Kersia

Project Name: Kersia – Food Safety Management Platform

Client: Kersia Group

Timeline: 2024 – 2026

Project Status: Production Live | Actively Maintained

project overview

Gateway 2.0 (Kersia Gateway) is a cloud-native, multi-tenant SaaS platform developed for Kersia Group to manage industrial cleaning procedures, compliance documentation, and operational activities across customer sites. Replacing the legacy Gateway 1 system, the platform enables organizations to create, maintain, approve, and distribute Cleaning Instruction Cards (CICs) while managing customers, sites, products, multilingual content, scheduled cleaning activities, compliance workflows, reporting, and user administration. By centralizing operational processes and automating business workflows, Gateway improves compliance, operational efficiency, and data consistency across global customer environments.

Built using React 19 and .NET 10, the platform follows a scalable layered architecture powered by Azure Cosmos DB and modern Azure cloud services. Background processing with Hangfire, real-time communication through Azure SignalR, and integrations with Microsoft Entra External ID, Microsoft Dynamics 365, Oracle Integration Cloud, Mailgun, and Datadog enable secure identity management, enterprise integrations, workflow automation, and centralized monitoring. Designed for scalability, maintainability, and high availability, Gateway serves as Kersia's central platform for managing cleaning operations and regulatory compliance across multiple regions and customer organizations.

Technology Stack

Frontend: The frontend is developed as a modern React 19 single-page application using Vite and React Router 7, delivering a fast and responsive user experience. It leverages Telerik KendoReact components, Bootstrap 5, and SCSS to build enterprise dashboards, interactive data grids, scheduling interfaces, reports, document viewers, and administrative tools. Application state is managed using React Context and Immer, providing scalable state management without Redux. The platform also integrates Microsoft Entra External ID for authentication, Azure SignalR for real-time updates, multilingual support through Crowdin, and Datadog Browser RUM for client-side monitoring, while Progressive Web App (PWA) capabilities enable installation and offline support.

Backend: The backend is built on .NET 10 using a layered architecture that separates business logic, data access, and shared infrastructure into maintainable projects. ASP.NET Web API exposes versioned RESTful APIs supporting customer and site administration, cleaning procedures, scheduling, reporting, user management, translations, and compliance workflows. Hangfire automates background processing for synchronization, scheduled cleaning tasks, notifications, and system maintenance, while integrations with Azure Functions and Microsoft Dynamics 365 provide document generation, Excel processing, image management, CRM connectivity, and legacy Gateway 1 data migration.

Authentication & Security: Authentication is implemented using Microsoft Entra External ID with JWT Bearer Authentication, while selected services also support API Key Authentication for secure system integration. The platform utilizes claims-based authorization, role and permission management, Microsoft Graph for user administration, mandatory multi-factor authentication (MFA) for local accounts, and additional security measures including Content Security Policy (CSP), HTML sanitization, security headers, and Cloudflare IP allow-listing to protect enterprise resources.

Database: The application uses Azure Cosmos DB as its primary database, with Entity Framework Core Cosmos Provider managing scalable, multi-tenant data persistence across shared and customer-specific datasets. Azure Blob Storage stores documents and media assets, while Redis provides distributed caching and supports real-time messaging through Azure SignalR. SQL Server is used only during the migration of historical data from the legacy Gateway 1 platform.

Third-Party Integrations: Gateway integrates with a wide range of enterprise services, including Azure Cosmos DB, Azure Blob Storage, Azure SignalR, Microsoft Entra External ID, Microsoft Dynamics 365, and Azure Functions, Azure Container Apps, Azure Static Web Apps, Azure Key Vault, Azure Container Registry, and Redis. Additional integrations with Microsoft Graph, Mailgun, IronPDF, Crowdin, Oracle Integration Cloud, Datadog, and Cloudflare enable identity management, CRM integration, email delivery, document generation, multilingual content management, legacy system migration, application monitoring, and enterprise-grade security.

Monitoring & Logging: Application monitoring and centralized logging are implemented using Serilog and Datadog, providing structured logging, distributed tracing, production diagnostics, and performance monitoring across backend services. The frontend is monitored using Datadog Browser RUM to capture client-side performance metrics and runtime errors, while Azure Application Insights supports monitoring for Azure Functions and supporting cloud services. Health endpoints and deployment metadata further simplify operational monitoring and production support.

Testing: The application follows a comprehensive testing strategy using xUnit, FluentAssertions, Vitest, and React Testing Library for backend unit testing, frontend component validation, and code coverage. On the frontend, these testing practices help maintain application quality and reliability throughout ongoing development.

Deployment & DevOps: The project uses GitHub Actions for CI/CD across development, staging, and production environments. Backend services are containerised with Docker and deployed to Azure Container Apps, while the image processing service runs as an Azure Function App. The React frontend is deployed through Azure Static Web Apps.

portfolio item photo

Sign-off dashboard

portfolio item photo

Gateway ac - Scheduler

portfolio item photo

Cleaning Procedure - Pdf Report

client

Kersia

category

Web Development

contact us

get in touch with us

-->