Real products are messy: auth, RBAC, real-time sync, payments, search, file uploads, undo, audit logs, conflict resolution. The interesting parts hide behind the demo - and they're where quality is won or lost.
I've built end-to-end platforms on real-time backends, event-driven architectures, and edge infrastructure - solo or embedded with your team. Engineered to last: secure foundations, stable under load, code that holds up two years in.
I work the way I'd want a contractor to work with me: short feedback loops, working software in your hands early, and decisions written down so we don't relitigate them six weeks later. You get the engineer, not a project manager forwarding tickets.
Born for complexity. Designed to stay simple.
10+ years of professional full-stack development experience
Expert in modern TypeScript stacks, AI integration, and edge infrastructure
Performance- and UX-driven from the first sketch to the final deploy
I've built real-time, collaboration-heavy platforms like LEG.TJ, Contentoren, and Gruppenplan entirely from the ground up - product design, frontend, backend, and infrastructure.
My approach is product-driven: clarity, reliability, and long-term sustainability. Systems that scale gracefully and stay enjoyable to maintain. Strong in TypeScript, React, Solid, Node/Bun, Convex, and event-driven architectures.
For AI work, I focus on what actually delivers value - not demos.
The parts that matter when your product carries real users, real data, and real money - built in from day one, not retrofitted after an incident.
Passwordless Authentication
OAuth via Google, Microsoft, Apple, or magic links - no passwords to phish, leak, reset, or store in a breach
Role-Based Access Control
Granular permissions enforced at the data layer - users only ever see and touch what they're allowed to
Real-Time Sync
Live collaboration via Convex, Yjs, or Postgres LISTEN/NOTIFY - conflict-free, no stale data, no manual refresh
End-to-End Type Safety
TypeScript across server, client, and database schema - the compiler catches drift between layers that tests miss
Hardened Security
CSP, HSTS, CSRF tokens, rate limiting, dependency scanning - the OWASP Top 10 fails closed by default, not as an afterthought
Encrypted at Rest & in Transit
TLS everywhere, encrypted disks, secrets rotated and never committed - your data is protected wherever it lives
GDPR Compliant
EU data residency, export and erasure flows, no shadow third-party sharing - compliant by design, not bolted on under threat of a fine
EU AI Act Compliant
Risk-classified AI use, human oversight on consequential outputs, transparency where required - built to the AI Act's obligations, not retrofitted once enforcement hits
Audit Trail
Event-sourced where state matters - who changed what, when, and why, queryable on demand for compliance or postmortems
Observability First
Distributed tracing, structured logs, and alerts wired up from day one - I hear about problems before your users do
Automated Backups
Point-in-time recovery with tested restore drills - data loss isn't one keystroke or one bad migration away
Stable Under Load
Idempotent endpoints, retry policies, queue-backed jobs, graceful degradation - it holds up when traffic spikes instead of falling over
Long-Term Support
One engineer who built it, knows it, and stays reachable - not an agency rotation that forgets the why six months in
Live examples and case studies - full deep-dives available on request.
LEG.TJ
National platform connecting the Tajik government and development partners to plan, track, and improve education support. The production app designed to help coordinationg $100M+ in funding flows with real-time collaboration.
Real-time group-planning platform for hotels, campsites, and tour operators. The production app handles room assignments, preferences, and collaborative workflows at scale on an event-driven backend.