Key Takeaways
- Ran the company's entire web presence, eight WordPress installs and a Laravel application, on one development, security and deployment cadence for five years.
- Built track.cred.ai, a server-side conversion gateway the company owns outright: events queued through Redis to Meta, TikTok, Google Ads and X, with no vendor tag manager and no per-event billing.
- Modeled the real funnel, enrollment through card activation and funding, matched across browser and app on the company's own customer identifier, so a click can be attributed to an account that funds weeks later.
- Fed the apps from a headless content API, with per-partner endpoints so new white-label programs are configured, not coded.
- Deployed Consent Mode v2 and a brand-matched open-source consent banner across every property at zero licensing cost.
- Kept a fintech security posture current, with hardening shipped as must-use plugins and the company enrolled in CISA's free vulnerability scanning program on my recommendation.
Organization
Cred.ai, legally CRED Technologies, is a Philadelphia fintech running a consumer banking app and the Unicorn Card, a credit card built around automated credit optimization rather than interest revenue. It also runs Cred.ai Pro and the SIREN white-label card program for partner organizations including Starbucks partners, Valor VIP, Lids and Power Home Remodeling Group.
Challenge
Cred.ai spends real money on paid acquisition, but the conversion, a funded account, happens inside an application on a different domain and often finishes inside a mobile app weeks later. Browser-side tracking cannot cover that journey, and a regulated financial brand needs its marketing stack, content delivery and security posture held to the same standard as its product.
Solution
- A purpose-built Laravel event gateway receiving events from the marketing site, the onboarding application and the mobile backend, and delivering them server-side to four ad platforms.
- A complete funnel taxonomy from enrollment start to account funding, deduplicated and matched on a per-customer identifier.
- A headless content API with per-product endpoints and CMS-managed placement, powering content inside the iOS and Android apps.
- Consent Mode v2, consent-gated tags, server-side opt-out forwarding and matching Firebase SDK configuration across web and mobile.
- Security work shipped where it survives updates, with verification steps the client's security team could run themselves.
- Search and content work driven by data: a reviews page fed by live app-store reviews, an FAQ built from real query data, and machine-readable feeds for AI search.
Results
- Customer acquisition cost down roughly 30% as platforms optimized on funded accounts rather than pageviews.
- 220,000+ enrollment funnel starts tracked end to end.
- A measured 25-day average gap between enrollment and card activation covered by server-side attribution.
- 99/100 Ahrefs site health held over years; organic and AI search visibility up roughly 35%.
- Under one hour of unplanned downtime a year across nine properties.