◈ PAKTI Book a call

// Recent work

A look at the kind of thing we build.

Client work

DEDA TILE LLC

Tile, stone and marble installation — Palm Beach County, Florida

A single-page site for a family tile installer: twenty-two of his own job photos, six customer reviews quoted word for word from his public HomeAdvisor profile, and a QR code that dials him. Static HTML, hand-written CSS, no framework shipped to the browser.

No third-party requests at all — no CDN, no analytics, no fonts fetched from anyone else, so nothing the client cannot see is loaded on his customers. He adds new job photos himself through a password-protected admin page, which writes outside the build so a deploy never wipes them.

Live at dedatile.com — open it and check it yourself. Visit the site →

// Concepts

And the kind of thing we build for everyone else.

Demo

Concept: Restaurant site

Menu, online reservations, and location page — the kind of site a restaurant client would get.

Demo

Concept: SaaS landing page

Pricing tiers, feature grid, and signup flow — built to show conversion-focused layout work.

Demo

Concept: Local service business

Booking form, service area map, and reviews section — a template for trades and local services.

// Security case studies

The kind of issues our security process is built to catch.

Illustrative scenarios based on common, well-documented vulnerability classes — not specific named clients.

Illustrative

Outdated plugin exposing an admin login bypass

Finding

A routine weekly scan flags a CMS plugin with a publicly disclosed CVE allowing authentication bypass on the admin login.

Action taken

Plugin patched within the 48-hour critical SLA; admin access additionally locked down with IP allow-listing and forced credential rotation.

Illustrative

Credential stuffing against a booking portal

Finding

Monitoring detects a spike in failed logins consistent with automated credential-stuffing against a customer booking portal.

Action taken

Rate limiting and account lockout added immediately; affected accounts forced to reset passwords; MFA rolled out for staff logins.

Illustrative

Staging environment indexed by search engines

Finding

A security misconfiguration check finds a staging copy of a site — with test data and no auth — publicly reachable and indexed.

Action taken

Staging moved behind authentication and blocked from indexing; deployment checklist updated to prevent recurrence.

Got something similar in mind?

Let’s talk about what you need.

Book a call →