Passionfruit Design

The whole stack. One person.

Modern web apps with a CMS your team can actually use. Researched with the people who will use them, then designed, built, secured, hosted and run by me. Interface to DNS.

How I build

Minimal technical debt.

Every dependency, build step and moving part is a future cost to you. I only add one when it pays for itself, and I remove what stops paying. Code is linted, typed or validated at its edges, tested in CI, and documented well enough that someone else could take it over. Everything below follows from that.

  1. Slim servers.

    Small, single-purpose Node services with thin request handlers. No heavyweight runtime, no plugin pile. Several production apps share one 2GB VPS, and some have no npm dependencies at all. You get speed and a small hosting bill.

  2. JSON throughout.

    Content is structured data from a headless or JSON-backed CMS, not pages locked in a theme. Schemas are validated at the boundary with Zod or JSON Schema. The same data feeds your website, a PWA, a dashboard or another system without rework.

  3. Server-rendered first.

    HTML arrives complete, with its own title, description, canonical link and structured data. Pages are pre-rendered where the content allows. JavaScript enhances. It is never required to read the page.

  4. Build in CI or not at all.

    Servers run code. They do not build it. Where a server needs TypeScript, Node runs it directly with type stripping.

  5. Current versions, always.

    Dependencies stay on current releases. They are not left to rot until an upgrade becomes a project.

  6. Standard and portable.

    Nothing proprietary. The same app runs on a VPS, on Vercel, on Cloud Run or on Azure, and you can take it elsewhere.

The lot

Every layer, from the people using it down to the network. No subcontractors. No gaps.

  1. Research and design

    I find out what people need before I build it, then test it with them.

    • User research
    • Interviews
    • Usability testing
    • Prototyping
    • Interaction design
    • UX
    • Accessibility to WCAG 2.2 AA
  2. Research and data analysis

    I design the study, run it, analyse the results and report them. Large datasets included.

    • Study design
    • Surveys
    • Data analysis
    • Large datasets
    • Dashboards
    • Reporting
    • Peer-reviewed publication
  3. Architecture

    Designed for the job and sized to run fast on modest hardware.

    • Headless CMS
    • JSON APIs
    • Small services
    • Server rendering
    • Pre-rendering
    • Progressive enhancement
  4. Web apps with a CMS

    Your staff edit the content. Nobody phones a developer.

    • Payload
    • Directus
    • A custom CMS written for the job
  5. Interface

    Hand-written where that is enough, a framework where the app warrants it.

    • HTML
    • CSS
    • JavaScript
    • React
    • Next.js
    • TypeScript
    • Tailwind
  6. Application and data

    APIs, databases, and the data you already have, moved in safely.

    • Node
    • Express
    • Fastify
    • REST and JSON APIs
    • Postgres
    • SQLite
    • Prisma
    • Full-text search
    • Data migrations
    • Legacy imports
    • Feeds to and from other systems
  7. Identity

    One sign-in for every app, with roles that match how your organisation works.

    • Passkeys (WebAuthn)
    • OIDC
    • Single sign-on
    • Google sign-in
    • Magic links
    • Role hierarchies
    • Central identity service
  8. Payments and ticketing

    • Stripe
    • Box office
    • Events
    • Bookings
  9. Integrations

    • Social media hooks
    • Webhooks
    • Media pipelines
    • Third-party feeds
  10. AI

    LLM features behind a provider you can swap, with privacy designed into the schema.

    • LLM features
    • Swappable provider interface
    • Privacy by schema
  11. DevSecOps

    • GitHub Actions
    • Automated deploys
    • Dependency patching
    • Content Security Policy
    • Security headers
    • Secrets management
    • pm2
    • Docker
    • Monitoring
    • Health checks
  12. Hosting

    Several production apps on one small box.

    • Linux VPS
    • nginx
    • Vercel
    • Google Cloud
    • Managed Postgres
    • Backblaze B2
    • Object storage behind a CDN
  13. Cloudflare

    • DNS
    • CDN
    • Caching
    • TLS
    • Edge protection
  14. DNS and email

    Your domain cannot be spoofed, and your mail arrives.

    • DNS management
    • Domain migrations
    • SPF
    • DKIM
    • DMARC to p=reject
    • BIMI
    • MTA-STS
    • Mail forwarding
    • Mailing lists
    • Transactional email
  15. Network

    • Reverse proxies
    • TLS
    • Private networking
    • VPN (Tailscale)
    • Network design
  16. Policy and governance

    I write the policy as well as the code.

    • Data protection by design
    • Accessibility
    • Security policy
    • Safeguarding
    • Regulatory compliance

Work

A charity platform, small-business sites on custom CMSs, university systems and a public archive.

Receipts

Figures about this page, measured by the server that sent it. None of them are typed in by hand.

Page weight
11.7 KB Everything this page downloads, compressed, in 4 requests. Check it yourself: page weight
Server render
0.15 ms Median of the last 21 renders. 95% took under 1.1 ms. Check it yourself: Server-Timing response header (browser dev tools, Network tab)
Server memory
21.6 MB What this server holds on its own, right now. Node's shared program code is not counted. Check it yourself: server memory
Third-party requests
0 The content security policy lets the browser load from this domain only. Check it yourself: third-party requests
Runtime dependencies
2 69 packages installed in total, counted from the lockfile. Check it yourself: runtime dependencies
Cookies set
0 Out of 4 responses since the server started. Check it yourself: Application tab in your browser's dev tools
Version
8d56c42 Deployed 2 October 2026 at 16:45 UTC. Check it yourself: version
DMARC policy
p=none Read live from DNS for passionfruit.design. Check it yourself: dmarc policy
Security headers
This response was served with:
  • Content-Security-Policy
  • Strict-Transport-Security
  • X-Content-Type-Options
  • X-Frame-Options
  • Referrer-Policy
  • Permissions-Policy
  • Cross-Origin-Opener-Policy
  • Cross-Origin-Resource-Policy
  • Cross-Origin-Embedder-Policy
  • Origin-Agent-Cluster
Check it yourself: security headers

All of this as JSON

Tell me what you need

A few lines about the project is enough. I read every message myself. Or email hello@passionfruit.design, or call or WhatsApp 07385 509278 (open WhatsApp).