Get in touchcorey@spiritdevs.com

Principal Engineer, Web and Mobile Platform Architecture · Corporate Interactive · Sydney, Australia

Theme
github.com/coreybainSnapshot 09 OCT 2026 · 15:08 UTC
Direct line

Start a conversation.

Send a note to corey@spiritdevs.com. Add a brief, job specification, or other context if it helps.

AttachmentsUp to 3 files · 4 MB combined

Submitting stores the message and nothing else — no queue in front of it, no autoresponder, no list to be added to.

03 / 05Case study

ZeroRisk

Principal EngineerCorporate InteractiveSydney, Australia

A travel-safety platform that combines location-aware security and health alerts, SOS and check-in flows, traveller communication and an operator map across mobile and web.

Visit the product website↗
Z
01The problem

Travel-safety software has to coordinate people, locations, alerts and incidents while permissions, connectivity and device capabilities vary. A failure path is part of the safety experience: travellers need a calm way to ask for help, while operators need current, role-appropriate context without exposing another organisation's data.

02The approach

I worked with the Corporate Interactive team across the long-running native applications and the newer shared platform. As Principal Engineer, I focused on modernising lifecycle, location, notification and security behaviour while shaping a multi-tenant web and Expo architecture with explicit authorisation, map scope and durable geospatial storage boundaries.

What the product is#

ZeroRisk is a travel-security platform built by Corporate Interactive for ZeroRisk International. The public SecApp experience provides location-relevant security and health alerts, emergency assistance, check-ins, traveller tracking, learning material and current security information. Behind the traveller experience, operators need to understand where people may be affected, communicate with them and coordinate an incident without mixing data between customer organisations.

The product has a long native history and is now also represented by a modern map-first platform. The current architecture brings together a Next.js operations dashboard, a role-aware Expo application, real-time Convex workflows and durable AWS data services including PostgreSQL/PostGIS and object storage. That combination supports immediate interaction while keeping location and operational records behind explicit ownership boundaries.

Working as part of the team#

This work has been a team effort across Corporate Interactive, the customer domain and multiple application generations. I have collaborated with other engineers while responding to operational requirements that do not fit neatly into a single screen: what a traveller sees after denying location access, how an operator's scope is calculated, what happens when a push token changes, and how an emergency flow behaves when the network is poor.

My role has included helping the team modernise incrementally. The established iOS and Android products still represent real user behaviour, so the newer platform cannot be designed as if history does not exist. We have used those existing workflows to define parity, document architecture decisions and sequence the transition without losing the safety behaviours people rely on.

My role and contribution#

In the native applications, my work has included location and notification lifecycle fixes, SOS and “I'm okay” flows, emergency and embassy information, typed application state, service decomposition, push-token handling, security hardening and more recent iOS platform work such as StoreKit 2 and scene lifecycle updates. These changes often concentrated on the paths around the happy path: permission changes, background transitions, stale credentials and unavailable services.

On the current platform, I have worked across authentication and two-factor flows, tenant-aware permissions, alert authoring, map layers and scope, mobile layouts, SOS handling and real-time data hydration. I have also helped define the architectural boundaries between real-time application state and durable geospatial storage so that speed does not weaken ownership or auditability.

What I learned#

ZeroRisk taught me that reliability in safety software is a product quality, not a backend metric. The interface has to remain direct and reassuring under stress, and permissions or network failures need explicit user states rather than silent degradation. It also reinforced that multi-tenancy and map scope belong in the data model: filtering after a broad query is not an adequate security boundary. Finally, modernisation works best when the team treats the old product as evidence—preserving proven behaviour while being willing to replace the structures that made it hard to reason about.

Case 03 · 09 OCT 2026 · 15:08 UTC
03

Outcomes

36 sessions · 79 hours

What changed

04 delivered
  • 01Location-aware security and health alerts delivered to travellers
  • 02SOS, check-in and emergency-information flows across native mobile apps
  • 03Role-scoped operator maps for alerts, incidents, messages and device health
  • 04A modern shared platform designed around tenant and spatial data boundaries

Stack

06 components
  • Next.js
  • Expo
  • Convex
  • PostgreSQL
  • PostGIS
  • AWS

Built with agents in the loop

Measured
36
Agent sessions
79
Hours at the desk

Against the busiest platform on record (882 sessions)

Average session132 min
Share of all sessions2%
Rank by effort4 of 4

Hours are wall clock with an agent in the loop — specifying, reviewing and correcting, not just generating.

04Keep readingAll work
T
Previous platform

TravelDocs

02 · Corporate Interactive

S
Next platform

SoldOnline

04 · Corporate Interactive