A travel-safety platform that combines location-aware security and health alerts, SOS and check-in flows, traveller communication and an operator map across mobile and web.
Visit the product websiteTravel-safety software has to coordinate people, locations, alerts and incidents while permissions, connectivity and device capabilities vary. A failure path is part of the safety experience: travellers need a calm way to ask for help, while operators need current, role-appropriate context without exposing another organisation's data.
I worked with the Corporate Interactive team across the long-running native applications and the newer shared platform. As Principal Engineer, I focused on modernising lifecycle, location, notification and security behaviour while shaping a multi-tenant web and Expo architecture with explicit authorisation, map scope and durable geospatial storage boundaries.
ZeroRisk is a travel-security platform built by Corporate Interactive for ZeroRisk International. The public SecApp experience provides location-relevant security and health alerts, emergency assistance, check-ins, traveller tracking, learning material and current security information. Behind the traveller experience, operators need to understand where people may be affected, communicate with them and coordinate an incident without mixing data between customer organisations.
The product has a long native history and is now also represented by a modern map-first platform. The current architecture brings together a Next.js operations dashboard, a role-aware Expo application, real-time Convex workflows and durable AWS data services including PostgreSQL/PostGIS and object storage. That combination supports immediate interaction while keeping location and operational records behind explicit ownership boundaries.
This work has been a team effort across Corporate Interactive, the customer domain and multiple application generations. I have collaborated with other engineers while responding to operational requirements that do not fit neatly into a single screen: what a traveller sees after denying location access, how an operator's scope is calculated, what happens when a push token changes, and how an emergency flow behaves when the network is poor.
My role has included helping the team modernise incrementally. The established iOS and Android products still represent real user behaviour, so the newer platform cannot be designed as if history does not exist. We have used those existing workflows to define parity, document architecture decisions and sequence the transition without losing the safety behaviours people rely on.
In the native applications, my work has included location and notification lifecycle fixes, SOS and “I'm okay” flows, emergency and embassy information, typed application state, service decomposition, push-token handling, security hardening and more recent iOS platform work such as StoreKit 2 and scene lifecycle updates. These changes often concentrated on the paths around the happy path: permission changes, background transitions, stale credentials and unavailable services.
On the current platform, I have worked across authentication and two-factor flows, tenant-aware permissions, alert authoring, map layers and scope, mobile layouts, SOS handling and real-time data hydration. I have also helped define the architectural boundaries between real-time application state and durable geospatial storage so that speed does not weaken ownership or auditability.
ZeroRisk taught me that reliability in safety software is a product quality, not a backend metric. The interface has to remain direct and reassuring under stress, and permissions or network failures need explicit user states rather than silent degradation. It also reinforced that multi-tenancy and map scope belong in the data model: filtering after a broad query is not an adequate security boundary. Finally, modernisation works best when the team treats the old product as evidence—preserving proven behaviour while being willing to replace the structures that made it hard to reason about.
Against the busiest platform on record (882 sessions)
Hours are wall clock with an agent in the loop — specifying, reviewing and correcting, not just generating.