Toronto · 43.77°N 79.41°W

I build systems that
hold up under attack.

Founding engineer at Aptosi, a seed-stage fintech working on invoice fraud detection. I work across application security, real-time firmware, and the product on top of both — three internships and a thousand-user ticketing platform behind me, and a Software Engineering degree at Seneca still ahead.

Focus
Application security
Currently
Aptosi · Seneca
Graduating
April 2027
Status
Open to roles
Selected work

Things I've shipped and broken on purpose.

  1. 2026

    CASA Tier II security assessment

    Took Aptosi through Google's CASA Tier II compliance end to end. Ran authenticated OWASP ZAP scans against production and found high-severity server-side template injection and SQL injection, plus a PII disclosure path. Wrote the assessment reports, worked with the external lab, and tracked every finding through to a fix.

    • OWASP ZAP
    • SSTI / SQLi
    • Threat reporting
    Aptosi
  2. 2026

    Merge-time SAST gate

    Wired static analysis into GitHub Actions across all four Aptosi repositories, with critical findings blocking the pull request rather than landing in a dashboard nobody reads. Security moved from a quarterly audit to a condition of merging, and the critical and high-severity backlog got resolved to clear a compliance bar rather than deferred.

    • GitHub Actions
    • SAST
    • CI/CD
    Aptosi
  3. 2025—

    Invoice classification engine

    Took Aptosi's core classification engine off a hand-written rule set and onto an AI-driven architecture, improving detection accuracy and letting it scale past the point where somebody has to write a new rule for every fraud pattern. The product around it spans a Chrome extension, a React/Next.js dashboard, and the backend API underneath.

    • Applied AI
    • Next.js
    • Backend API
    Aptosi
  4. 2025—

    QuickBooks Online integration

    Built and hardened Aptosi's Intuit integration: OAuth 2.0 authorization flows, launch and disconnect URLs, webhook subscriptions, and the migration onto Intuit's CloudEvents payload format. Accounts-payable data crossing a trust boundary, carefully.

    • OAuth 2.0
    • Webhooks
    • Fintech
    Aptosi
  5. 2026—

    CYRAVENT

    A multi-tenant security intelligence platform I'm building milestone by milestone from a full engineering spec — Next.js and TypeScript on the front, FastAPI with PostgreSQL and Redis behind it, a provider-agnostic AI layer, Docker throughout. Defensive only, with RBAC, audit logging and tenant-isolation tests treated as requirements rather than follow-ups.

    • Next.js
    • FastAPI
    • Multi-tenant
    • RBAC
    Personal
  6. 2025

    Matangi Event

    A full-stack ticketing platform that scaled to over a thousand users, handling live payment transactions end to end. Shipped to real buyers, which meant debugging payment flows in production and tuning the checkout UX against actual traffic rather than a staging fixture.

    • Payments
    • Full-stack
    • matangievent.com
    Freelance
  7. 2024

    Interactive livestream platform

    Real-time RTSP livestreaming with draggable, resizable broadcast overlays — React and Flask, React-RND for the overlay layer, MongoDB behind a CRUD API. Live video and a mutable UI on top of it, staying in sync.

    • RTSP
    • React
    • Flask
    • MongoDB
    Personal
  8. 2024

    CloakScan

    A privacy Chrome extension that detects and blocks third-party trackers, measured at a 95% data-leak prevention rate. Reading what a page tries to exfiltrate before it gets the chance — the same instinct as the security work, pointed at the browser.

    • Chrome extension
    • Privacy
    • Tracker blocking
    Personal
  9. 2024—

    Real-time acquisition on FRDM-K66F

    ADC sampling under FreeRTOS with DMA-fed ring buffers, I²S/SAI audio output, and time-of-flight and gyroscope sensors over I²C. The kind of code where a missed deadline isn't a warning, it's a wrong answer.

    • FreeRTOS
    • DMA
    • C
    Seneca
  10. 2024

    Attention-based computer vision

    VGG16 transfer learning with CBAM attention blocks, alongside recurrent models and reinforcement-learning experiments. The half of my stack that's allowed to guess, sitting next to the half that never is.

    • CNNs
    • CBAM
    • PyTorch
    Seneca
About

Three disciplines, one stack.

Most engineers pick one of these. I kept all three because they sharpen each other. Application security taught me to read a system looking for what it wasn't designed to do. Embedded work taught me that correctness has a deadline measured in microseconds. Product engineering keeps both honest — a finding nobody can act on and firmware nobody ships are the same thing.

At Aptosi I'm a founding engineer on a small team, which in practice means I own problems rather than tickets: the compliance assessment, the CI security gate, the accounting integrations, the classification engine, and whatever else is between us and shipping. Before that I was a web developer intern at Alpha Business Consulting in Calgary and a full-stack intern at Coding Cloud in Ahmedabad, and alongside all of it I write firmware for NXP Kinetis boards and train vision models at Seneca.

The things I've shipped outside work tend to be the ones that taught me most. A ticketing platform that took real money from a thousand-odd real people. A livestream tool with a UI you can drag around while the video keeps playing. A Chrome extension that blocks 95% of the trackers trying to read the page you're on.

I grew up in Himmatnagar, Gujarat, and moved to Toronto in 2023. I'm graduating in April 2027 and looking for teams working on security, fintech infrastructure, or anything with firmware in it.

Stack

What I reach for.

Security

  • OWASP ZAP, authenticated DAST
  • SAST in CI, policy as code
  • Threat modelling & reporting
  • SPF, DKIM, DMARC
  • OAuth 2.0, webhook signing

Embedded

  • FreeRTOS on NXP Kinetis
  • DMA, ring buffers, I²S/SAI
  • I²C, SPI, UART
  • ToF and IMU sensor integration
  • C, C++, bare-metal debugging

Frontend

  • TypeScript, JavaScript
  • React, Next.js, SvelteKit
  • Tailwind, Bootstrap
  • WebSockets, Socket.io
  • Chrome extensions

Backend

  • Node.js, Express
  • Python, FastAPI, Flask
  • Java, Spring Boot
  • PHP, Laravel
  • REST, GraphQL

Data & infra

  • PostgreSQL, MySQL, SQL Server
  • MongoDB, Redis, Firebase
  • Docker, Kubernetes
  • AWS, Google Cloud
  • CI/CD, Git

Machine learning

  • CNNs, VGG16 transfer learning
  • CBAM attention
  • RNN / LSTM
  • Reinforcement learning
Experience

The route so far.

  1. 2025 — now

    Founding Engineer · Aptosi

    Seed-stage fintech building invoice fraud detection and vendor verification. Security, integrations, and full-stack product work.

  2. 2024 — now

    Executive · Seneca Software Developers Club

    Built and maintain the club site that runs event registration and communications, and organize the technical workshops that go on it.

  3. 2025

    Web Developer Intern · Alpha Business Consulting

    Calgary. Designed and deployed a PDF-to-Excel bank statement processor that cut manual data entry by 70% and improved accuracy, plus internal tooling in React, Node.js and SQL/NoSQL.

  4. 2024 — 2025

    Full Stack Developer Intern · Coding Cloud

    Ahmedabad. Feature development and code review across five client accounts, owning the end-to-end communication that kept scopes clear and deliveries on time.

  5. 2023 — 2027

    B.Eng Software Engineering · Seneca Polytechnic

    Newnham Campus, Toronto. Software engineering, operating systems, algorithms, artificial intelligence and system design, alongside full-time engineering work.

  6. 2023

    Moved to Toronto · from Himmatnagar, Gujarat

    Started over in a new country and a new field at the same time.

Contact

Hiring for security, fintech, or anything with firmware in it?

I read everything and I answer fast.