The brief
Norton (Gen Digital), working with AEON Marketing, runs promotions with a wide range of retail and technology partners. Each one needed its own claims site, with its own branding, offer terms and claim window, and every new promotion meant briefing, designing and building a bespoke site from scratch. That model was slow, costly and increasingly unsustainable.
The stakes were higher than a typical claims portal. The platform collects personal information, 25-digit product keys and payment details on behalf of a global cybersecurity brand, so any architectural weak point would be a direct threat to Norton’s reputation.
The goal: one secure platform Norton could use to launch new partner offers quickly and independently, across several regions, without becoming several products.

The approach
Security was treated as a first-order design input, not a late-stage checklist. Before a single page was built, we mapped every point where data is collected, stored and transferred, and assessed the architecture against Australian cyber security standards to design out weak points.
The platform is one reusable base, a Next.js (SSG) front end on a NestJS and PostgreSQL back end, deployed to Google Cloud. Region, language, partner branding, claim windows and offer terms are handled as configuration rather than forks, so every new campaign site inherits the same security posture by default.
Claim, eligibility and payment workflows are modelled explicitly, so each step has an owner, a state and a defined failure path. The contract between front end and API was agreed before screens were built, which kept delivery fast across the team.





What I did
- Developed the cashback promotion platform in Next.js (SSG) with a reusable architecture supporting multi-region and multi-campaign deployments from a single codebase
- Built scalable NestJS services on PostgreSQL and Prisma, implementing secure cashback claim, eligibility verification and payment processing workflows
- Designed a configurable campaign management architecture, so region-specific promotional sites go live with minimal code changes
- Engineered security-focused workflows: robust input validation, authentication and authorisation controls, secure API design, data protection and defences against common web application vulnerabilities
- Set up cloud deployment and release practice on Google Cloud with Docker, GitHub Actions and CI/CD
Tech stack
Front end
Back end and data
Cloud and delivery
Case study
Norton: a secure, self-serve claims platform. Delivered with AEON Marketing for Norton (Gen Digital).
We delivered a complete, production-ready platform ecosystem:
- A secure, reusable base platform architected to Australian cyber security requirements, with encryption in transit and at rest, secure form handling and hardened infrastructure
- A self-serve model that lets Norton launch new partner redemption campaigns without commissioning a bespoke build each time
- A streamlined claims journey covering product key validation, claim submission and status handling, terms and conditions, FAQs and a dedicated help pathway
- Rigorous quality assurance and security testing before go-live, plus documentation and handover so Norton’s team can configure and launch future campaign sites independently
Every new campaign site now inherits the same secure foundation, which gives Norton the confidence to move fast without compromising the trust its brand is built on.
The result
- Secure by default Every campaign inherits it
- Faster launches New offers go live quickly
- Reusable asset Not a recurring build cost
- Simpler claims Submission through to payment