
QuantiMeet
Flat-price team scheduling
Cal.com went closed-source earlier this year. The community kept the last MIT version alive as Cal.diy, which is a single-tenant engine: one install, one team. We are building QuantiMeet on it as a hosted service where every team gets its own database and subdomain. Beta Day is tomorrow, September 22. Here is what broke on the way.
Multi-tenancy is only real when the negative tests can fail.
The engine resolves the tenant from the Host header on every request. The first proof script only checked that the right tenant loaded. The version that mattered checked that a forged Host header, an unknown host, and a cookie from another tenant all got refused. Two of those failed the first time. If a proof cannot fail, it is not a proof.Build-time URLs are baked into the bundle.
The engine reads its public URL at build time and writes it as a literal into about 118 files. You cannot swap that per request with a proxy. We ended up resolving the tenant in a custom server and passing the tenant through a signed value in the OAuth state so calendar callbacks land on one fixed host and hand off to the right subdomain.Do not write the policy before the measurement.
Our Privacy Policy said calendar tokens were encrypted at rest per team. When we finally checked, they were encrypted with one engine-wide key, not per team. We built per-tenant encryption to make the sentence true, with a script that reads the raw row and fails if it can see plaintext. The legal page now has a proof behind it. It should have started that way.The job queue does not drain itself.
Reminder and webhook jobs sat in the queue forever because nothing called the cron endpoint. A five-minute timer fixed it. Every self-hosted engine has one of these; find it before your first customer does.Send yourself the emails from a real tenant.
Booking confirmations went out fine. The organiser copy bounced for four days because the organiser address on our test tenant was not a mailbox, and the bounce notices bounced too. Nothing in the app showed it. The fix was five minutes; noticing it took four days.
Pricing is one number: $10 a month for the whole team, no seat count. We publish a Fair Pricing Pledge that says what we will and will not do with that price. The first 25 beta teams are free until six months after launch. We are not affiliated with Cal.com, Inc.
The questions we most want are the ones about what would make you not trust it.
Simon, founder, QuantiMeet
About
Scheduling tools charge per seat, so a team of ten pays ten times for the same product. QuantiMeet is $10 a month for the whole team, built on the MIT Cal.diy engine after Cal.com went closed-source.

1 Comment