Success story · B2B SaaS, inbound leads
LeadPendingTwo people shipped a lead inbox in 24 hours: leads get a reply in 10 minutes, not the market's 40+ hours
LeadPending collects the leads from every website into one inbox, alerts the owner in Telegram, drafts each reply in the lead's language and shows how a shared proposal gets read. A lead gets its reply in 10 minutes, where the market average is more than 40 hours, over 90% are answered within the first hour, and 12,000 leads have gone through it so far. I designed the architecture, the security and the handling of personal data, and the whole team is two people. It went live a day after the first commit, with the security gates and test coverage most teams reach only after months of work.
- Client
- LeadPending
- Product
- Lead inbox, AI replies, tracked documents
- Leads processed
- 12,000
- My role
- Fractional CTO
- Team
- 2 people
- Interface
- English and Russian
- Website
- leadpending.com

In numbers
- to answer a lead, where the market average is 40+ hours
- 10 min
- from the first commit to production, where weeks are the norm
- 24 h
- of leads answered within the first hour
- 90%+
- leads processed, each one landed exactly once
- 12,000
- live sites moved their forms from Telegram to LeadPending in 9 days
- 13
- automated tests, so two people release without a QA department
- 2,100+
The product
One inbox for every site, a reply drafted from one line, the Telegram alert and the reading report for a shared proposal. The screens are from leadpending.com and show demo data.
The starting point
The sites' contact forms dropped every lead straight into a Telegram chat. Nobody could see who was still waiting for an answer, and replying meant copying text between Telegram, an AI chat and the mail client. A proposal sent as a PDF link never said whether anyone had read it.
LeadPending had to replace all of that with one queue for every site, a written reply within ten minutes, and nothing sent until a person approves it. It stores the names, emails, phone numbers and reading activity of people who are not its customers, so security and personal data were in the design from the first version of the spec.
What we did
One Go service, with nothing extra to run or pay for
I designed one Go service for the API, mail, Telegram and document tracking, two React apps (the customer's cabinet and the admin panel), a Next.js website, a separate document viewer and PostgreSQL. There is no Redis and no message broker, because retries and idempotency live in the database. The project started from my own scaffold, so accounts, organizations, passkeys and the admin panel worked on day one. Fewer parts means less to host, monitor and pay for.
12,000 leads, each landed exactly once, none lost and none doubled
A site sends a lead with one call from its server or through the npm package leadpending-web. Repeating the call with the same key returns the first lead, so a retried form never creates a duplicate. The package also passes the visitor's path, UTM tags and device, and the server scores each lead for spam and still keeps it.
A reply in 10 minutes from the phone, where the market takes 40+ hours
Each new lead arrives in the owner's Telegram with the full contact and message. The owner answers in one line, by voice or text, and the model drafts the reply in the lead's language with the site's signature. A lead gets its answer in 10 minutes, where the market average is more than 40 hours, and over 90% of leads are answered within the first hour. A person presses Send on every reply, and the lead's own text reaches the model as content, never as an instruction.
Proposals that report who read them, shipped in two days
Documents shares a PDF by a personal or public link, or embedded on the customer's site, and shows who opened it, from where, on what device and how long each page was read. Link previews, mail scanners, cloud networks and headless browsers count as robots, and the owner's own views are left out. The feature went from approved spec to production in two days.
Personal data with hard limits from the first spec
Every row belongs to one organization, and every query checks it. The document viewer sets no cookies and loads nothing from third parties, and raw viewing events are kept for 180 days. Deleting a site or an account opens a 30-day recovery window before hard deletion, and a connected site can erase a lead by its own ID through the API. Lead content is not used to train models, and the privacy policy names every provider that receives data.
Security checked on every release, with no security team
More than 2,100 automated tests guard the code, the server's against a real PostgreSQL. API keys and invite tokens are stored only as hashes, sessions are random tokens kept in the database, and the admin panel needs a passkey and signs every request. Every release passes secret scanning over the whole git history and the Go and npm vulnerability gates; images carry an SBOM and provenance, containers run as a non-root user, and a release that fails its checks in production rolls itself back. That is the release discipline of a much larger company, kept by two people.
Live in 24 hours, 13 sites in nine days
The product was running in production the day after the first commit, a pace most in-house teams never reach. Nine days after that commit, 13 live websites had moved their contact forms from Telegram to LeadPending, each with its own API key, and a real submission was checked end to end. This site, oleg.is, sends its contact form and my proposals through LeadPending too.
The result
Two people had LeadPending in production a day after the first commit, and eight days later it was handling the contact forms of 13 websites. It has processed 12,000 leads since: a lead gets its reply in 10 minutes, where the market average is 40+ hours, and over 90% are answered within the first hour, with no ops, QA or security staff behind it.
| The result | Before | After |
|---|---|---|
| Reply to a lead | Market average: 40+ hours | 10 minutes, 90%+ within the first hour |
| Leads from the sites | Straight into a Telegram chat | One queue, with a clock on every lead |
| A reply | Typed by hand, copied between chat, AI and mail | Drafted from one line, in the lead's language |
| A proposal | A PDF link, with no sign it was read | Opens, pages and reading time, robots left out |
Stack
- Go
- PostgreSQL
- React
- Next.js
- pdf.js
- OpenAI
- AWS SES
- Telegram Bot API
- Docker
- GitLab CI
- Sentry
- Cloudflare
Full case · PDF
LeadPending
Two people shipped a lead inbox in 24 hours: leads get a reply in 10 minutes, not the market's 40+ hours
- 01The architecture: one Go service, three web apps and the document viewer
- 02Personal data: what is stored, for how long, and how it is deleted
- 03How a lead is received exactly once: API keys, idempotency, spam scoring
- 04The reply path: Telegram, voice, the draft and the human Send
- 05Documents: telling people from robots in reading analytics
- 06The release pipeline: security gates, production checks and automatic rollback
The full LeadPending case
The public story stops here. The PDF has the rest: the architecture before and after, the migration plan, how the team works with AI agents, what it all costs to run and where the savings came from.
More stories
All storiesWant the next story to be about your company?
In a 30-minute call we pick the first task to hand to AI and estimate what it will save you.



