Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

SnackBase

Open-source, GxP-compliant back end for Python teams

Details

External ID
46600092
Source
HN
Company
—
Product
SnackBase
Website domain
snackbase.dev
Launched
Jan. 13, 2026
Cohort
—
Upvotes
70
Upvotes percentile
0.8517786561264822
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Hi HN, I’m the creator of SnackBase.I built this because I work in Healthcare and Life Sciences domain and was tired of spending months building the same "compliant" infrastructure (Audit Logs, Row-Level Security, PII Masking, Auth) before writing any actual product code.The Problem: Existing BaaS tools (Supabase, Appwrite) are amazing, but they are hard to validate for GxP (FDA regulations) and often force you into a JS/Go ecosystem. I wanted something native to the Python tools I already use.The Solution: SnackBase is a self-hosted Python (FastAPI + SQLAlchemy) backend that includes:Compliance Core: Immutable audit logs with blockchain-style hashing (prev_hash) for integrity.Native Python Hooks: You can write business logic in pure Python (no webhooks or JS runtimes required).Clean Architecture: Strict separation of layers. No business logic in the API routes.The Stack:Python 3.12 + FastAPISQLAlchemy 2.0 (Async)React 19 (Admin UI)Links:Live Demo: https://demo.snackbase.devRepo: https://github.com/lalitgehani/snackbaseThe demo resets every hour. I’d love feedback on the DSL implementation or the audit logging approach.

Enrichment

Theme
database infrastructure and developer tools
Vertical
Horizontal
Function
Data infrastructure
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
gxp-compliant backend for python
Manually corrected
False

Could you build this?

Partial The BaaS backend and Postgres wrappers are easy to vibe-code, but true GxP compliance requires specialized regulatory validation, 21 CFR Part 11 electronic signature rules, and formal audit standards.

What it would actually take: Built on Python (FastAPI), PostgreSQL with Row-Level Security, and cryptographic audit log chains. The difficult component is meeting strict FDA 21 CFR Part 11 requirements, including immutable append-only logs, verified digital signatures, time-drift controls, and producing automated GAMP 5 qualification validation packages.

Discussion

14 comments analyzed.

Competitors mentioned: Keybase (audit log approaches), Supabase, PocketBase, Django, Rails

Concerns raised: AGPL license may restrict commercial self-hosting use, Custom hooks/schemas licensing ambiguity with in-process execution, Database performance impact of immutable hash-chain audit logs, Custom DSL maintenance burden (700+ lines of lexer/parser/evaluator), Postgres support still experimental, not production-ready

Feature requests: Explicit linking exception to exempt user-defined hooks from AGPL, Postgres as first-class default instead of SQLite in quick start, Native read/write splitting for database scaling architectures, Clearer upfront documentation on database support status

Competitors

Other products that read as similar to this one — 20 launches clear the similarity bar, closest 8 shown.

Attention rank: #4 of 21 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 75 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a data infrastructure tool for Media & entertainment yet.