Hamza Hafeez
Software and AI Systems Engineer
Lahore, Pakistan·Remote-ready · Open to relocate
Summary
I design and ship production software at the intersection of multi-agent AI, backend systems, and application security. My work ranges from research on executive-control architectures to live products with billing, auth, observability, and developer tooling. I care about systems that are measurable, operable, and honest about their trade-offs.
Focus
AI systems
Multi-agent pipelines, LLM routing with fallbacks, evaluation/judgment loops, RAG, and chat orchestration with intent routing and token budgets.
Backend
Go and FastAPI services, PostgreSQL with RLS, Redis caching and Pub/Sub, WebSockets, async workers, multi-tenant schemas, API design.
Security
OWASP/CWE-oriented analysis, SAST integrations, sandboxing, secure auth, webhook verification, audit logging, and local-first security tooling.
Product delivery
End-to-end ownership from architecture to production: Next.js apps, SDKs, billing, CI/CD, docs, and client delivery across multiple countries.
Experience
Founder and Software Engineer
Histeeria
Python · TypeScript · FastAPI · PostgreSQL · Redis · LLM APIs · SDKs
- Building trust infrastructure for AI agents: SDK ingest, async evaluation, dashboards, alerts, reports, and public agent profiles.
- Implemented a three-tier judgment pipeline: rule-based checks, LLM judge, and adjudicator scoring across eight dimensions.
- Shipped zero-dependency client SDKs on PyPI and npm, with a FastAPI backend and multi-tenant schema.
- Pivoted from an earlier social-platform direction (Asteria) into agent observability and runtime evaluation.
Founder and Chief Engineer
Cortex EDR
Next.js 15 · TypeScript · Supabase · NextAuth · Paddle · Multi-provider LLM routing
- Built a multi-agent security auditing platform (~29k lines of TypeScript) that scans GitHub repositories and produces scored, CWE/OWASP-classified reports.
- Designed a 7-agent sequential pipeline: recon, security, architecture, quality, debt, AI-pattern detection, and orchestrator synthesis with shared scan memory in PostgreSQL.
- Implemented provider-agnostic AI routing with fallbacks (OpenAI, OpenRouter, Gemini, Groq, DeepSeek), usage logging, and tier-gated model selection.
- Shipped Cortex Chat: intent classification, scoped context retrieval, token-budgeted compression, tool loops, and sanitization for post-scan codebase Q&A.
- Delivered production SaaS surfaces: auth, RLS, Paddle billing, PDF reports, CI/CD (lint, typecheck, build, CodeQL), and Railway deploys.
Software Engineer
Upvista Digital
Go · FastAPI · Next.js · PostgreSQL · Redis · Docker · Cloud
- Delivered full-stack and AI systems for clients in Japan, the United States, Germany, New Zealand, Singapore, and Pakistan.
- Own technical discovery, architecture, implementation, and production handoff as the primary engineering contact.
- Build multi-tenant backends, secure APIs, and cloud deployments using Go/FastAPI, PostgreSQL, Redis, and Docker.
Engineer
Cortex Attack
TypeScript · Node CLI · Docker · nmap · nikto · semgrep · trivy · Ollama
- Built a terminal-native security orchestration engine that coordinates host scanners and falls back to Docker when tools are missing.
- Runs a local-first, non-destructive audit pipeline: service discovery, route discovery, header analysis, vuln scan, dependency audit, attack-graph reasoning, and remediation narrative.
- Supports local Ollama models by default, with optional OpenAI/Anthropic providers for deeper exploit-path analysis and code patches.
- Available on npm (https://www.npmjs.com/package/cortex-attack) use 'npm install -g cortex-attack' to install
Engineer, Architect, & Creator
Anya
TypeScript · Python · NATS · WebSockets · CV · TTS/STT · Memory systems
- Building an open-source companion-robot OS that combines perception, memory, cognition, and expressive behavior.
- Designed an event-driven NATS architecture so subsystems stay in continuous communication without blocking each other.
- Used practical hardware constraints: Raspberry Pi as onboard compute, phone as sensors and face.
Founder and Engineer
Asteria (early Histeeria)
Go · Next.js · Flutter · PostgreSQL · Redis · WebSockets · E2EE
- Built a privacy-first social platform spanning Go backend, Next.js web, and Flutter mobile with end-to-end encrypted messaging.
- Designed for high concurrency: Redis Pub/Sub for multi-instance WebSockets, async workers, feed caching, and modular-monolith boundaries.
- Implemented OTP/OAuth auth, real-time messaging, feeds, statuses, notifications, and GDPR-oriented data export paths before pivoting the company thesis toward AI agent trust.
Research
Project Cortex: A Prefrontal-Cortex-Inspired Orchestrated Architecture for Artificial General Intelligence
Self-published research article · 36 pages · reviewed by 57 researchers
- Proposed an executive-control architecture for multi-agent systems: orchestrator, specialized agents, shared memory, risk evaluation, and hierarchical task decomposition.
- Applied the same model in production systems such as Cortex EDR, where agents map to narrow functions and an orchestrator synthesizes shared working memory into a final report.
Skills
Languages
Go · TypeScript · Python · SQL · C# · Dart
Systems and backend
FastAPI · Gin · Next.js · PostgreSQL · Redis · NATS · WebSockets · Docker · CI/CD · Distributed systems
AI systems
Multi-agent pipelines · LLM routing and fallbacks · LangGraph / LangChain · RAG · Runtime evaluation · Prompt contracts and structured output · Usage and cost observability
Security
OWASP / CWE analysis · SAST · Semgrep · Secure API design · AuthN/AuthZ · RLS · Webhook verification · Local-first security tooling
Delivery
System architecture · Technical scoping · SDK and CLI packaging · Billing and multi-tenant SaaS · Client delivery · Documentation
Education
BS, Computer Science
National University of Modern Languages
Won 5 hackathons