Aviation
Preparation Academy

Serving CPL Meteorology, chapter 4
Live Platform

Material is not preparation

A student pilot can have all the material and still not know what actually matters, why a correct answer is correct, or how they will hold up under exam timing.

And behind them, someone has to actually run the business: examinations, products, orders, coupons, guarantee claims, refunds, student access. If that needs a developer every time, it isn't a platform — it's a website with a bill attached.

Three audiences, one codebase

A public marketing site, a student learning platform and an admin CMS in one Next.js application. Prospective students get pricing transparency and a free ten-question mock exam before they commit to anything.

Active learners get syllabus-indexed study material across PPL, CPL and IR — fifteen theory subjects plus flight-test groundwork — chapter-based practice, timed mock exams at real exam pace, automated Knowledge Deficiency Reports delivered as PDFs by email, and progress tracked per student.

From syllabus to a measured read

Learn

syllabus-indexed

Practice

chapter-based

Mock

real exam timing

KDR

emailed as PDF

Track

per student

Ready

guarantee-backed

The browser is never trusted

Everything that decides money or access — prices, discounts, entitlements, payment verification, guarantee eligibility — is computed server-side. None of it is taken on the client's word.

That is not a posture statement; it is tested. A dedicated suite runs thirty checks across access control, IDOR, authentication integrity, payment tampering and XSS. The last audit recorded zero vulnerabilities.

Where the thinking went

  • Server-side money and access — prices, discounts, entitlements and guarantee eligibility are all computed on the server. A price that can be edited in a devtools panel is not a price.
  • Verified payments, not reported ones — Razorpay callbacks are checked by server-side signature verification before anything is granted — the client saying a payment succeeded is not evidence that it did.
  • Signed sessions — JWT sessions signed with jose, passwords hashed with bcryptjs. Input validated with zod at the boundary rather than trusted inward.
  • Reports as artefacts — Knowledge Deficiency Reports are generated server-side as PDFs with pdfkit and delivered by email through Resend — something a student keeps, not a page they have to be logged in to re-read.
  • A content pipeline, not hand-keying — dedicated tooling extracts, imports, maps, audits and changelogs PPL, CPL and IR syllabus content, with coverage and visibility reports — so fifteen subjects stay in sync with their source syllabi instead of drifting.
  • Own design system — a custom CSS design system carrying light and dark themes, rather than a UI framework — the interface is the product's, not a library's defaults.

What is actually built

0

Theory subjects

0

Unit tests

0

Assertions

0

Security checks

A platform someone can actually run

Full CMS

Examinations, products, orders, coupons, guarantee claims, refunds and student access — all managed without touching code.

A guarantee with a workflow

The first-attempt pass guarantee is not a marketing line: claims and eligibility are modelled, and refunds are handled.

Tested where it counts

Around 1,500 assertions across purchase flows, payments, guarantee workflows, accessibility and security — Vitest for units, Playwright and custom Node suites for the rest.

Independent, and says so

Built against the NZ Privacy Act and India's DPDP Act. Not affiliated with, endorsed by, or acting on behalf of Aspeq or CAANZ.

Where it goes next

Insight

Deeper readiness analytics on top of the progress data the platform already captures per student and per subject.

Content

Wider syllabus coverage through the same extraction and audit pipeline that keeps the current fifteen subjects current.

Scale

Instructor and school accounts — cohort visibility over the same entitlement model that already governs individual access.

01 — Documentation

README

Complete project documentation.

02 — Source

Open Repository

Public source code on GitHub.

The full platform — all three surfaces.

Tech Stack

Application

Next.js 16, React 19

Language

TypeScript, strict

Data

PostgreSQL 16, Prisma 6

Commerce

Razorpay, Resend, pdfkit

Assurance

Vitest, Playwright, zod

Building something where readiness is the real question?

Measuring whether someone is ready — and getting money and access right every time — is the hard part. Let's talk.