Activa · status
The full 24 BLVD product is standing: a real multi-tenant org, the ticket loop, membership, loyalty, a Square-style POS, two Flutter apps, and a Thailand payments plan. Two adversarial security reviews ran and every real finding is sealed. The one open decision is yours: the remote apply.
Live proof
The Activa member app, built onto your iPhone 16e against the local backend, rendering real 24 BLVD data — header, QR-pass button, event-type filters, the events feed, and a working event detail sheet with correct paid-vs-RSVP logic. This is the Flutter UI actually painting, not a mockup.
Behind it, every loop is verified over the real GoTrue + PostgREST API: member RSVP, door check-in, POS sale — each a 2xx with confirmed post-action state.

Member app · iPhone 16e · live local backend · 1 Sep 2026
Component status
How it's verified
Four SQL suites (core RBAC, hardening, POS, POS hardening) pass on every fresh supabase db reset.
RSVP, check-in and POS checkout each driven through the real API — 2xx with verified state (ticket checked-in, stock decremented, invoice issued, points banked).
Member app built + run on the iPhone 16e simulator, rendering live 24 BLVD data (screenshot above).
42 review agents total. Found 3 real breaches (2 RBAC cross-tenant reads, 1 POS cash-skim exploit) — all sealed and re-verified dead.
1 · Remote apply. Your single deploy call — one supabase db push puts all 13 migrations on the hosted project.
2 · Payments & the wallet. Pick the gateway together (Opn/Omise recommended) and get Thai counsel on the cross-tenant stored-credit wallet (Bank of Thailand e-money question).
3 · Next build. Paid ticketing once a gateway lands, a POS terminal in the admin, and per-operator payout statements.