Four years inside one company's
production estate. Still shipping.
Forward deployed engineer. four and a half years embedded at ATG Entertainment: 920 pull requests, 97% of my work in repositories I do not own, median same-day merge. Feature delivery fell from 47% to 28% of those PRs between 2024 and 2026 while security and observability tripled, because I stopped building the system and started being accountable for it. Four products shipped solo alongside it, not after: 94% of my active weeks in 2026 touch both. Available for engagements or a role. Scope-or-refund on every sprint.
Diagram: an event-driven AWS reference architecture. Amazon EventBridge fans out to SQS queues that trigger Lambda functions writing to DynamoDB, processing billions of events per year.
Trusted by engineering teams at



End-to-end engineering for
companies that run on AWS.
Software Development
TypeScript, Node.js, React, Python. Product engineering from MVP to enterprise scale.
AWS Architecture
Serverless, microservices, event-driven design, Well-Architected reviews.
AI Engineering
Production RAG and generative AI on Bedrock, with accuracy tracking and regression checks so a prompt change cannot quietly make things worse.
Edge & Cloudflare
Cloudflare Workers and KV at the edge. Routing, caching, security headers, zero-downtime maintenance.
Cost Optimization
Public, verifiable cost scans on costpatrol.io. Not a claim, a report you can open.
DevOps & Infra
CI/CD, Terraform/CDK, observability, incident response. Boring deploys.
Growth Engineering
Server-side conversion tracking that counts once: Conversions API events deduplicated against the browser pixel, dispatched off the critical path, with the identity normalisation that decides whether they match anyone at all. Starts with an audit of the events you fire today.
What we have
delivered.
Named clients, real architectures, numbers a skeptic can verify. A sample below; the rest are in the case studies.
All case studiesZero tracking to ad-ready
A commercial launch in Egypt with no ad account, no pixel and no product page. Built the acquisition stack: server-side conversion tracking deduplicated against the browser pixel, a bilingual RTL product page carrying the real 70-unit schedule as an interactive plan, a teardown of ten live competitors, and a 72-prospect outbound list. The audit also caught the live site advertising unit sizes the building does not have.
Read the case study50+ Lambdas, 4 countries
KYC/CDD compliance platform serving Norway, Sweden, Denmark, and Finland. 6 compliance providers integrated. Multi-tenant SaaS on Serverless plus CDK plus Cognito.
Read the case studyHIPAA + SOC2, 2 regions
Multi-tenant platform tracking medical diagnostic samples from collection to result. Region-specific data residency, KMS encryption, audit trails, RBAC across five roles.
$6,496/mo cut
17 redundant Aurora clusters consolidated, 56 findings surfaced and triaged. One of five public scans you can open and check yourself.
see the report on costpatrol.ioReal-time ops, Fortune 500
Downstream petroleum distribution scheduling (AWSM). Real-time operations dashboards, Step Functions ETL across SAP and the data warehouse, and WebSocket shipment streaming. 12-month engagement as Backend and DevOps lead.
Read the case studyWe ship our own products
in weeks, with Claude Code.
Specs first, Claude Code implements against the spec, a senior engineer gates every line on auth, money, and security. The same method we bring to your build. Three of ours are in production right now.
CostPatrol
FinOps SaaS
127 detection rules scan AWS accounts daily and deliver the exact fix command, with a dollar amount, straight to Slack.
VowTrust
Deal verification
Dual-mode compliance verification with an immutable audit trail and exportable certificates. 1,000+ TypeScript files, built solo.
Boody
AI nutrition coach
A self-hosted LLM reads food photos and returns calories and protein on WhatsApp, backed by a 4-layer memory that coaches.
How the work actually gets done.
AI writes a lot of the code. A written spec comes first, and a review pipeline has to agree before anything ships. The numbers that matter are not how much got written, but how little had to be taken back.
Writing
The same standard, in public.
Every claim in these carries an AWS documentation source, and arithmetic derived from published rates says so rather than passing itself off as an AWS figure. One of them documents a gap in my own detection engine.
AWS COST OPTIMIZATION
What CloudWatch Actually Costs You
Logs default to Never Expire, retention only cuts storage and not ingestion, the charge stops before deletion does, and every dimension combination is a separate billable metric.
11 min readAWS COST OPTIMIZATION
Three AWS Compute Numbers That Do Not Mean What They Look Like
The under-5% Spot figure is a cross-region historical average, the default allocation strategy is one AWS labels not recommended, and the EKS Auto Mode fee survives every discount.
12 min readAWS COST OPTIMIZATION
The AWS Costs That Do Not Show Up Where You Would Look
An idle API Gateway cache invisible to request graphs, Lambda startup billed but not logged, and why savings figures cannot simply be added together. Including one my own scanner gets wrong.
11 min readAWS COST OPTIMIZATION
The AWS Charges That Survive Being Switched Off
CloudFront plans that bill while disabled, IPv4 addresses that stopped being free, gateway endpoints that never took over, and cross-AZ transfer that names no service.
12 min readThree steps. Priced up front.
The engagement model and the price are the same three stages. No surprises, no scope creep.
Free diagnostic
FreeWe audit your architecture, costs, and delivery pipeline in 48 hours. You get a prioritized roadmap.
30-day sprint
From $8KI implement the plan myself. Weekly updates, working code, measurable outcomes.
Handover or retainer
CustomFull documentation and knowledge transfer. Or we stay on for the next sprint. Your call.
Scope or refund.
We agree on scope and timeline in writing before the sprint starts. If we miss the agreed deliverables, you get 100% of the sprint cost back and keep all code and IP.
- Scope locked in writing
- You own all code and IP
- 30-day warranty on every deliverable
One senior engineer.
AI-native delivery.
Mohamed Shehabeldin builds and ships the products himself, with an AI-native pipeline: Claude Code plus a 20-skill review system that does what a team used to. Eight years of production systems across petroleum, fintech, and IoT behind it. Youssef Hany and Hania Ayman come in for custom UI and design, like the FourseeDesign build. That is the whole roster, and it is deliberate: there is no bench to staff up from. Remote-first since 2020, registered in Estonia. You talk to the engineer who writes the code, because there is only one.
Meet the teamCommon questions.
Full-stack software development, AWS cloud architecture, cost optimization, DevOps, and consulting. We work best with teams that need senior-level execution on projects with clear outcomes. The 48-hour diagnostic is free; paid work starts at $8K for a 30-day sprint and scales to $50K-$500K for full delivery.
Still have questions? Book a call