Case Study — Practical Life Visitations
A corrupted PDF, a false assumption about what "verified" means, and everything else caught building the same site.
Practical Life Visitations is a virtual-only, court-approved supervised visitation service, built for families who can't be in the same room due to distance, incarceration, or a court order. The site serves two capability-statement PDFs, one California-specific, one a "national" version for private and voluntary out-of-state accounts, the document a county case worker, procurement contact, or referring agency opens to decide whether to place a referral or add the service as a vendor.
The live, deployed PDF
Capability Statement — National
Practical Life Visitations provides virtual supervised visitation services for private and voluntary accounts nationwide.
Minnesota (Operating Nationwide)
Contact: To start NGS LLC
What was actually happening on push
The national PDF rendered corrupted on the live, deployed site: a stray floating line reading "Minnesota (Operating Nationwide)" sat in the wrong place, and the real business contact information was replaced with garbled text. This PDF is what a procurement officer or agency contact opens to decide whether to place a case. A garbled document at that exact decision point reads as illegitimate.
The PDF's binary content was embedded in a Cloudflare Function as one large base64 string literal. That giant string was getting silently corrupted somewhere in the push-and-deploy path, even though the local copy parsed fine before pushing. Two rounds of "fixed it," based on local verification, still shipped the same bug, because the local copy and the live, served file weren't actually the same content.
The corrected PDF
Capability Statement — National
Practical Life Visitations provides virtual supervised visitation services for private and voluntary accounts nationwide.
✓ Contact and service details render correctly
What changed
Disabled PDF stream compression at generation time so the underlying stream is simpler and more resilient. Split the base64 payload from one giant string into an array of small chunks joined at request time, since smaller pieces are less likely to be mangled in transit. Added a verification step: after every push, re-fetch and decode the actual live content from GitHub, not the local working copy, and run it through a PDF parser to confirm it parses correctly and contains the right text, before calling the fix done.
This changed what "done" means. Not "it works on my machine," but "I confirmed the exact file a stranger would actually receive."
When you're a solo practitioner, there's no receptionist, no shared team inbox, no separate ops person logging referrals. A county case worker or agency contact deciding whether to place a case with you is implicitly asking whether this organization has its act together, or whether they'd be handing a case to one person's personal email. The admin-side setup, a dedicated business email that sends automated case correspondence and routes replies somewhere actually checked, a referral form that captures structured information instead of "just email me," PDFs served on request instead of attached ad hoc, makes the process feel institutional and repeatable, even though it's running behind one person. This isn't about deceiving anyone. It's about the intake experience not signaling "solo operation, hope she checks her phone."
Two different kinds of visitors hit a "sign up" moment on the site, carrying different amounts of real information and real intent. Someone curious about the not-yet-live parenting-coaching offering is just raising their hand, no case file, no referral number, no documents, and asking for more than an email would lose them for nothing, since there's nothing to act on yet anyway. A case worker or agency contact submitting an actual referral almost always has something in hand, a referral order, case details, sometimes a document, and a single email field would under-collect what's needed to act on it, leading to chasing them by reply-email regardless. The two forms aren't the same form styled differently, they're sized to how much the visitor actually has to give at that moment.
A draft bullet for the national capability statement cited FAR 2.101 to claim federal micro-purchase readiness. FAR governs federal purchases, not state or county ones, and the underlying claim was false anyway, there was no SAM.gov registration and no non-California credentials. Removed the bullet entirely and replaced it with an accurate three-way split: California court placements, private and voluntary accounts nationwide, and a disclaimer for court-mandated cases outside California.
Clicking a footer link (Confidentiality, Resources) loaded the new page at the previous page's scroll position instead of the top. Fixed with a component that resets scroll on every route change.
Icon and card styling had drifted across the site, some pale-pink-tinted, some plain white boxes, with no consistent reference point. Picked one existing card as the standard and brought every card, icon, and CTA box on the site in line with it, including redesigning flat-dark CTA boxes to use a photo background with a dark overlay, matching the one CTA section that already looked right.
An email to a county agency bounced. The domain listed in a public directory had no DNS records at all. Confirmed the correct live domain against the county's own official vendor page before re-sending.