ever sees an order, confirmed by a signature-verified Razorpay webhook as the authoritative backstop to the browser callback.
Highlights
- Account-derived tenant isolation, proven by an end-to-end security test
- Razorpay payments with webhook reconciliation and real refunds on cancellation
- Five-role access model from platform admin down to canteen operator
- Two Android apps for students and canteen staff, shipped from one backend
- Audit logging, database-backed rate limiting, and Flyway-versioned schema
- Full test suite run against a real MySQL service container in CI
Inside the product



Want something like this for your business?
Speak directly with the founder about your workflow, bottleneck, or product idea.