Delivered remotely for a business based in Madrid, Spain. Names withheld by agreement.
Project Overview
Industry: Public safety and emergency response technology, with an adjacent consumer personal-safety application.
Type of solution: A real-time video platform: a REST API with four role-specific web portals, two native mobile applications, browser-based responder and site-operator consoles, geofenced coverage routing, and an evidence retention pipeline.
Business context: A person in an unsafe situation has one tool — the camera in their pocket. It produces a private file on a private device. It does not reach anyone who can respond, it is not preserved anywhere, and it disappears entirely if the device does. On the other side, an emergency response agency has no practical way to receive live citizen video that is scoped to its own area of responsibility. Jurisdiction is geographic and does not follow place names, so "is this incident ours?" is a question that has to be answered by geometry, not by an address string.
General users: Members of the public opening live sessions from mobile; responders and their delegated sub-users watching and joining sessions from a browser; site operators publishing streams from a fixed location; consumer subscribers using trusted-contact alerting; and platform administrators managing coverage areas, agencies and the session archive.
General purpose: To move video evidence off the individual's device in real time, put it in front of the agency responsible for that location within seconds, and preserve it afterwards in storage that the agency owns.
The Business Challenge
The recording never leaves the phone. A private video file on a personal device is not evidence in any useful sense. It is not visible to anyone who could act, and it does not survive the device being seized, damaged or drained.
Seconds matter, and the work before the first frame is substantial. Between the user's tap and a responder seeing video, the system has to acquire a location fix, resolve an address, determine coverage, create a recorded room, mint credentials and notify people. All of that has to feel like one tap.
Sessions end badly by definition. In this product the normal termination path is the exception. Devices get taken, batteries die, signal drops, apps get force-closed. If finalisation depends on the client behaving correctly, the recording is lost precisely in the situations where it matters most.
Jurisdiction is a shape, not a name. Reverse geocoding a set of coordinates returns a locality string. Agency coverage is a polygon that does not align with locality boundaries, and coverage areas genuinely overlap. Getting this wrong routes an incident to the wrong desk.
Evidence belongs to the agency, not the platform. Recorded sessions are sensitive material with retention and custody expectations. Pooling everything into one platform-controlled store is the wrong answer.
Four different clients, one media pipeline. Two native mobile apps, a responder console in a browser and a site-operator publisher all have to join the same kind of session, with different capture sources, different lifecycles and different controls.
Responders are not sitting at a screen waiting. A session that nobody notices is the same as no session. Notification has to reach people who may be anywhere, and the console has to surface an incoming session no matter what page a responder is on.
Entitlement changes where the app cannot see it. For the subscription-backed consumer module, subscription state changes at the app store, often while the application is not running at all.
Our Approach
Keep the application out of the media path entirely. The backend mints short-lived, single-room access credentials and configures each session's recording rules; media flows directly between participants and hosted real-time video infrastructure. This is the decision that makes everything else affordable: the application tier scales with sessions created, not with minutes of video streamed.
Make session finalisation reachable from three directions. The client reports completion. The video infrastructure fires a room-ended webhook. And a scheduled reconciliation sweep looks for completed sessions that have no recording and generates one. Any single path failing does not cost the recording. On Android we went further and finalise the session when the app is removed from recents, rather than orphaning a live room.
Resolve coverage geometrically. Administrators draw coverage areas as polygons on a map. At session start, the device's coordinates are reverse geocoded for a human-readable address and tested for containment within stored coverage areas. Where areas overlap, the user is shown the options rather than having one picked for them, and where no polygon is configured the platform falls back to a locality match.
Store evidence where it belongs. Each coverage area can be configured with its own object storage destination and credentials, so composed recordings are written into storage the agency controls rather than into a single shared platform bucket.
Offload media as a resumable batch. Recordings are composed by the video infrastructure at session end, then pulled and re-stored on a nightly schedule in small batches, with a per-session status flag so the job resumes cleanly rather than reprocessing.
Verify every endpoint an alert can reach. For trusted-contact alerting, each contact's phone number and email address is independently verified by one-time passcode before it can receive anything. An emergency message to a mistyped number is worse than no message.
Drive entitlement from store notifications. Both stores' server-to-server notification channels are consumed, signed payloads decoded, and an explicit transition model applied for renewal, cancellation, expiry and auto-renew changes — with a scheduled revalidation sweep behind it and a persisted notification audit trail.
Build the mobile clients natively. Real-time capture with explicit codec control, background and foreground lifecycle handling, screen capture and device-side fallback recording are exactly the areas where a native implementation earns its cost.
The Solution
One-tap live session. From the mobile application, a single action acquires location, checks coverage, creates a recorded room and puts the user on camera with two-way audio and video.
Geofenced coverage routing. Map-drawn coverage polygons determine which agency receives a session, with overlapping coverage surfaced as a choice and a locality-based fallback where no polygon exists.
Immediate responder notification. When a session opens, SMS alerts go to the active responders assigned to the resolved coverage area, carrying the incident's address.
Agency console. Responders see the live sessions in their assigned areas, with counts updating continuously in the navigation so an incoming session is visible from any page. They join the live session in the browser, and can leave or end it.
Two-way session, not a one-way feed. The person on scene and the responder are in the same room, with camera flip, microphone control, speaker routing and reconnection handling on the mobile side.
Session thumbnails from the live stream. A frame is captured from the outgoing video track and uploaded as the session's thumbnail, so the console shows what a session actually looks like without touching the recording.
Recorded evidence with a preserved archive. Every session is recorded under server-enforced rules, composed at the end, and transferred on a schedule into the coverage area's own object storage. Playback is available in the consoles and in the mobile apps.
Site operator streaming. A fixed-location operator publishes a live stream from the browser, combining camera and display capture as separate tracks into the same session model, with the same recording and archive behaviour.
Delegated agency accounts. Agencies provision their own sub-user accounts within an allocated seat count, each scoped to the same coverage areas.
Trusted-contact alerting. In the consumer module, a subscriber maintains a list of verified contacts and a set of pre-written messages, and can send any of them — or a custom message — as an SMS carrying a location link.
Verified identity. Registration is confirmed by SMS one-time passcode, login can require a second factor, and email and phone changes are each re-verified.
Subscription lifecycle. In-app purchase on both platforms with restore support, receipt validation, store server notification handling and scheduled revalidation.
Administrative platform. Coverage areas and their geofences, agencies and responders, users, content pages, session archive and per-area storage configuration, all managed from a server-rendered back office.
Key Features
Geofenced incident routing Coverage areas drawn as polygons on a map determine which agency receives a live session, with overlapping coverage presented as a user choice rather than resolved arbitrarily.
One-tap recorded live session Location acquisition, coverage resolution, room creation, credential minting and responder notification collapsed into a single user action.
Triple-redundant session finalisation Client reporting, infrastructure webhooks and a scheduled reconciliation sweep independently ensure a session closes and produces a recording, because the normal failure mode here is the device disappearing mid-session.
Per-agency evidence storage Each coverage area can write its composed recordings into its own object storage destination with its own credentials, keeping custody of the material with the agency.
Browser-based responder console Responders watch and join live sessions from a browser with no installation, with live session counts surfacing across the interface.
Multi-source site streaming A fixed-location operator publishes camera and display capture as separate tracks into the same recorded session model.
Two-way real-time session Native mobile clients with explicit codec selection, camera and microphone control, audio routing and reconnection handling — not a one-way broadcast.
Verified trusted-contact alerting Pre-written or custom messages sent by SMS with a location link, to contacts whose phone and email have each been separately verified.
Store-driven subscription entitlement Entitlement state derived from signed store server notifications with an explicit transition model, backed by scheduled receipt revalidation and a persisted notification audit trail.
Layered role model with delegated provisioning Separate authenticated portals for administrators, agency responders, delegated sub-users and site operators, with agencies provisioning their own seats within an allocated limit.
Technical Architecture
Mobile clients. Two native applications built independently for their platforms. Both integrate the real-time video SDK for capture and participation, acquire and reverse-geocode location, handle background and foreground transitions carefully, and upload a captured frame as the session thumbnail. The Android client adds a foreground media-projection capability and a background service that finalises the session if the app is removed from recents; the iOS client adds a device-side capture fallback and native in-app purchase handling.
API layer. A token-authenticated REST API serving both mobile clients, covering registration and verification, session creation and status, coverage lookup, trusted contacts and messaging, and subscription operations.
Web portals. Four session-authenticated server-rendered portals — administrator, agency responder, delegated sub-user and site operator — each behind its own role middleware, with the responder and operator portals embedding the real-time video JS SDK for browser-based participation and publishing.
Real-time media layer. Hosted real-time video infrastructure handles all media. The application configures rooms with server-side recording rules, mints short-lived room-scoped access credentials, and receives room and composition status webhooks. No media traverses the application tier.
Coverage resolution. Device coordinates are reverse geocoded through a mapping provider, then tested for containment against stored coverage polygons, returning one area or several. Coverage areas are authored in the administrative portal using map drawing tools.
Notification layer. SMS delivery for responder alerts, one-time passcodes and trusted-contact messages, through a hosted communications provider; email for password recovery and contact verification.
Media retention pipeline. Recordings are composed at session end, with a scheduled reconciliation command generating any that are missing. A nightly command pulls each composed recording and writes it into the object storage destination configured for that session's coverage area, marking the session as transferred so the job is resumable.
Billing layer. In-app purchase on both platforms, with receipt validation, store server-to-server notification endpoints, an entitlement transition model and a scheduled revalidation sweep.
Data layer. A relational database holding users and roles, coverage areas with their geofences and storage configuration, agency-to-area assignments, sessions with location and lifecycle state, trusted contacts, subscriptions and store notification records.
Flow: Native mobile app → Token-authenticated API → Coverage resolution (reverse geocode + polygon containment) → Recorded room created, room-scoped credentials issued → Responder SMS alert → Browser console joins live session → Room and composition webhooks → Scheduled media transfer → Per-agency object storage
Technology Stack
| Category | Technology |
|---|---|
| Backend language | PHP |
| Backend framework | Laravel |
| Database | PostgreSQL, migration-managed schema |
| API authentication | Laravel Passport (OAuth2 bearer tokens) |
| Web portals | Blade server-rendered portals with Bootstrap, jQuery and DataTables |
| Asset pipeline | Laravel Mix / webpack / Sass |
| Real-time video | Twilio Programmable Video — rooms, server-side recording rules, compositions, scoped access tokens, status webhooks |
| Messaging & verification | Twilio Programmable SMS and Twilio Verify (registration OTP, optional login second factor) |
| Object storage | Google Cloud Storage, with per-coverage-area bucket and credential selection |
| Mapping | Google Geocoding API; Google Maps JavaScript API with the drawing library for geofence authoring |
| Scheduled work | Laravel console commands — media transfer, composition reconciliation, subscription revalidation |
| Caching & queues | Redis and queue configuration |
| Android | Java and Kotlin, Java 17, Android Gradle Plugin 8, minSdk 24 / target SDK 34, build flavours per environment |
| Android libraries | Twilio Video Android SDK, Retrofit 2 with OkHttp, Fused Location Provider, Glide and Ion, ExoPlayer-based playback, foreground media-projection service |
| iOS | Swift, UIKit with storyboards, iOS 15 deployment target |
| iOS libraries | Twilio Video iOS SDK, Alamofire, StoreKit in-app purchases, AVFoundation capture, CoreLocation and MapKit, MessageUI |
| Billing | Apple in-app purchase with App Store server notifications; Google Play billing with Play Developer API and real-time developer notifications |
| Delivery | CI pipeline driving a release-based deployment tool across staging and production |
Technical Challenges & Solutions
| Challenge | Our Approach |
|---|---|
| A session must go from a single tap to live, recorded and dispatched in seconds | The whole sequence — location fix, reverse geocode, coverage resolution, room creation, credential minting and responder SMS fan-out — is collapsed into one server round trip behind one user action, with the client rendering the camera preview while it completes. |
| Sessions routinely terminate abnormally, which is exactly when the recording matters most | Finalisation is reachable from three independent directions: the client's own status update, the infrastructure's room-ended webhook, and a scheduled sweep that finds completed sessions with no recording and generates one. On Android, removing the app from recents also finalises the session rather than orphaning it. |
| Agency jurisdiction is geographic and does not follow place names | Coverage areas are authored as map-drawn polygons and evaluated by geometric containment against the device's coordinates at session start. Overlapping coverage returns multiple areas and lets the user choose; a locality match is retained as a fallback where no polygon is configured. |
| Recorded evidence belongs to the agency, not the platform | Each coverage area carries its own object storage destination and credentials, so composed recordings are written into storage the agency controls rather than pooled into a single platform-owned bucket. |
| Real-time video at scale would overwhelm an application tier | Media never touches the application. The backend configures rooms, enforces recording server-side and mints short-lived room-scoped credentials; participants exchange media directly with hosted infrastructure, so the application scales with sessions created rather than minutes streamed. |
| Four different clients had to join the same kind of session | A single room model with server-side recording rules, joined by two native mobile clients, a browser responder console and a browser publishing console — each with its own capture sources and controls, none of them able to change whether the session is recorded. |
| Responders are not sitting watching an empty console | SMS alerts go to the responders assigned to the resolved coverage area the moment a session opens, and live session counts are polled into the console navigation so an incoming session is visible from any page. |
| Subscription state changes at the store, not in the app | Entitlement is driven by both stores' signed server-to-server notifications with an explicit transition model for renewal, cancellation, expiry and auto-renew changes, backed by a scheduled revalidation sweep and a persisted notification audit trail. |
| Emergency alerts sent to unverified contact details | Every trusted contact's phone number and email address is independently verified by one-time passcode before it is eligible to receive an alert. |
Security & Reliability
Authentication. OAuth2 bearer-token authentication for the mobile API and session authentication for the web portals, with registration confirmed by SMS one-time passcode and an optional SMS second factor at login.
Separated role portals. Administrator, agency responder, delegated sub-user and site operator each occupy a distinct route group behind its own authentication middleware, rather than sharing one portal with conditional rendering.
Scoped session visibility. A responder sees only sessions in the coverage areas assigned to their account, and delegated sub-users inherit the scope of the account that provisioned them.
Scoped, short-lived media credentials. Video access credentials are minted server-side, grant access to exactly one room, and expire on a bounded window. Recording rules are set by the server, so no client can opt a session out of being recorded.
Time-limited media access. Playback of composed recordings uses short-lived signed URLs rather than durable public links.
Verified alert endpoints. Both the phone number and the email address of every trusted contact are separately verified before they can receive an emergency message.
Custody of evidence. Per-coverage-area storage destinations keep recorded material in storage the agency controls, separated from other agencies' material.
Resilient finalisation. Three independent paths ensure a session closes and produces a recording, so an abnormally terminated session still yields preserved evidence.
Transport and origin controls. Cross-origin policy and trusted-proxy handling on the API, with input sanitisation on write paths.
Scalability & Performance
Media out of the application path. The single largest scaling decision in the system: the application mints credentials and receives webhooks, while media flows directly between participants and hosted infrastructure. Load on the application tier tracks sessions created, not minutes streamed.
Batched, resumable media transfer. Composed recordings are pulled into object storage on a nightly schedule in bounded batches, with a per-session status flag so an interrupted run resumes rather than reprocesses.
Bounded reconciliation. The sweep that generates missing recordings processes a limited number of sessions per run, so a backlog drains steadily rather than producing a load spike.
Scoped, paginated consoles. Responder listings are filtered to assigned coverage areas and paginated, keeping result sets bounded regardless of platform-wide volume.
Lightweight liveness polling. The continuously refreshed live-session indicator calls a dedicated count endpoint rather than re-fetching session listings.
Thumbnails from the stream, not the recording. Session thumbnails are captured from the outgoing video frame on the device, avoiding any server-side processing of recorded media.
Explicit encoding control on mobile. Codec selection and encoding parameters are set directly on the native clients, so video quality degrades gracefully on constrained connections instead of failing.
Stateless application tier. Token authentication and externalised object storage keep application instances free of local state, with cache and queue infrastructure configured for offload.
Business Outcomes
- Video leaves the device in real time, so a recording survives whatever happens to the phone that made it.
- Incidents reach the agency responsible for that location, resolved geometrically rather than by place name, with overlapping coverage handled as a deliberate choice.
- Responders are alerted rather than expected to watch, with SMS notification at session start and live counts surfaced across the console.
- Recordings are preserved into storage the agency controls, keeping custody of sensitive material with the organisation that owns it.
- Sessions that end abnormally still produce evidence, because finalisation does not depend on any single component behaving correctly.
- Agencies manage their own users, provisioning delegated accounts within their allocated seats without platform involvement.
- Fixed sites can publish into the same pipeline, extending the platform beyond mobile capture with no separate infrastructure.
- Entitlement stays correct without the app running, driven by store notifications and a revalidation sweep rather than by client reporting.
Why it worked
Real-time video products are easy to demonstrate and hard to make trustworthy. The demo is a room with two participants and a working camera. The product is what happens when the camera is knocked out of someone's hand, the network drops in the middle of a session, the app is force-closed, or a coverage boundary runs through the middle of a street. In an emergency product those are not edge cases — they are the operating conditions.
Our team builds for those conditions. We designed session finalisation so that no single component can cost a recording, with the client, the infrastructure webhook and a scheduled sweep each able to complete the job alone. We kept media out of the application tier entirely, which is what makes the economics work and what keeps the platform responsive under load. We treated jurisdiction as geometry rather than as a string, because routing an incident to the wrong desk is a failure that costs time nobody has. And we put recorded evidence in storage the agency controls, because custody of that material is a governance question before it is a technical one.
Our teams work across Laravel and modern PHP, real-time video integration, native Android and native iOS development, geospatial routing, scheduled media pipelines, store billing and subscription lifecycle management, and multi-tenant role architecture — with the judgement to know which failure modes in a safety-critical product have to be engineered against rather than documented.
Final Summary
Someone who feels unsafe reaches for their phone and starts recording. Until this platform existed, that produced a private file on a private device — invisible to anyone who could help, and gone if the device was taken or died. On the other side, emergency response agencies had no way to receive live citizen video scoped to the area they are actually responsible for.
Our team built a platform that closes the gap in a single tap. Location is acquired and reverse geocoded, coverage is resolved against map-drawn polygons, a recorded two-way video room is created, credentials scoped to that one room are issued, and the responders covering that location are alerted by SMS — all before the first frame reaches a console. Responders join from a browser with nothing to install, see live session counts wherever they are in the interface, and can watch, participate or end the session. Recordings are composed automatically and transferred on a schedule into object storage that the agency itself controls.
The engineering that matters most is invisible. Session finalisation is reachable from three independent directions — the client, the infrastructure webhook, and a scheduled reconciliation sweep — because in this product the ordinary way a session ends is the device disappearing. Media never touches the application tier, so the platform scales with sessions rather than with streaming minutes. Coverage is geometry, not place names. Alert destinations are verified before they can receive anything. Around that sit native mobile clients on both platforms, browser-based consoles for responders and fixed sites, role-separated portals with delegated provisioning, and store-driven subscription entitlement. The result is a system where the recording survives the situation that produced it — which, in a safety product, is the only test that matters.