THE BUILD RECORD · MEASURED FROM OUR OWN REPOSITORIES
Fourteen builds. One engineering discipline.
Cyberate Technologies engineers the operating systems, enterprise platforms and websites running across DDDI Group's companies, our research network and private clients. This page is the record of that work, counted straight from the source code rather than assembled from a slide deck.
Counts measured from Cyberate's source repositories in August 2026, excluding third-party and generated code.
Every stage of the residential delivery chain we describe has a system behind it, built for a real operation inside DDDI Group or its ecosystem and hardened in live use.
Feasibility: Site assessments with photo, video and slope evidence, structured for a go or no-go decision.
Design data: A 19-page specification PDF normalised into 130 catalogued, traceable line items.
Compliance: Insurance capacity, approvals and outbound-email risk checked before commitments are made.
Quoting: Drawings measured in the browser; product rules priced by an engine the business edits itself.
Delivery: Phases, tasks, inductions, site attendance and variations on one live programme.
Finance: Quotes flow into budgets and actuals automatically; funds, receipts and approvals stay audit-clean.
AI agents: Drafting, flagging and extracting inside agreed boundaries, with a human confirming every action.
WHAT WE'VE BUILT
Not a portfolio of screenshots. A register of working systems.
Fourteen builds in four groups. Twelve are in production or in delivery; two are prototypes, and they are labelled as prototypes because that is what they are.
Construction & development operating systems: Five builds, proven inside DDDI Group's live operations before anything was offered outside the group.
Enterprise & financial platforms: Two builds for work where the audit trail is the feature, not a reporting afterthought.
Custom engineering beyond construction: Two builds applying the same discipline to airline ticketing and insurance broking.
Web engineering & growth: Five public sites and more than 380 unique pages — over 500 prerendered routes once both languages of the bilingual site are counted — built so search engines and AI assistants can read them.
01 · LIVE · FOR CYBERATE PM & DDDI GROUP
Development Management Platform
The system behind Proof Case 01: one operating model for a portfolio that grew from 2 projects to 34. Project templates expand into fully dated programmes, and the scheduling engine underneath was written rather than bought.
De-identified recreation of the live interface. The development lifecycle template holds working-day offsets rather than fixed dates, so a start date is chosen per project and weekends are skipped automatically. Stage structure and task names are the real ones.
A self-built Gantt engine: Task dependencies and working-day scheduling, with no third-party chart library underneath.
Templates that become programmes: Seven stages and 53 main tasks expand into a 455-working-day programme, dated from the project's own start.
Growth under test: 4.2× code growth from v1.0 to v2.1 in five months, with 322 unit tests gating every deploy.
Contract-to-handover control for a residential builder: lots, buyers, budgets, specifications, selections, inductions and variations in one system. Accepted quotes generate their budget lines automatically and roll back cleanly, so quotes, budgets and actuals can no longer disagree.
De-identified recreation of the live interface. Supplier quotes are compared per trade package, and an accepted quote generates its budget line automatically. Supplier names and amounts are de-identified samples, because pricing is the supplier's information.
An insurance-capacity engine: Policy-period attribution, expiry zeroing and auto-release on archive: one algorithm, one source of truth for builder cover.
AI that only reports what it sees: Quote extraction returns the amount as stated and the tax wording as evidence. It never computes tax itself; that stays with a person.
Fields cut to what is used: Capture fields fell from 101 to 10, based on what 162 real supplier quotes actually contained.
03 · LIVE · FOR AN AUSTRALIAN WINDOWS & DOORS MANUFACTURER
Automated Quoting & Production ERP
The engine behind Proof Case 03, where quoting moved from days to minutes. A plan PDF is calibrated in the browser, measured by clicking, and the dimensions become quote lines without anyone transcribing them from a drawing.
De-identified recreation of the live interface. A quote as the system produces it: every opening numbered and located, with its series and glazing resolved from the catalogue. Project references are replaced; the line format is the real one.
Drawings measured in the browser: pdf.js rendering under a canvas overlay: calibrate the scale, click to measure, feed the quote directly.
A rule engine the business edits: Series, glass, profiles and screens are repriced by the people who know the products, without a code change.
Quote through to install: Multi-version quotes with a full status lifecycle, carried on to the production board, delivery and installation.
One internal platform running six business lines: finance approvals, land assessment, lending, multi-site content, memberships and email. It is also where our most-used AI workflows live, each of them ending at a person rather than at a send button.
De-identified recreation of the live interface. The rule codes, severities and suggested rewrites are the real shape of the agent's output; the draft is ordinary site correspondence with nothing identifying in it. Every send is released by a human.
Email risk caught before send: 24 codified rules covering unconditioned commitments, contract-notice risk and escalation triggers, with approval routing built in.
Bills and vouchers read, not retyped: AI recognition with per-field confidence auto-fills the finance forms, and a person confirms the result.
Rules the business can tune: A four-level finance approval chain, and an AI prompt library managed in-app by business users with no redeploy.
Beyond the four construction systems sit three more builds and two prototypes. Three of them serve industries with their own regulators, where a permission model and a reversal-only ledger are product features rather than implementation details. The last is the prototype the construction system's own hardest ideas were first proved in.
Investment Management Platform: Raise-to-receipt control for property investment projects, for Cyberate Investments. (Models the real Australian fund structure: operating company, management company and trust, per project.; Bank-statement import with a four-state matching engine against subscriptions and payments.; Idempotent receipt issuance with void-not-delete history, so financial paper trails stay intact.): React 18 · TypeScript · A4 PDF receipt generation
Airline Ticketing Operations Platform: A 34-module trade desk for airfare distribution, and the largest single codebase in this record. (A 1,700-line parsing engine turns raw Amadeus PNR text into passengers, segments, travel documents and multi-reissue ticket history.; Deterministic price benchmarking with layered cohort matching and minimum-sample guards, reproducible by design.; 26,000-row by 88-column Excel exports moved into a Web Worker, so the desk stays responsive and exports stay cancellable.): React 19 · TypeScript · ECharts · Web Workers
Insurance Brokerage System: In delivery for a licensed Australian brokerage: an enquiry-to-claim workflow with staff, client and referrer portals on one permission model. (156 named permission codes across four data scopes, re-checked at the service layer, with tests for URL-tampering attempts.; An 11-step enquiry orchestration a broker can enter at any point, with policy comparison and renewal reminders built in.; Dual commission ledgers, brokerage and referrer, corrected by reversal only so history stays intact.): React 19 · TypeScript · 57 test files · EN / 中文 dictionaries
R&D Evidence Manager: A prototype for R&D Tax Incentive compliance: every dollar traceable to an activity, every activity to its evidence. (Reverse-parses government application PDFs into a structured company, project and activity database.; A payroll reconciliation engine compares actual pay against timesheet-derived cost, month by month.; Built on the know-how of Cyberate's own registered R&D projects under the incentive scheme.): React 19 · TypeScript · pdf.js
Selections & Knowledge Prototype: A prototype, and where the construction system's hardest ideas were proved before they were productised. (An 11-phase residential construction engine with six task-trigger types, from phase entry to inspection failure.; Insurance policy-period modelling, later rebuilt into the production capacity engine.; Its selections, catalogue, knowledge and passport concepts now run inside the live construction system.): A four-day proving sprint, then absorbed into production
WEB ENGINEERING & GROWTH
Five public sites. Built to be read by machines as well as people.
More than 500 pages across five sites. Each one ships behind build-time gates: if a page loses its prerendered content, its canonical tag or its performance budget, the build fails instead of the reader.
cyberate.com.au: Our own site, and the standard we hold the others to. (75 indexable pages, every one of them canonical, with an FAQ schema on 63 of them.; Fully readable to non-JS AI crawlers: complete prerender, an llms.txt fact layer, and explicit allow rules for 20 named search and AI crawlers.; Deterministic performance budgets enforced at build time, so regressions fail the build rather than the user.): React · TypeScript · self-built prerender & perf-budget tooling
Research Services Platform: For a Registered Research Service Provider in our research network. (The build fails if prerendered pages lose real content, so an invisible page never ships.; An edge worker turns SPA soft-404s into honest 404s; payload tuning cut one request from 1.3 MB to 21 KB, and 17s to 1.6s.; A 10-question R&D readiness self-check, deliberately scoped as education and never as eligibility advice.): React · TypeScript · prerender verification · Cloudflare edge worker
Brokerage Website Rebuild: In delivery for a licensed Australian brokerage. (Wix to self-hosted static Next.js 15: 38 pages with zero external runtime dependencies.; Build gates encode the audit findings: exactly one H1 per page where the old homepage had twelve, JSON-LD on every page, no legacy asset references.; A 31-entry redirect matrix, and insurance-safe copy rules where a tick means covered, so ticks appear only where cover is real.): Next.js 15 · static export · self-hosted fonts & assets
THE HARD PARTS
Twelve problems that didn't have an off-the-shelf answer.
Each of these was solved for a live operation, and each is verifiable in the code that runs it.
Insurance capacity, computed correctly: Builder cover is consumed per contract, per policy period. Contracts now attribute to the period of their signing date, expired policies zero out and archived projects release capacity: one algorithm, one file, one truth.
A data model that matches reality: Building contracts were attached to buyers; reality attaches them to lots. We moved the model to one contract per lot, deleted the apportionment logic it made unnecessary, and migrated the live data.
AI that reads, humans who decide: Quote extraction returns what a document says: the amount as stated, the tax wording as evidence, a confidence score. It never computes tax. Capture fields fell from 101 to 10, based on 162 real quotes.
Email risk caught before send: 24 codified rules across three severities cover unconditioned commitments, contract-notice triggers and missing approvals. New commitments are extracted into a ledger, escalation is routed automatically, and a human releases every send.
Airline GDS text, structured: A 1,700-line parser turns semi-structured Amadeus PNR output into passengers, segments, travel documents and multi-reissue ticket history: the format airlines actually emit, not the one the documentation promises.
Benchmarks you can reproduce: Airfare references are computed by layered cohort matching on route, cabin, lead time and month, with minimum-sample guards. Using a language model for the arithmetic was considered and rejected, because a quoted number has to be reproducible.
Drawings measured in the browser: Calibrate a plan PDF's scale, click to measure, and the dimensions become quote lines. pdf.js rendering under a canvas overlay replaced manual transcription from architectural drawings.
Funds modelled the way the law is written: Each investment project carries its operating company, management company and trust as first-class records. Receipts issue idempotently and void without deleting, because the audit trail is the product.
Permissions that fail closed: Page, project and tab-level scopes deny by default. The brokerage system carries 156 named permission codes re-checked at the service layer, with tests that attempt URL tampering and multi-role edge cases.
Schema evolution without downtime: Frontends write new fields first and fall back automatically where a field does not exist yet. When the backend catches up, behaviour upgrades itself with no redeploy and no interruption.
Big exports off the main thread: A 26,000-row by 88-column export froze the interface for five seconds. Moving spreadsheet generation into a Web Worker kept the desk interactive, and made long exports cancellable.
Websites AI can actually read: Full prerendering verified at build time, llms.txt fact layers, edge-level soft-404 fixes and payload cuts from 1.3 MB to 21 KB. Search engines and AI assistants see the real site, or the build does not ship.
THE DISCIPLINE BEHIND IT
How fourteen builds stay honest.
Evidence note
What is counted
Fourteen distinct builds: twelve in production or in delivery, two prototypes.
How it was measured
Source lines, file counts and commit counts read directly from Cyberate's own Git repositories.
Measurement date
August 2026.
What is excluded
Third-party dependencies, generated output and build artefacts. Two duplicate mirror repositories were removed from the commit count.
Relationship
Most of these systems were built for companies inside DDDI Group, Cyberate's parent group, so they are first-party deployments rather than independent customer references.
Lines of code and commit counts measure the volume of engineering work recorded, not its quality or its business value. They are reported here because they are checkable, not because they are the point.
Clients outside DDDI Group are described by industry rather than by name, because permission to publish their names has not been confirmed.
Figures for systems in delivery describe the build as it stands today and will change before handover.
Quality gates, not promises: Builds fail on missing H1s, broken prerenders, absent configuration and blown performance budgets. More than 400 automated tests run before anything deploys.
Proven, then productised: Ideas run as prototypes inside our own group first. The selections prototype lived four days as an experiment, and its best ideas now run in production for a real builder.
AI inside boundaries: Five AI workflows are live across these systems. Each reads within an agreed data boundary, drafts or flags, and waits for a person. None commits, sends or publishes on its own.
One chain, shared services: Group login, shared permission models and a common file layer connect the systems, so a builder, a fund and a development manager work from the same operating fabric.
Honest numbers only: Sample-size guards on statistics, education-not-eligibility scoping on assessment tools, and evidence notes on public claims. If we cannot verify it, we do not publish it.
The Build Record, in plain answers.
Is this a portfolio or a verified count?
A count. The totals on this page — 14 builds, 490k+ lines of TypeScript and JavaScript, 2,000+ source files, 1,500+ commits — were measured directly from Cyberate's own Git repositories in August 2026, excluding third-party dependencies and generated code. The evidence note sets out what was counted, what was excluded and what these numbers do not say.
Why are some of the clients unnamed?
Because they have not confirmed permission to be named. Companies inside DDDI Group are named, since they are already publicly associated with the group. External clients are described by industry instead: a licensed Australian brokerage, an international air-ticketing operator, a registered research service provider. We would rather publish a vaguer description than an unapproved name.
Are the interface images real screenshots?
No. They are recreations of the live interfaces, rebuilt as HTML rather than captured as images. Interface structure, field names, workflow stages and column layouts are the real ones. Client and project names are removed, supplier names become Supplier A to E, addresses are reduced to suburb and money figures are rounded to illustrative values. Every recreation carries a caption stating exactly what is real and what has been de-identified.
Does Cyberate take on work outside construction?
Yes, and four of the fourteen builds are outside it: airline ticketing, insurance broking, investment fund administration and R&D tax compliance. The common thread is regulated operations where an audit trail, a permission model and a reproducible number matter more than a fast demo. Construction remains the core, because that is the industry Cyberate is built inside.
Your workflow could be build fifteen.
Most operations start with the single stage where control leaks worst: quoting, scheduling, approvals, reporting or group finance. Tell us where it hurts, and we will tell you honestly whether something already in this record fits.