# Build brief — a focused alternative to Proofling

> **Verdict:** Partly, if you narrow it · **Buildability:** 49/100 · **Category:** Testimonials
> **Source:** https://www.canitbevibecoded.com/proofling
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from Proofling. Verify current pricing and capabilities before acting.

## Context

**Proofling** — Automated testimonial asks, follow-ups, approval, and embeddable proof. It currently costs $19/mo.

A collection form, approval queue, wall, and embed are one-session work. The real Proofling loop adds payment-triggered asks, dependable email follow-ups, consent history, video processing, and integrations, which makes an honest replacement a contained effort project with ongoing operational work.

This brief describes a focused, single-operator replacement for the part of Proofling that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Accept a payment webhook, schedule one testimonial request and follow-up, collect consent, approve replies, and render them on a hosted wall and embed.

- Build a focused single-user workflow with real persistence, search, and export.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Node.js 22.

### Data and integrations

- Stripe account and webhook signing secret.
- Resend API key.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build a self-hosted testimonial automation app inspired by Proofling.
Use Node.js 22, TypeScript, Fastify, better-sqlite3, server-rendered HTML, and vanilla CSS.
Keep it single-tenant and deployable as one small service on a VPS.

- Add an .env.example for ADMIN_PASSWORD, APP_URL, STRIPE_WEBHOOK_SECRET, and RESEND_API_KEY.
- Create POST /webhooks/stripe and verify Stripe signatures before processing events.
- Idempotently store completed checkout customers and ignore duplicate webhook deliveries.
- Let the admin configure an ask delay, one optional follow-up delay, sender name, and message copy.
- Run a database-backed worker every minute; queued jobs must survive restarts and retry with backoff.
- Send email through Resend, with MAIL_MODE=log for local development without an API key.
- Give each customer an expiring signed /r/:token response link; never expose sequential database IDs.
- Collect name, role, company, optional 1-5 rating, testimonial text, avatar, and explicit publication consent.
- Resize avatars to 128px WebP, discard originals, and reject oversized or non-image uploads.
- Add a Basic Auth /admin page with pending, approved, private, and failed-delivery views.
- Allow approve, unpublish, delete, and resend; nothing public appears before approval and consent.
- Render a mobile-friendly /wall page with approved cards, dark mode, and honest buyer-context badges.
- Serve /embed.js so one script plus a div creates a sandboxed, auto-resizing wall on another site.
- Expose approved data at /proof.json and /proof.md without private contact details.
- Exclude multi-user accounts, billing, non-Stripe integrations, video, AI rewriting, and referrals.
- Add tests for signature verification, webhook idempotency, scheduling, consent gates, and public filtering.
- Include SQLite migrations, seed data, a Dockerfile, and a README covering setup, backups, and permissions.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Polished onboarding and multi-tenant workspaces.
- Payment integrations beyond the single Stripe webhook.
- Managed email delivery, retries, scheduling, and suppression.
- Guided video capture, processing, captions, and retention controls.
- Connectors, OAuth flows, and vendor API changes require constant upkeep.
- Reliability at the vendor's scale is an operations problem, not a prompt.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/proofling
