The challenge
Industrial safety software is judged at the moment something goes wrong. If a worker is in trouble, the alert has to reach the right people quickly and reliably, with an accurate picture of where that person is. In complex industrial environments, location is hard: sites are large, and different areas carry different risks.
The data is sensitive as well. Worker monitoring and location data is personal information about people at work, and enterprise customers expect it to be protected to a standard they can check. For a platform selling to industrial companies, security controls are part of the product, not an add-on.
Scope note: the product is Bodytrak’s. My part was the backend architecture and the security controls described here, working within the client’s engineering team.
The backend needed to:
- Turn real-time events into alerts without delay or loss
- Support incident reporting and integrations with other safety systems
- Handle geolocation and geofencing across complex industrial sites
- Protect worker data with encryption, MFA and role-based access
- Support scalable deployments without trading away reliability
What I built
I led the backend architecture around an event-driven design. Safety data arrives as a stream of events, and each one may need to raise an alert, update a location, add to an incident or notify another system. Treating those as events, rather than as requests that wait on each other, keeps alerting fast and lets each part fail or recover without blocking the rest.
Alerting, incident reporting and safety integrations were built on that event flow. An alert can feed an incident report, and the same events can be passed to other safety systems through integrations, so the platform fits into existing safety processes instead of sitting beside them.
Geolocation and geofencing provide the location intelligence. Geofences describe areas of a site, and location data is checked against them so the platform knows when someone enters or leaves an area that matters. In complex industrial environments that logic has to be precise: a false alert erodes trust, and a missed one is worse.
The services run as microservices in Python and Node.js on cloud-native AWS infrastructure. That supports scalable deployments, and it lets individual parts of the backend be scaled and released on their own, so a change to one integration doesn’t put alerting at risk.
On security, I implemented the controls enterprise buyers ask about first: encryption to protect sensitive data, multi-factor authentication (MFA) on access, and role-based access control so people see only the data their role needs. Building these into the backend, rather than adding them afterwards, means SOC 2 and ISO 27001 evidence can come from how the system actually works.
Architecture and stack
- Backend
- Python · Node.js · Microservices · Event-driven architecture
- Cloud
- AWS
- Location
- Geolocation · Geofencing
- Security
- Encryption · MFA · Role-based access control
Outcome
The backend I led gives Bodytrak an event-driven foundation for real-time safety: alerts, incident reporting and safety integrations built on the same flow of events, with geolocation and geofencing for complex industrial sites.
The security controls protect sensitive worker data and supported the company’s SOC 2 and ISO 27001 work. Together with the cloud-native setup, they support scalable deployments and product reliability, which is what customers in high-risk industries need before they rely on a safety platform.
The same experience shapes my consulting today. Security controls that hold up in an audit, and event-driven systems that stay up when it matters, are what I help other teams build.
- Event-driven alerting and incident reporting for real-time safety
- Location intelligence through geolocation and geofencing
- Encryption, MFA and role-based access protecting worker data
- Security controls that supported SOC 2 and ISO 27001 work
Last updated 2026-10-03