YandF DEV designs, builds and ships web, mobile and cloud products for companies in Morocco and beyond.
Mobile App + Self-Hosted API • Access Control
| Client | In-house product by YandF DEV |
|---|---|
| Sector | Events, education and institutions |
| Period | Documented 30 August 2026 (com.yandfdev.yandfevent) |
| Scope | Flutter application, self-hosted PHP API and MariaDB schema, ticket signing, GDPR centre, brand and icon pipeline |
| Our role | Everything: this is our own product, built and maintained by the team |
| Live product | https://yandef.com |
Attendance and access control for events: cryptographically signed tickets, offline decisions at the door, and participant data that never leaves your own server.
Event check-in fails in exactly the places events happen: a basement, a marquee, a saturated hall. Cloud-based scanners stop working the moment the network does, and the queue stops with them. Organisers who handle personal data — schools, institutions, companies — also have a second problem: the usual services hold the participant list on someone else's infrastructure.
The design starts from the queue, not the dashboard. Door staff need one decision — let this person in, or do not — delivered in under a second, in bad light, one-handed, while a line builds behind. Everything else (manual check-in for disputes, cancelling a scan, entry/exit/re-entry) sits one level down. The organiser's view is the opposite: live counters, attendance curve, flow per door, presence rate per session.
Dark, warm, high contrast: a near-black violet ground crossed by the amber-orange-magenta gradient taken from the logo, set in Inter. The whole icon set — adaptive Android icon with its monochrome layer, round icon, silhouette notification icons, Play Store icon, in-app logos — is derived from a single master file by a reproducible pipeline, so one image changes and everything regenerates.
Flutter on Android against a self-hosted PHP API and MariaDB at yandef.com. Event signing keys are encrypted at rest with AES-256-GCM and can be revoked in one gesture, invalidating every ticket issued before and regenerating the rest. The QR payload is 84 characters, uppercase only, which keeps it in alphanumeric mode — a smaller code, read faster, even printed small or shown on a cracked screen. Google Sign-In tokens are verified on the server (signature, issuer, audience, expiry), never on the phone.
Tech Stack: Flutter (Android), self-hosted PHP API, MariaDB, HMAC-SHA256 signed tickets, AES-256-GCM key storage, Google Sign-In verified server-side
How this was measured: The behaviours listed above are properties of the design — a signature that cannot be produced without the server key, a device-side identifier that makes a replayed upload a no-op — not measurements taken after the fact. Attendance figures from a live event will be added here once an organiser authorises publication.
Let's discuss your vision. Our team is ready to help you succeed.
Want something like Y&F Event?
Tell us what you are building and we will come back with an approach, a rough shape of the work and what it would take. We reply to every request within 1 business day.
Discuss a similar project