Project Objectives
🎯 Build a web and mobile eSignature platform with enterprise-grade security
🎯 Ensure full compliance with HIPAA, SOC 2, ISO 27001, and the eSign Act
🎯 Deliver intuitive, mobile-friendly UX with Figma-to-HTML implementation
🎯 Create a scalable, API-ready architecture for future roadmap items
🎯 Outsource the entire product lifecycle—from concept to go-live
Key Challenges
Compliance-Centric Build
The project demanded strict adherence to healthcare and data protection regulations, including HIPAA, SOC 2, and ISO 27001, right from Phase 1.
Mobile & Web Parity
Ensuring a consistent and seamless user experience across both mobile and web platforms was essential to meet user expectations.
Tight Timeline
Phase 1 had to be completed, tested, and launched within a tight 12-week timeline, including User Acceptance Testing (UAT).
Workflow Flexibility
The platform needed to support varied workflows across healthcare, human resources, and legal departments, requiring high flexibility in design and functionality.
Product Ownership
With development and deployment being outsourced, full product ownership and control had to be maintained externally, which introduced additional coordination challenges.
Perigeon's Role as Product Outsourcing Partner
As a full-cycle product development partner, Perigeon Software managed everything from architecture to release:
- Frontend (Web): Razor views, HTML5, Bootstrap, integrated from Figma designs
- Mobile App: Developed in Flutter for cross-platform support (iOS & Android)
- Backend: .NET REST APIs with OAuth-based secure access
- Cloud: Azure App Services, Azure SQL, Azure Blob for encrypted document storage
- Cloud & DevOps: Azure App Services, Blob Storage, Azure SQL, CI/CD pipeline
- Scheduler API: Built for automated document expiration and status tracking
Mobile Experience Highlights
- Dashboard for pending, signed, and expired documents
- One-click mobile signing with biometric verification (where supported)
- Push notifications for document reminders
- Offline draft support with background sync
- Consistent UX with web platform
🔐 Security and Compliance
- AES-256 encryption at rest, TLS 1.2 for data in transit
- eSign Act-compliant signature process with full audit trails
- HIPAA safeguards: session timeouts, activity logs, access control
- SOC 2-aligned security policies and ISO 27001-based information governance
- Role-based access and tamper-proof audit logging
🛠 Agile Product Outsourcing
- 6-member agile squad (Frontend, Mobile, Backend, QA, DevOps, PM)
- Bi-weekly sprint reviews and UAT with Valcare leadership
- Jira-managed sprint cycle and GitHub CI workflows
- Azure Monitor and Application Insights for diagnostics
Results & Business Impact
Web + Mobile Launch
Successfully launched Phase 1 across both web and mobile platforms within the 12-week deadline.
Compliance Success
Achieved full compliance with HIPAA, SOC 2, and ISO 27001 standards, ensuring data security and regulatory alignment.
Early Adoption
Over 500 users were onboarded within the first month post-launch, indicating strong initial adoption and market fit.
User Experience
Received a 4.8/5 average rating across App Store and web platforms, reflecting high user satisfaction and effective UX design.
Ready for Phase 2
Laid a strong foundation for upcoming development phases with scalable components like API integrations, workflow engine, and white-labeling options.