A multi-tenant platform that helps an insurer's trucking clients lower FMCSA CSA/DOT safety scores through evidence, corrective plans, driver training and DataQs challenges.
Co-built by Talha Saleem
~147
endpoints
16
API modules
6
RBAC roles
system architecture
01The problem
Carriers insured by GEIA need a repeatable, auditable way to lower their CSA BASIC scores: evidence intake, corrective plans, driver training and DataQs challenges, all tracked per carrier. The work ran on spreadsheets and email, with filing deadlines tracked by hand.
02My contribution
Co-built it with one other engineer (73 of 200 commits across three repos). On the NestJS API I built the Users module with invites and 6-role RBAC, granular staff permissions, SendGrid and Twilio notifications, the Training module (modules, quizzes, assignments, attestations), password reset, refresh tokens and support tickets. I also wired both React portals to the live API, including the 6-step DataQs submission wizard.
Every request passes a JWT → tenant → role guard chain over tenant-scoped, soft-delete entities.
Security hardening: Helmet, CORS, rate limiting and refresh-token rotation.
Moved TypeORM auto-sync to versioned migrations, writing 6 of the first 10.
Hashed evidence files and an audit trail per dispute.
03Outcome
A hardened API of 16 modules, 40 entities and ~147 endpoints behind a staff console and a carrier portal, with tenant-scoped data, an audit trail and daily KPI snapshots.
04Product screens
GEIA CSA/DOT Score Improvement Platform
05Engineering note
FMCSA data doesn't fit a generic document tracker. CSA scores are percentiles per BASIC category and DataQs requests follow their own review process, so the schema models violations, disputes and evidence per carrier.