Back to Case Studies
01CASE STUDY

HPD Compliance Operating System

A complete compliance management platform for NYC HPD violations - eliminating deadline surprises, scattered documents, and coordination chaos across 300+ buildings.

The pain

Missed certification windows → higher fees

No automated deadline tracking meant violations slipped past certification dates, triggering escalation and additional penalties.

No single source of truth

Case details lived across emails, PDFs, spreadsheets, and portal screenshots-leading to lost context and duplicated effort.

Evidence scattered everywhere

Photos, invoices, access logs stored in WhatsApp, email attachments, and local drives. Certification packets took hours to compile manually.

Access coordination killed productivity

Scheduling inspections, managing tenant communication, and documenting 'no access' failures consumed excessive team time.

Portfolio-level triage was impossible

No visibility into which buildings needed urgent attention. Teams reacted to fires instead of preventing them.

Compliance Timeline Engine

Automated deadline calculation, SLA tracking, and escalation flags based on violation type and certification windows.

  • - Rules-driven deadline computation
  • - Email/SMS reminders (T-72h, T-24h, T-2h)
  • - Urgency scoring & prioritization

Case OS + Unified Timeline

Single case file per building: all violations, tasks, documents, communications, inspections in one auditable timeline.

  • - Event-sourced activity log
  • - Full-text search + faceted filters
  • - HPD data sync (daily ingestion)

Evidence Vault

Structured proof collection: photos, invoices, contractor attestations with before/after validation and tamper detection.

  • - Required evidence checklists
  • - Auto-timestamping + EXIF capture
  • - One-click certification packet export

Access Orchestration

Tenant scheduling, automated reminders, 'no access' documentation workflows, and delivery tracking.

  • - SMS/WhatsApp notification sequences
  • - Tenant contact preference tracking
  • - Calendar sync (Google/Outlook)

Portfolio Risk Dashboard

Real-time risk scoring across all buildings: severity + deadline proximity + repeat history + enforcement flags.

  • - "Top 20 at-risk" live view
  • - Blocked/stalled reason tracking
  • - Trend analysis (buildings worsening)

Multi-tenant Architecture

Enterprise white-label ready: separate portals for inspectors, clients, and admins with role-based access control.

  • - Subdomain per company
  • - Granular RBAC (inspector/client/admin)
  • - Activity audit logs

Portfolio-level risk dashboard with real-time prioritization

Portfolio dashboard showing 300+ buildings with risk scores, deadline proximity, and status distribution.

Unified case timeline-every event in chronological order

Violation lifecycle timeline showing all events: issuance, appointments, evidence uploads, status changes, certification.

Evidence vault with required proof checklists

Evidence checklist interface: required photos, contractor attestations, before/after validation status.

Mobile-first inspector portal for field operations

Inspector portal mobile view: schedule, access appointment details, upload evidence on-site.

Outcome

Zero

Missed certification deadlines since deployment

What changed

Compliance became predictable. The team went from reactive firefighting to proactive case management.

Portfolio visibility unlocked strategic decisions. Risk scoring showed which buildings needed attention first, enabling better resource allocation and client communication.

Documentation became defensible. Every closure is backed by structured proof-photos timestamped, contractors attested, access attempts logged. Disputes are resolved with evidence, not memory.

Operations scaled without adding chaos. New buildings onboard in minutes. Inspectors work from mobile. Clients see status updates in real-time. The system handles growth without breaking.

Built as a scalable, multi-tenant SaaS platform designed for reliability, auditability, and future regulatory expansion beyond HPD.

Core Primitives

Abstractions that work for any compliance domain

ObligationRuleEventTaskEvidence

Stack

Next.jsNestJSPostgreSQLS3-compatible storageJob queuesSMS/email providers

Key Design Decisions

  • Event-sourced timeline for immutable audit trails
  • Rules engine (config-driven) for deadline/escalation logic
  • Multi-tenant with row-level security

Need a compliance operating system?

We build systems that make regulatory work predictable, defensible, and scalable-for HPD, environmental law, or any compliance domain.