I am a Software Engineer and Security Researcher, bridging the gap between high-performance product development and zero-trust architectural principles. Currently in my third year of a B.Tech in Computer Science, my engineering philosophy revolves around building scalable, decentralized, and compliance-driven systems.
- Engineering Core: Full-stack development using Node.js, React, and server-side typed ecosystems, with a focus on low-latency data pipelines and fault-tolerant cloud architectures.
- AI/ML & Security Nexus: Designing security perimeters for AI models (AI Security), integrating hybrid AI classifiers, and conducting Vulnerability Assessment and Penetration Testing (VAPT).
- Compliance & Product Mindset: Passionate about mitigating enterprise compliance overhead (GRC) through self-hosted, automated governance platforms tailored for modern businesses.
- Open To: Full-time roles, internships, freelance VAPT engagements, and open-source collaborations focused on securing the application perimeter.
| Domain | Proficiency | Details |
|---|---|---|
| AI Security & Defensive Prompting | Advanced | Hardening LLM integrations against payload injection, prompt leaking, and adversarial attacks. |
| Hybrid Classification Architecture | Advanced | Deploying customized RoBERTa models combined with Logistic Regression for automated, high-precision content detection. |
| Generative AI Auditing | Intermediate | Developing internal toolchains to analyze, trace, and flag generative AI plagiarism securely. |
| Data Privacy & Cryptography | Advanced | Architecting zero-knowledge environments; implementing on-the-fly AES-256-CBC and SHA-256 evidence hashing before disk storage. |
VaultIQ — Zero-Knowledge Assignment & AI Classification Platform
Secure assignment collection platform engineered with on-the-fly client encryption and decentralized vaults. Integrates a custom hybrid AI classifier to guarantee uncompromised data sovereignty.
| Stack | Performance | Security | Repository |
|---|---|---|---|
| React, Node.js, AWS S3, PyTorch | 98.3% AI-content detection, ROC-AUC 0.997 | AES-256-CBC, SHA-256 | View Code |
Professional Insight: Engineered to solve enterprise-grade privacy concerns in educational and corporate assignment collection. By shifting cryptographic sealing prior to disk storage and utilizing RoBERTa for AI content detection, the platform establishes a zero-trust boundary that inherently verifies structural integrity upon download.
Dharma — Self-Hosted GRC & Automated Evidence Engine (in development)
Self-hosted Governance, Risk & Compliance platform with automated evidence collection, being built to streamline audit readiness for Indian startups and MSMEs.
| Stack | Status | Security | Repository |
|---|---|---|---|
| Next.js, tRPC, PostgreSQL (pgvector), Ollama (local LLM), MinIO, Docker | In active development — private repo, walkthrough on request | Hash-chained, tamper-evident audit logging | Private |
Professional Insight: Designed to mitigate the compliance overhead faced by startups by mapping evidence to controls with a local Ollama model, so documents never touch a public AI API. Evidence is hash-chained so altering a record breaks the signature chain. Multi-tenant workspace support and Stripe billing are in progress.
Network Reconnaissance Tool — Recon, Scripted
Python tool wrapping Nmap for TCP/UDP port discovery, with DNS resolution and traceroute mapping — the reconnaissance phase of a real VAPT engagement, scripted and reusable.
| Stack | Focus | Repository |
|---|---|---|
| Python, Nmap, Sockets | Enumeration, service/version mapping, attack-surface discovery | View Code |
Professional Insight: Built to speed up the enumeration phase of hands-on VAPT work — the same recon workflow used during live assessments at HackersVilla Cybersecurity.
VAPT Intern | HackersVilla Cybersecurity Pvt Ltd March 2024 – Present
- Performed live vulnerability assessments, penetration testing, and network reconnaissance against real systems.
- Documented findings and remediation recommendations in reports that engineering teams acted on.
- Applying the same offensive-security lens to GRC — connecting technical findings to business risk and compliance frameworks.
Burp SuitePenetration TestingVulnerability AssessmentNetwork SecurityGRC
| Recognition | Details |
|---|---|
| CEH Certification Preparation | Actively preparing for the Certified Ethical Hacker (CEH) credential to validate offensive security methodologies. |
| API Vulnerability Discovery | Identified and documented Broken Authentication flaws while assessing OWASP crAPI. |
| Zero-Knowledge Architecture Design | Designed a client-side, cryptographically sealed storage protocol, applied in VaultIQ. |
Current_Status:
Learning:
- Advanced AI Security Patterns
- Zero-Trust Enterprise Architecture
- CEH Exam Methodologies
Building:
- Dharma — GRC evidence platform
- Zero-Knowledge Cryptographic Microservices
Exploring:
- Post-Quantum Cryptography in Node.js
- Decentralized Threat Intelligence Feeds
Open_To:
- Security Engineering Roles & Internships
- Offensive Security & VAPT Freelancing
