PLANOMAD TECHNOLOGY
One Rust core. Identity, payments and sync live in the core; a product is its surface and its own logic.
Sign-in and passkeys, subscriptions and receipt verification, sync, telemetry — the layer a new product does not rebuild. REDDY shipped on this core; AMBEDO sits on the same one.
Records commit to embedded SQLite first; only the delta reaches the server. Server cost scales with sync volume, not user count. Products keep working through a network outage.
Entitlements only from server-side verification. Receipts queried directly against Apple and Google; store notifications re-confirmed at the edge. Access control by Postgres row-level security, schemas isolated per domain, account and data deletion built into the product.
Sign-in and passkeys, entitlements, realtime sync, telemetry — one Rust crate. 80,000+ lines with the app engines. The shared core: forbid(unsafe_code), every warning an error. One fix in the core, one build, both platforms.
React Native for the surface. The Rust core compiled into the binary as a static library, called synchronously over JSI through Nitro Modules. No async bridge. Motion on the UI thread as Reanimated worklets; GPU surfaces through Skia shaders.
Every write committed to embedded SQLite first — an answer that never waits on the network. Sync by revision-checked optimistic concurrency: a stale write is a conflict, not an overwrite. Propagation over a TLS WebSocket, in realtime.
No streaks, no guilt mechanics, no feed. Enforced in the core rather than per product — nothing to slip, product by product.
Business logic in one Rust core. Each product, a rendering layer on top.