CARTIQO is an independent software product studio based in Denmark. We build and run our own products, starting with Pineapple, our Discord bot, and we build websites and custom Discord bots for other businesses — shown working in full before anyone pays.
Not connected to Cartiqo, the Dutch vector map product by Webmapper. Same name, different field.
Self funded and small on purpose. Two halves:
- We build and run our own software. Starting with Pineapple, the one bot a Discord server actually needs.
- We build websites for other people. You see the real site working, in full, before you pay for it.
Whoever designs a thing builds it, so nothing gets lost in a handover. Launch day is the start of the work, not the end of it.
| The numbers | |
|---|---|
| 14 | modules in Pineapple, on one subscription |
| 3 | slash commands in the picker, none of them for setup |
| $0 | what a client pays before seeing their finished site |
| 2026 | independent since |
| Project | What it is | Status |
|---|---|---|
| Pineapple | Verification, tickets, moderation, applications, levels, giveaways and eight more, sharing one theme, one log and one set of permissions. Every module is set up on a dashboard with a live preview, so the message you approve is the message it posts. | Building |
| CARTIQO Lists | A directory for Discord bots and communities. Listings, voting and a public API. | Early |
| CARTIQO Tools | Free browser tools for people who run communities, including a cover and icon studio that exports PNG and SVG. | Building |
| Walu_Cutzz | A booking site for a barbershop in Kolding. Clients pick the cut and a time, no phone call, no DM. | Live |
Pineapple's rule, and the reason it is not another bot with forty commands: commands are for acting, the dashboard is for deciding. Three commands in the picker, none of them for setup, and anything you configure you see previewed before it posts.
More detail on all of it at cartiqo.xyz/projects.
The repositories we keep public. Most of our product code is private while it is being built, and moves out here when it is worth someone else's time.
| Repository | What it does |
|---|---|
| discord-transcript | Self contained HTML transcripts of Discord channels, rendered with Discord's own message components. TypeScript. |
| CTQCore | FiveM core resource: connect queue and configuration, built on CTQBridge. Lua. |
| CTQBridge | Connects a FiveM server to the CARTIQO dashboard. QBCore, Qbox, ESX and standalone. Lua. |
| CTQui | A modern NUI kit for FiveM: notifications, text UI, progress bars. JavaScript. |
The three FiveM resources are early and untested. They are published so the work is readable, not because they are ready for a production server. We say so on each one rather than letting you find out.
Everything else we have opened up is in the repository list.
Notes from our own codebase: a real defect or a real decision, with the code that shipped. Listed by the question each one answers.
Security
| Answers | Piece |
|---|---|
| Should a rate limiter run before or after request validation? | Rate limit before you read the body, not after |
| Why does my Stripe webhook signature verification always fail? | Parsing the JSON is what breaks the webhook signature |
| Is it safe to build a Stripe success_url from the Origin header? | Your checkout return URL is an open redirect unless you pin the origin |
| How do I check whether an API key was ever committed to git? | The env file your .gitignore does not protect is the one that leaks |
Engineering
| Answers | Piece |
|---|---|
| Can I fulfil an order on the Stripe success page instead of a webhook? | The success page is not a receipt, and treating it as one loses money |
| Why does every page on my Next.js site have the same og:title? | Every page on your Next.js site may be sharing one Open Graph description |
| Why is my CSS class not applying even though the selector matches? | Your CSS reset outranks your components, and nothing will error |
Accessibility
| Answers | Piece |
|---|---|
| Do I need keyboard handling if I add an ARIA role? | An ARIA role is a promise, and a broken one is worse than none |
How we work
| Answers | Piece |
|---|---|
| How does CARTIQO work, and what do I pay before seeing anything? | We build the site before we invoice for it |
All of it at cartiqo.xyz/blog.
| Step | |
|---|---|
| 01 Define | Get clear on the problem and who it is for before anything gets drawn. Small scope, high standard. |
| 02 Design | Draw the real screens, not a rough sketch. What you approve is what gets built. |
| 03 Build | Built properly and checked over, in pieces that fit together, so it can change later without breaking. |
| 04 Ship and run | Release it, watch how it behaves, keep improving it. |
For commissioned work the deal is simple: you brief us, we accept or decline, and if we take it on you see a real preview of your site before any money moves. Like it and you pay and it is yours. Do not, and you owe nothing. The quote is fixed before the preview, so there is no moving number. Start at cartiqo.xyz/commission.
Everything ships on one stack so the studio only has to be excellent at a small number of things.
| Layer | What we use |
|---|---|
| Language | TypeScript everywhere, Lua for FiveM |
| Web | Next.js 15, React 19, Tailwind CSS |
| Design system | One shared component library and token file per project, vendored rather than linked |
| Data | Prisma, MySQL |
| Discord | discord.js, Sapphire |
| Tooling | pnpm, Turborepo, ESLint, Prettier, GitHub Actions |
House rules live in CONTRIBUTING.md: conventional commits with a subject that stands alone in a file list, one commit per module, tokens edited instead of components.
Anything claiming to be CARTIQO that is not on this list is not us.
| Where | Handle |
|---|---|
| Web | cartiqo.xyz, cartiqo.app |
| GitHub | @CartiqoFramework |
| Discord | CɅRTIQO. Support |
| @cartiqo.xyz | |
| CARTIQO |
We never ask for passwords, tokens or payment in a DM. If someone using our name does, report it to hello@cartiqo.xyz or open an impersonation report.
Work, questions, security reports and everything else: hello@cartiqo.xyz.
Security issues have their own route, please read SECURITY.md first.
Released under the MIT License unless a repository says otherwise. Copyright CARTIQO.