Skip to content

Ilia DudaCo-op Jan 2027

A debt-settlement portal built to Russian federal law

Sole Developer and Project Lead · July 2026 – present

A self-service portal where people settle a debt without a phone call, built end to end as sole developer for a licensed Russian collection organisation. Federal law set the architecture: personal data stays in the country, and every login code is counted against a legal contact allowance, the conservative reading of an unsettled question; both are enforced in code and at build time.


Fig. 1
A settlement, with only the terms worth choosingthe portal’s arithmetic · illustrative discount ladder, not the client’s terms

Settlement calculator

Discount
15%
Pays in total
51,000 ₽
Monthly
4,250 ₽
Last payment
4,250 ₽

Monthly payment by term. 35 terms offered up to 36 months; 1 hidden (hollow): at a step in the discount ladder a longer term would cost more a month. Dashed lines are the ladder’s steps.

The calculator offers only terms worth choosing: at a step in the discount ladder a longer term would cost more a month, so that term is hidden (hollow). Every sum is in integer kopecks.
Offered terms for an illustrative debt of 60,000 ₽
MonthsDiscountMonthlyLast payment
130%42,000 ₽42,000 ₽
225%22,500 ₽22,500 ₽
325%15,000 ₽15,000 ₽
420%12,000 ₽12,000 ₽
520%9,600 ₽9,600 ₽
620%8,000 ₽8,000 ₽
715%7,286 ₽7,284 ₽
815%6,375 ₽6,375 ₽
915%5,667 ₽5,664 ₽
1015%5,100 ₽5,100 ₽
1115%4,637 ₽4,630 ₽
1215%4,250 ₽4,250 ₽
1310%4,154 ₽4,152 ₽
1410%3,858 ₽3,846 ₽
1510%3,600 ₽3,600 ₽
1610%3,375 ₽3,375 ₽
1710%3,177 ₽3,168 ₽
1810%3,000 ₽3,000 ₽
1910%2,843 ₽2,826 ₽
2010%2,700 ₽2,700 ₽
2110%2,572 ₽2,560 ₽
2210%2,455 ₽2,445 ₽
2310%2,348 ₽2,344 ₽
2410%2,250 ₽2,250 ₽
265%2,193 ₽2,175 ₽
275%2,112 ₽2,088 ₽
285%2,036 ₽2,028 ₽
295%1,966 ₽1,952 ₽
305%1,900 ₽1,900 ₽
315%1,839 ₽1,830 ₽
325%1,782 ₽1,758 ₽
335%1,728 ₽1,704 ₽
345%1,677 ₽1,659 ₽
355%1,629 ₽1,614 ₽
365%1,584 ₽1,560 ₽
Fig. 2
What each login code costs the debtor’s legal allowance230-FZ, Russia’s debt-collection law: article 7 caps the messages a debtor receives, article 8 lets them refuse contact

The login’s statutory cost, in messages

24 hours0/2
7 days0/4
30 days0/16

No code requested yet.

Calls are a separate channel with separate caps — 1 a day, 2 a week, 8 a month — and the login path is forbidden by a build gate from importing them.

Simulated clock
day 1, 09:00
Interaction
allowed

Request a code, move the simulated clock, and request again: the meters show what each code spends

The login is an electronic message, so every code the debtor asks for can spend part of a legal allowance of 2 a day, 4 a week and 16 a month. The portal counts rolling windows, one contact per verification episode, and checks a refusal of interaction before any cap.
Messages a debtor may receive, by rolling window (230-FZ art. 7)
WindowMessages allowed
24 hours2
7 days4
30 days16

The product

People in debt avoid the phone call, so the product is the opposite of one: look the debt up, see what a settlement would cost and over what schedule, and reach an SBP payment screen whose amount the server recomputes — without speaking to anyone. I am the only developer, building it end to end for a licensed collection organisation: the debtor flow, the arithmetic, the statutory limits, the disclosures, and the build gates that keep them true.

What the law set

Two federal laws decided the architecture before any product decision did. 152-FZ keeps personal data in the country, which ruled out foreign hosting, foreign font CDNs and foreign analytics: the portal runs in a Russian cloud region with self-hosted Cyrillic typography, and zero third-party origins is a build gate rather than a policy.

230-FZ caps creditor-initiated contact, and a login code is an electronic message. Whether a code the debtor asked for counts is not settled, so the code names the question, documents all three readings, and ships the conservative one — one contact per verification episode — with the reason written as an asymmetry: if counsel says it does not count, a constant flips; had it shipped permissive, the state machine would need rewriting. The abuse throttle runs before the statutory counter, so an attacker cannot spend a real debtor’s allowance for them.

Money you can audit

Every amount is integer kopecks and every discount integer basis points; a float never touches money. The discount is floored, recurring payments round up to a whole rouble and the final payment absorbs the remainder, a single payment is exact to the kopeck, and the offered terms are pruned so that no longer term ever costs more a month than a shorter one. The payment step recomputes the amount on the server from the chosen term and the debtor’s own obligation; it never accepts an amount from the browser, and no debt data ever travels in a URL.

Compliance enforced at build time

Because calls and messages have different ceilings, importing the wrong set at a send site is a compliance bug no happy-path test would catch. The telephone caps live in their own module, and a static check forbids the login path from importing them — matching static imports, dynamic imports and require calls alike. A display component that publishes both caps on the rights page is banned only from the route that actually sends and counts.

Standards are build gates rather than intentions: types, lint, contrast computed from the design tokens, origin compliance, a JavaScript size ratchet, and accessibility 100 as a hard failure. The layout-shift gate is 0.05 and the measured value is 0 on every audited route; the suite declares 226 unit tests and runs 146 end-to-end cases.

The gates are held to the same standard as the product: a boolean audit takes the worst of its runs, never the median, and a server is ready when it answers a request, not when it prints a log line — an assertion measured against an environment no real visitor uses is not a guard.


role
sole developer and project lead
status
in active development
client
a licensed collection organisation; not named here
stack
Next.js 16 · React 19 · Turbopack · Tailwind 4 · Yandex Cloud