Freelance Software Engineers in SindhFreelance Software Engineers in Sindh
Full-Stack Engineer for SaaS & Business Systems
5.0
Rating
15
Followers
Full-Stack Engineer for SaaS & Business Systems
Production-ready AI agents and SaaS built to scale reliably.
$25k+
Earned
2x
Hired
108
Followers
Production-ready AI agents and SaaS built to scale reliably.
Cover image for From Instinct to Infrastructure: How
From Instinct to Infrastructure: How Athliq Went From Trainer's Notebook to Production Performance Platform ────────────────────────────────────────── The Person Who Understood the Problem Before Anyone Else Did Marcus had been a strength and conditioning coach for eleven years. He'd worked with professional football squads, Olympic track athletes, and NCAA programs. He knew exactly what was wrong with how performance data was managed, not because someone told him, but because he'd lived inside the problem every day. Every morning, he'd open four browser tabs, a spreadsheet, and a WhatsApp thread just to answer one question: Is this athlete safe to train today? HRV from one app. Sleep data from another. Yesterday's load from a Google Sheet. Wellness check-ins in a form nobody filled out consistently. Injury notes in a physio's personal folder. The picture was always incomplete, not because the data didn't exist, but because no system was designed to assemble it. He wasn't guessing the problem. He was the problem's daily victim. So he built something. ────────────────────────────────────────── The First Version Had Real Value What Marcus and a developer friend put together in six weeks was genuinely useful. A React frontend. Static JSON files simulating the data feeds he wished he had. A morning readiness dashboard showing each athlete's status: green, amber, red. ACWR calculations. A training plan view. A return-to-play protocol tracker. It looked like a real platform. It felt like one. When he demoed it to his performance director, the response was immediate: "This is what we've been trying to build for two years." The prototype surfaced something important. The problem wasn't that nobody had the data. The problem was nobody had designed the right lens to look at it through. Marcus had. His system organized information around the questions coaches actually ask, not the questions software vendors assume they ask. The initial build worked. For one squad. In static conditions. With fake data. And that was exactly the point where it started to matter, and exactly the point where its limitations became unavoidable. ────────────────────────────────────────── What Started Breaking The prototype had no backend. Data was hardcoded. Every "insight" was pre-written. The readiness scores didn't calculate; they were authored. When a second sport scientist saw the demo and said, "Can we plug in our GPS data?" there was no honest answer that didn't involve a complete rebuild. More specifically: The data layer was decorative. The JSON files looked real but required manual authoring for every scenario. There was no pipeline, no ingestion, no validation. Any live deployment would mean the dashboard showed stale or fabricated numbers, which in a performance context is worse than showing nothing at all. The AI insights were static strings. Every "AI-generated" recommendation was hardcoded text. In the prototype, this was fine. It demonstrated the concept. In production, it would mean the same insight appearing for every athlete regardless of their actual state, silently eroding clinician trust. The system had no concept of time. Training load calculations, ACWR ratios, wellness trends, all of these are temporal by definition. The prototype rendered them as snapshots. A real system needed rolling windows, historical comparison, and the ability to detect change over time. There was no role isolation. The role switcher in the UI was cosmetic. A physio and a performance director seeing the same underlying data with a CSS class change was not access control, it was theater. Nothing would survive a real integration. Real wearables return messy, incomplete, delayed data. The system had no error handling, no retry logic, no fallback states. The first real data feed would have broken the UI in ways that were invisible until they were catastrophic. The system was not wrong. It was early. ────────────────────────────────────────── Why They Didn't Just Fix It Themselves Marcus understood sport science. His developer understood React. Neither of them had built a production data system before, and that gap is not a skills deficiency, it is a domain specialization. What they needed was not someone to rewrite their frontend. The frontend was actually good. The visual hierarchy was sharp, the domain terminology was accurate, the workflows reflected how coaches genuinely think. That institutional knowledge was irreplaceable and not to be discarded. What they needed was: • A real-time data layer that could ingest from multiple sources reliably • A calculation engine that could run ACWR, load zone distributions, and readiness scoring against live data • A structured API contract between the front and back end • Authentication and role-based data scoping that actually enforced access boundaries • Observability, so when something silently broke, someone would know The prototype had proven the concept. The job now was to make the concept dependable. ────────────────────────────────────────── What We Actually Did We kept the frontend. Almost entirely. The visual design, the component architecture, the domain-accurate terminology, all of it stayed. We refactored the data layer, not the UI layer. The prototype's greatest strength was its UX fidelity to how coaches actually work, and we had no interest in rebuilding that from scratch. We built a real data ingestion pipeline. Rather than static JSON, we designed a service layer that could ingest from GPS units, HRV monitors, and wellness form submissions. Each source had its own adapter with validation, normalization, and error handling. Partial data was acceptable; silently wrong data was not. We replaced static calculations with a live computation engine. ACWR calculations now ran against a rolling 28-day window of actual load data. Readiness scoring pulled from real HRV baselines, not fixed numbers, and recalibrated as an athlete's personal baseline shifted over a training block. We replaced pre-written AI insights with a rules-based inference layer. Every insight shown in the platform now corresponded to a condition that was evaluated against live data. If Lena Vasquez's ACWR crossed 1.3 and her HRV dropped more than 15% from her 7-day baseline, the injury risk flag was triggered, not because it was hardcoded, but because those conditions were true. We implemented real role-based access control. A physio sees medical data, injury history, and RTP protocols. A sport scientist sees load analytics and benchmarks. A performance director sees the squad-level overview. A head coach sees readiness and today's session. The frontend already had role-switching built in, we gave it actual enforcement. We added observability throughout. Every data ingestion event was logged. Every calculation that produced an out-of-range result generated an alert. If a data source stopped sending, the system surfaced a staleness warning rather than silently displaying old numbers as current. ────────────────────────────────────────── Tech Stack React 19 + Vite, Tailwind CSS v3, Recharts, React Router v7, Node.js + Fastify, PostgreSQL + TimescaleDB, Redis, GPS/HRV/sleep data adapters (Catapult, Polar, Garmin), Google Forms/Typeform ingestion, Auth0, row-level security, Sentry, Datadog, Railway/Render, Vercel, Supabase Storage What Changed The morning workflow Marcus had been running across four tabs and a spreadsheet now ran in a single view that was populated automatically before he arrived at the training ground. The difference wasn't just convenience. It was confidence. When the dashboard flagged an athlete as high-risk, the coaching staff could interrogate why and trust the answer. When a return-to-play progression showed 80% completion, that number reflected actual criteria met against measured data, not a manually updated percentage. The platform was no longer a demo tool. It was a clinical decision-support system. For the squads using it, the shift was measurable: fewer reactive injury responses, more consistent load monitoring, and perhaps most importantly, a shared language between coaching staff, physios, and sport scientists built around the same data rather than competing interpretations of separate sources. ────────────────────────────────────────── The Part That Rarely Gets Said Most platforms built in this space start from the software side. Someone builds a data collection tool, adds a dashboard, and then tries to reverse-engineer what coaches actually care about. Athliq started from the other direction. A domain expert who understood the problem at a professional level built the frame first, and built it correctly. The pain points were real, the workflows were accurate, the terminology was precise. The engineering work didn't fix a bad idea. It made a good idea survivable. That distinction matters more than most technical case studies acknowledge. The hardest part of building a platform like this is not the infrastructure. It's knowing which questions to answer. That knowledge was already there. Our job was to make sure the system could keep answering them reliably, at scale, over time. ────────────────────────────────────────── Athliq is now in active deployment across two professional squads and one university performance program. The morning readiness dashboard processes real-time data from four integrated sources and serves role-scoped views to performance directors, sport scientists, physiotherapists, and athletes.
1
3
2K
Cover image for Case Study: From Prototype to
Case Study: From Prototype to Production — Building a Credit Management Platform for Ad Operations The Starting Point The founder wasn't guessing the problem. They had spent years inside the ad-credit ecosystem, managing wallet balances across regions, reconciling top-ups via bank wire and stablecoin, chasing compliance documents, and watching campaigns stall because a pixel stopped firing at 2am. They knew exactly what a credit management platform needed to look like. So they built one. Using Figma wireframes translated directly into a React frontend, they shipped a working prototype in days. Two portals were created. One for clients managing wallets and ad accounts, and one for internal operators handling treasury, compliance, and risk. It included real-time spend charts, AI-driven anomaly detection banners, a work queue for ops teams, and an embedded AI assistant that could answer questions about balances, compliance status, and pixel health. The prototype proved the concept. Clients could see their wallet balances, request top-ups, allocate funds to ad accounts, and track campaign performance. Admins could manage treasury operations, review KYB pipelines, monitor risk scores, and process a prioritized work queue. The domain logic was sound. The UX was sharp. But the system was never designed to survive real load. What Started Breaking The prototype worked on mock data. Every API call returned hardcoded arrays after a random delay. There was no backend. No database. No real authentication. The login screen accepted any email and assigned a role based on a toggle switch. Session state lived in localStorage as a raw JSON blob. This was fine for demos. It stopped being fine the moment real money entered the picture. The specific fractures: 1. No transactional integrity. Wallet balances, top-ups, fund transfers, and ad account allocations were all simulated. In a live system, a transfer of $25,000 from a master wallet to a regional sub-wallet is not a UI state change. It is a financial transaction that requires atomicity, audit trails, and rollback capability. The prototype had none of this. 2. Compliance was cosmetic. KYB document statuses were static labels. In production, document verification involves third-party identity providers, expiration tracking, automated re-upload reminders, and regulatory audit logs. The prototype rendered badges like "Verified", "Pending", and "Missing", but nothing enforced the state machine behind them. 3. Risk scoring was decorative. The AI risk badges showed tooltips like "Large P2P transfer detected, document expiring", but these were string literals, not outputs from a scoring model. Real risk assessment requires transaction pattern analysis, velocity checks, cross-referencing compliance status, and escalation workflows that route to the right ops agent. 4. The work queue had no backend. Urgent items like "$45,000 P2P transfer anomaly" appeared in the queue, but resolving them was just a frontend state toggle. There was no case history, no assignment logic, no SLA tracking, and no integration with the compliance or treasury systems that actually needed to act on these events. 5. Multi-tenancy was absent. The platform served one mock client and one mock admin. Scaling to dozens of clients, each with their own wallets, sub-wallets, ad accounts, compliance profiles, and credit limits, required data isolation, permissioning, and tenant-aware queries that did not exist. 6. Ad platform integration was faked. TikTok metrics like impressions, clicks, ROAS, and pixel health were all static datasets. Production requires OAuth-based API integrations, rate-limited data syncing, webhook listeners for pixel status changes, and graceful degradation when platform APIs go down. The founder understood all of this. The prototype was never meant to be the product. It was meant to prove that the product was worth building. Why They Brought In a Team The gap between the prototype and production was not a matter of fixing bugs. It was an architecture problem. The founder needed: - A real backend with transactional guarantees for financial operations - A compliance engine that could enforce document workflows across jurisdictions - A risk system that could ingest transaction data and surface actionable alerts, not static strings - Multi-tenant data architecture with proper isolation and access control - Ad platform integrations that could handle real API contracts, rate limits, and failures - Observability including logging, monitoring, and alerting so the ops team could trust the system under load They did not need someone to rewrite the frontend. They needed someone to build the system underneath it. What We Delivered Financial Operations Layer We replaced the mock API with a transactional backend. Every wallet operation, including top-ups, transfers, allocations, and refunds, now runs through an auditable pipeline with: - Atomic balance updates with optimistic locking - Double-entry ledger for every fund movement - Idempotent transaction processing to prevent duplicate charges - Full audit trail with actor, timestamp, and before and after state Top-up requests now flow through a verification pipeline with submission, proof-of-payment upload, approval, and balance credit. Each step is recorded and reversible. Compliance and KYB Engine - We built a document lifecycle system that replaces static badges with enforced state transitions: - Documents move through missing → uploaded → under_review → verified → expired with rules governing each transition - Expiration monitoring triggers automated client notifications before deadlines - Third-party identity verification integration for director ID matching - Jurisdiction-aware requirements where different regions require different document sets - Audit-grade logging for every status change, reviewer action, and override The KYB pipeline now routes cases to specific compliance agents based on workload, region, and verification type. Risk and Anomaly Detection We replaced hardcoded risk labels with a scoring system that evaluates: - Transaction velocity based on spend acceleration versus historical baseline - P2P transfer patterns and threshold breaches - Compliance status correlation, such as expired documents combined with high spend - Account dormancy detection where inactivity triggers review Risk scores update in near real time. High-risk events automatically generate work queue items with priority, context, and suggested actions. Work Queue and Case Management We transformed the frontend-only task list into an event-driven operations system: - Events from treasury, compliance, and risk systems automatically create queue items - Assignment logic routes items to the right agent based on type, region, and capacity - SLA tracking with escalation rules for overdue items - Case history that records every action, note, and resolution - Enforced status transitions so items cannot be resolved without required actions Multi-Tenant Architecture We designed the data layer for tenant isolation from the ground up: - Each client organization has isolated wallets, documents, ad accounts, and transaction histories - Role-based access control separates client-facing and admin-facing data - API endpoints are tenant-scoped to prevent cross-tenant data leakage - Admin views aggregate across tenants with proper permissioning Ad Platform Integration We built a sync layer for TikTok Ads with an architecture that supports additional platforms: - OAuth-based account linking with token refresh management - Scheduled metric pulls with rate limit awareness and backoff - Pixel health monitoring via event signal tracking instead of static labels - Graceful degradation where stale data is clearly labeled if APIs fail Observability We added the infrastructure the ops team needs to trust the system: - Structured logging for every financial operation, compliance action, and API call - Health dashboards for backend services, integration sync status, and queue throughput - Alerting on anomalies such as failed transactions, sync delays, and SLA breaches - Error tracking with business context, not just stack traces The Outcome The system went from a prototype that could demo well to a platform that could process real money, enforce real compliance, and surface real risk under real load. What changed: - Financial operations now run with transactional guarantees. Wallet balances are accurate, auditable, and reconcilable. - Compliance is enforced, not displayed. Document workflows follow regulated state machines with full audit trails. - Risk detection is continuous and contextual. The ops team acts on scored alerts instead of static labels. - The work queue drives operations. Events flow in automatically, route correctly, and track resolution against SLAs. - Multi-tenancy works. New clients onboard into isolated environments without architectural changes. - Ad integrations sync reliably. When they fail, the system clearly shows it instead of masking stale data. The founder’s instinct was right from the start. The domain model, the UX, and the operational workflows all held up. What we built was the engineering foundation that made it dependable. The system worked until it didn’t. Not because the idea was flawed, but because it was never designed to handle this level of complexity. The prototype proved the product. The production system proved it could scale. Tech Stack Overview 1. Backend: Node.js (NestJS) 2. API: GraphQL 3. Auth: Auth0 4. Database: PostgreSQL 5. Cache/Queue: Redis 6. Search: Elasticsearch 7. Infrastructure: AWS 8. Containers: ECS Fargate 9. CI/CD: GitHub Actions 10. IaC: Terraform 11. Integrations: Stripe 12. Risk Engine: Python (FastAPI) 13. ML Pipeline: scikit-learn 14. AI Assistant: OpenAI GPT-4 15. Vector Store: Pinecone
2
1.9K
Cover image for Multi-Tenant CMS and Website Platform
Multi-Tenant CMS and Website Platform for Multi-Brand Organizations Description: A production-ready multi-site CMS that lets one team run many branded websites from a single admin. It includes tenant isolation, a block-based page builder, automated WordPress migration, AI-assisted page building, and AWS infrastructure. The challenge: The client needed to manage many separate websites from one CMS. Each site had its own domain, theme, content and users. The platform had to do four things at once: • keep tenants fully isolated from each other • give editors reusable building blocks instead of one-off pages • make moving existing WordPress sites in fast instead of a manual rebuild • run reliably in production, not just work as a prototype What I built: 1. Multi-tenant Payload CMS. Tenant isolation, per-tenant domains and themes, and role-based access control, so every brand stays separate within one admin. 2. Block-based page builder. Reusable content blocks, plus blog and form support, so editors build pages without a developer. 3. WordPress migration automation. Existing sites are imported automatically, and content import and export runs through structured workflows. 4. AI-assisted page and component generation. Claude turns screenshots and layouts into ready-to-use pages and components, which speeds up new-site setup. 5. Performance and SEO. Static site generation with Next.js, semantic HTML, and Tailwind CSS for fast, search-friendly pages. 6. Production AWS infrastructure. Defined in CloudFormation with RDS (PostgreSQL), S3, CloudFront, ACM, SES, Lambda and WAF, with separate staging and production environments. 7. Production-readiness work. Improvements to admin UX, data workflows, environments and infrastructure security, plus Playwright in the tooling. The outcome: The product went from concept to a production-ready multi-site platform. One team can now launch and run many branded websites from one place. Each site is isolated, fast and SEO-friendly. Migrations and new builds take a fraction of the manual effort. Key takeaway: A white-label CMS only scales when flexible content tooling comes with real production engineering: isolation, migrations, infrastructure and security. Good fit for: agencies, franchises, multi-brand organizations, and SaaS teams managing many websites from one platform. Skills and tools used: Next.js · Payload CMS · PostgreSQL · Tailwind CSS · AWS · CloudFormation · CloudFront · RDS · S3 · Lambda · SES · WAF · Playwright · Claude API · Multi-Tenant SaaS · Headless CMS · WordPress Migration · SEO
1
13
Cover image for KovaRisk: When the Interface Knew
KovaRisk: When the Interface Knew More Than the System ────────────────────────────────────────── The Expert in the Room Compliance officers don't struggle to understand risk. They struggle to act on it fast enough. The team behind KovaRisk understood this precisely. They had spent years inside financial institutions watching the same dysfunction repeat: alerts buried in spreadsheets, investigations tracked in email threads, audit trails reconstructed after the fact. They knew what the interface needed to feel like because they'd lived with the one that didn't. So they built it. Fast. Exactly as they'd imagined it. What emerged was sharp: a risk monitoring dashboard with filterable alert feeds, entity profiles with 12-month risk trajectories, a rule engine with toggle controls, and an audit log that felt immutable. The scenario switcher let compliance teams stress-test different alert load states. The side panel made investigations feel contained and intentional. It looked like a system that had survived production. It hadn't been asked to yet. ────────────────────────────────────────── What Existed Was a Strong Interface - Not a System Every alert in KovaRisk was generated at startup. Every risk score was computed by a random seed function. Every status change - Investigating, Resolved, Escalated - lived in component state. Every timeline event was appended to an in-memory array. Every rule toggle disappeared on refresh. The audit log recorded nothing. The export downloaded a snapshot of what React was holding at that moment. The entity risk history was a curve drawn from a formula, not a record. The logic was there. But it had nowhere to live. A compliance officer investigating a high-risk wire transfer would open the side panel, read the plain-English rule explanation, mark the alert as Investigating, add an internal note - and lose every one of those actions the moment they refreshed the browser. No colleague could see what they'd done. No regulator could verify it had happened. In financial compliance, that's not a UX problem. It's a liability. The prototype validated the workflow brilliantly. It exposed exactly how a compliance team would move through their day. But three things were missing: a source of truth, a coordination layer, and a trail that could be audited under pressure. ────────────────────────────────────────── They Didn't Need More Features - They Needed a System Behind the Interface The team came with a clear idea and a working prototype. What they needed was the architecture that made the prototype a product - the layer that turned interface actions into durable facts. Not a rebuild. A foundation. ────────────────────────────────────────── The Layer That Made It Dependable Data Models: Giving State a Home The first thing to reconstruct was where the data should actually live. KovaRisk's frontend implied a clear schema - alerts, entities, rules, audit events - but none of it persisted. The production system needed a PostgreSQL core with five primary entities: • Alert — with foreign keys to Entity, Rule, Transaction, and a JSONB timeline column for ordered event history • Entity — with risk tier, jurisdiction metadata, and a one-to-many relationship to RiskScore snapshots • Rule — with active/disabled state, trigger thresholds, false-positive tracking, and a versioning mechanism so changes to rules didn't retroactively alter historical alerts • AuditEvent — append-only, with actor ID, action type, target reference, and a server-generated timestamp that clients cannot modify • InternalNote — owned by an alert, with authorship and a soft-delete flag to preserve compliance integrity Every status change, note, escalation, and flag the UI handled ephemerally became a write to this schema. The Alert Generation Engine: Replacing the Seed Function In the prototype, 85 alerts appeared because a loop ran 85 times at startup. In production, alerts are the output of a Transaction Monitoring Service - a background process that runs continuously against incoming transaction streams. This service: • Evaluates each transaction against every active Rule definition • Computes a risk score using rule weights, entity risk tier, jurisdiction flags, and behavioral baselines • Creates an Alert record only when a threshold is breached • Emits an event to a notification queue for high-risk triggers The rule engine the UI let users toggle wasn't decorative. Each rule mapped to an evaluation function in the monitoring service. Disabling a rule didn't just grey out a card - it removed it from the active evaluation set. Re-enabling it didn't retroactively generate alerts it would have caught; it resumed from the point of activation. That distinction mattered for regulatory defensibility. ────────────────────────────────────────── Async Workflows: The Operations the UI Implied But Couldn't Sustain Several interactions in the prototype implied workflows that couldn't complete synchronously. Escalation - When an alert was escalated, the UI changed a status badge. In production, escalation triggers a queue job that: notifies the senior compliance officer via a configured channel, creates a case record linking the alert, and starts a response SLA timer. The UI reflects the outcome - it doesn't produce it. Scheduled Screening - The Sanctions Screening Match rule in the prototype was static. In production, it's a nightly job that re-screens all active entities against updated OFAC, EU, and UN sanctions lists - generating new alerts if a previously clean entity now appears. The results feed back into the alert pipeline. Report Export - The dashboard's Export Report button downloaded a text file of whatever React was holding in memory. In production, report generation is an async job: the user requests the report, the job runs server-side against the live database, and a download link is returned when ready. The content is a verifiable, timestamped record - not a UI snapshot. ────────────────────────────────────────── The Audit Log: From Feed to Fact The prototype's audit log was populated by a generateAuditLog function. It looked comprehensive and immutable. It was neither. Production audit events are written by the API layer on every state-modifying operation - before the response is returned to the client. The table is append-only. No update operations are permitted on AuditEvent records. Timestamps are server-generated in UTC and stored with full precision. Actor identity comes from the authenticated session, not from a string the client sends. The audit log the interface displayed was a simulation of accountability. The production version is the accountability. ────────────────────────────────────────── Tech Stack 1. Frontend: React + Vite, React Router v6, Recharts, React Context + local state, TanStack Query 2. Backend: Node.js + TypeScript, Fastify, Prisma, PostgreSQL, Redis, BullMQ, Passport.js + express-session 3. Infrastructure: AWS ECS / Railway / Render, S3, AWS Secrets Manager / Doppler, Sentry + Datadog, GitHub Actions 4. External Integrations: OFAC / ComplyAdvantage, Refinitiv World-Check, SendGrid / SMTP, Webhooks  ────────────────────────────────────────── From Interface to System The prototype answered the right questions. It proved the workflow was sound, the information hierarchy was correct, and the alert investigation pattern worked the way compliance officers needed it to. What it couldn't answer was: what happens when two investigators open the same alert simultaneously? What happens when a rule change needs to take effect immediately across 200 pending alerts? What happens when a regulator asks for every action taken on a specific entity over the past 18 months? Those questions don't live in the interface. They live in the system. KovaRisk's interface was always strong. What it needed was the architecture to make it real - persistent, coordinated, auditable, and defensible under scrutiny. The logic existed from the beginning. We gave it somewhere to live.
2
2K
Full Stack Web Developer | .NET + HTML/CSS/JS | Clean & Fast
26
Followers
Full Stack Web Developer | .NET + HTML/CSS/JS | Clean & Fast
Software Engineer | Python, React | AI & Automation
Software Engineer | Python, React | AI & Automation
Bringing Your Ideas to Life with Modern, Custom Websites
5.0
Rating
5
Followers
Bringing Your Ideas to Life with Modern, Custom Websites
Cover image for Syed Ahmer Shah built a
Syed Ahmer Shah built a versatile Taxi Booking & On-Demand Mobility Platform that combines passenger transportation and delivery services within a single cross-platform mobile application. The solution allows customers to arrange taxis, private vehicles, motorcycles, and various on-demand services through one unified digital ecosystem for Android and iOS. The project highlights expertise in Mobile Application Development, Ride Hailing App Development, Transportation Technology, Logistics Software Development, Custom Software Engineering, Backend Development, and UI/UX Design. The platform was engineered to support both everyday ride-booking requirements and broader delivery use cases without compromising usability or performance. Customers can request rides instantly, schedule trips in advance, view estimated fares, identify nearby drivers, and follow their journeys through live GPS tracking. Secure digital payments, trip history, driver ratings, and in-app communication provide a complete ride-booking experience. The platform also extends into parcel delivery, food delivery, courier operations, and other on-demand services, creating a multi-purpose super app for transportation and local services. The cloud-native backend manages GPS location services, real-time driver-passenger matching, intelligent route planning, payment processing, live trip updates, messaging, push notifications, and operational data synchronization. Dedicated dashboards give passengers, drivers, merchants, and administrators access to role-specific management tools. The architecture is designed for high availability, responsive performance, security, and scalable operation across Android and iOS devices. This project demonstrates Syed Ahmer Shah’s ability to create enterprise-level ride hailing systems, taxi reservation applications, logistics platforms, delivery solutions, mobility software, and scalable super apps for transportation companies, startups, logistics providers, and on-demand businesses. Technologies Used: React Native, Node.js, Express.js, Firebase, PostgreSQL, AWS Cloud, Google Maps API, Socket.io (http://Socket.io), REST APIs, Payment Gateway Integration, Push Notification Services. Services Provided: Mobile App Development, Android App Development, iOS App Development, React Native Development, Ride Hailing App Development, Taxi Booking App Development, Super App Development, Logistics Software Development, Delivery App Development, GPS Tracking Development, Backend Development, API Development, UI/UX Design, Cloud Infrastructure Development. Keywords: Ride Hailing App Development, Taxi Booking App Development, Super App Development, Mobile App Development, React Native Development, Android App Development, iOS App Development, Logistics App Development, Delivery App Development, Courier App Development, Mobility Platform Development, Google Maps API, Node.js, Firebase, PostgreSQL, AWS, REST API, Custom Software Development, Software Engineer.
1
30
Cover image for Syed Ahmer Shah developed an
Syed Ahmer Shah developed an intelligent AI-Powered Fitness & Workout Tracking Mobile Application designed to help users establish consistent exercise routines, follow customized training programs, and work toward their health and fitness objectives. The cross-platform solution combines personalized workouts, activity monitoring, performance analytics, and AI-driven recommendations within a streamlined experience for Android and iOS users. The project highlights expertise in Mobile Application Development, Fitness App Development, Healthcare Software Development, AI Application Development, Custom Software Engineering, Backend Development, and UI/UX Design. The platform was designed to provide users with a personalized digital fitness companion that adapts to their goals, abilities, and training preferences. Users can create detailed fitness profiles and select workout programs according to fitness level, personal objectives, workout duration, and targeted muscle groups. The application provides guided exercises while allowing users to record completed sessions, estimate calories burned, review historical activity, and analyze performance over time. AI-powered recommendations help personalize future workouts, while reminders encourage consistent training. Wearable and health-device integrations allow activity and wellness information to be synchronized across supported devices. The platform is supported by secure cloud infrastructure featuring user authentication, real-time data synchronization, workout and exercise management, health data connectivity, push notifications, subscription handling, performance analytics, and centralized administration. The admin dashboard enables authorized teams to manage users, trainers, exercise libraries, workout programs, subscriptions, and reporting. The architecture is built for reliable performance, security, and scalability across Android and iOS platforms. This project demonstrates Syed Ahmer Shah’s ability to develop AI-powered fitness applications, workout tracking platforms, healthcare software, wellness solutions, personal training applications, and customized mobile products for gyms, fitness startups, personal trainers, wellness companies, healthcare organizations, and digital health businesses. Technologies Used: React Native, Node.js, Express.js, Firebase, PostgreSQL, AWS Cloud, REST APIs, Health Data Integration, Wearable Device Integration, Push Notification Services, Subscription Management. Services Provided: Mobile App Development, Android App Development, iOS App Development, React Native Development, Fitness App Development, Workout App Development, Healthcare App Development, AI App Development, Backend Development, REST API Development, UI/UX Design, Cloud Infrastructure Development. Keywords: AI Fitness App Development, Workout Tracking App, Mobile App Development, React Native Development, Android App Development, iOS App Development, Healthcare App Development, Personal Trainer App, Gym App, Health & Wellness App, Node.js, Firebase, PostgreSQL, AWS, REST API, Custom Software Development, Cross-Platform App Development, Software Engineer.
1
62
Cover image for Syed Ahmer Shah developed a
Syed Ahmer Shah developed a secure and scalable Digital Banking & FinTech Mobile Platform that brings payments, money transfers, digital accounts, card management, budgeting, and everyday financial services together in one intuitive cross-platform application. The project demonstrates expertise in Mobile Application Development, FinTech Software Development, Digital Banking Solutions, Banking Software Engineering, Custom Software Development, Backend Development, Cloud Infrastructure, and UI/UX Design. The platform was designed to provide individuals and businesses with convenient digital financial tools while maintaining strong security and reliability. Users can open and manage digital accounts, transfer funds, send and receive money, handle physical and virtual payment cards, pay bills, and review detailed transaction activity. Financial management features allow users to monitor spending, create budgets, analyze expenses, and receive real-time financial insights. The platform also supports QR-based payments, biometric login, KYC verification, instant transaction alerts, and secure payment processing to provide a comprehensive digital banking experience. A cloud-native backend supports secure API connectivity, real-time transaction synchronization, payment gateway integrations, financial analytics, authentication services, and centralized administration. The administrative dashboard provides authorized teams with tools for managing customers, accounts, transactions, payments, compliance processes, and financial reports. The architecture is optimized for high availability, data protection, and scalable operation across Android and iOS devices. This project showcases Syed Ahmer Shah’s capability to develop digital banking applications, FinTech platforms, mobile banking systems, payment applications, digital wallet solutions, and enterprise financial software for financial institutions, FinTech startups, payment providers, and digital finance businesses. Technologies Used: React Native, Node.js, Express.js, PostgreSQL, Firebase, AWS Cloud, REST APIs, Payment Gateway Integration, KYC Verification, Push Notification Services. Services Provided: Mobile App Development, Android App Development, iOS App Development, React Native Development, FinTech App Development, Digital Banking App Development, Digital Wallet Development, Payment App Development, Banking Software Development, Backend Development, API Development, UI/UX Design, Cloud Infrastructure Development. Keywords: Digital Banking App Development, Mobile Banking App Development, FinTech App Development, Banking Software Development, Digital Wallet Development, Payment App Development, Mobile App Development, React Native Development, Android App Development, iOS App Development, Financial Software Development, Digital Payments, Money Transfer App, KYC Integration, Payment Gateway Integration, Node.js, Software Engineer.
1
53
Cybersecurity engineer and software developer building robus
New to Contra
Cybersecurity engineer and software developer building robus
Cover image for ShadowForge is an adversary-emulation and
ShadowForge is an adversary-emulation and security-validation platform I built to help security teams model attack scenarios, visualize activity, correlate threat intelligence, and evaluate defensive visibility from a single operations interface. The platform brings together scenario orchestration, network visualization, threat intelligence, MITRE ATT&CK mapping, enterprise identity simulation, analytics, and reporting into one unified workflow. I designed the application around modular simulation components so authorized lab and security-validation exercises can be configured, observed, and translated into useful defensive findings rather than scattered logs and manual notes. Key engineering work included: Centralized security operations dashboard Configurable adversary-emulation scenarios Reconnaissance and environment-discovery simulation Lateral-movement and persistence scenario modeling Live execution-event visualization Network topology and host mapping MITRE ATT&CK technique mapping Threat-intelligence and IOC enrichment Enterprise user simulation for realistic lab scenarios Security analytics and severity tracking Automated findings and report generation Modular architecture designed for controlled security testing ShadowForge turns an authorized security exercise into something measurable: operators can configure a scenario, observe activity as it happens, correlate findings with threat intelligence and ATT&CK techniques, and produce structured results for defensive analysis. Built for controlled labs, security validation, and authorized adversary-emulation environments.
0
67
Cover image for Grim Lens is a local-first
Grim Lens is a local-first malware intelligence and threat-hunting workbench I built for security teams that need to analyze evidence without sending sensitive samples to the cloud. The platform ingests static artifacts such as PE metadata, strings, YARA matches, decoded configurations, PCAP summaries, and screenshots, then organizes them into investigation cases with risk scoring, enrichment, reporting, and cross-case intelligence. I designed the system around a strict security boundary: no sample execution, no automatic uploads, and no outbound enrichment unless explicitly requested. The backend is built in Rust using Axum, Tokio, SQLx, SQLite, YARA-X, and structured analysis modules, while the desktop interface is built with Avalonia/.NET 10 using MVVM and interactive charts. Key engineering work included: Local-first malware case management Static PE analysis and entropy inspection YARA rule matching and rule-pack management Threat-intelligence enrichment using services such as VirusTotal, abuse.ch (http://abuse.ch), and AlienVault OTX Rate limiting and TTL caching for external enrichment Cross-case indicator correlation Automated Markdown and PDF report generation Risk distribution, family, and category dashboards Rust REST API with structured validation and errors SQLite-backed local storage and migrations Cross-platform Avalonia desktop application CI builds and packaged Windows/Linux releases The result is a practical analyst workbench that turns scattered malware artifacts into a structured, searchable casebook while keeping control of sensitive data on the analyst’s own workstation.
0
74
Cover image for Vexis is a custom x86-64
Vexis is a custom x86-64 binary analysis and reverse-engineering platform I built from the ground up in Rust, with a .NET desktop frontend for interactive analysis. Instead of wrapping an existing disassembly library, I implemented the core instruction-decoding pipeline myself, including legacy and REX prefixes, ModR/M, SIB addressing, RIP-relative addressing, instruction boundaries, and control-flow instructions. From that decoded instruction stream, Vexis reconstructs basic blocks, functions, and typed control-flow graphs, calculates cyclomatic complexity, identifies anti-disassembly patterns, and generates structured analysis reports. The visual frontend turns the analysis engine into a usable product: users can inspect full disassembly, explore function-level CFGs, review complexity and control-flow statistics, and analyze entire batches of binaries from one interface. Key engineering work included: Custom x86-64 instruction decoder written in Rust Linear-sweep and recursive-descent analysis strategies Basic-block and function recovery Control-flow graph generation and visualization Cyclomatic complexity and binary statistics Anti-disassembly detection Batch analysis across multiple binaries JSON, Markdown, and Graphviz reporting Differential testing and fuzz testing of the decoder .NET GUI communicating with the Rust engine across a clean process boundary The result is more than a frontend demo: it is a complete analysis pipeline that goes from raw PE64 machine code to searchable disassembly, recovered program structure, visual control flow, and automated reports.
0
58
Software Engineer | Web Developer | SAAS Developer
Software Engineer | Web Developer | SAAS Developer
I build products that ship and ideas that scale.
I build products that ship and ideas that scale.