About
I'm Aaron Dsilva, a CTO based in Pune, India. I've spent eight years building production systems in places where mistakes are expensive: healthcare, e-commerce, and security.
Right now I run The Lean Product Studio with a distributed team of ten engineers, and lead engineering at Aplify, a multi-vendor e-commerce platform. Before that I built HIPAA-grade healthcare systems used by hospital organizations across the US and India, and mobile health products for the UK, Europe, and Africa.
As a technical partner, I've delivered systems used by teams at King's College London and Johnson & Johnson. I've passed FDA, HIPAA, SOC 2, and ISO 27001 audits without a security incident. These days most of my time goes into AI: I've shipped four production RAG systems and I'm currently building Clinvo, an AI-native EHR.
Aplify · Chief Technology Officer (CTO)
- — Architect scalable e-commerce platform infrastructure supporting a multi-vendor marketplace model with real-time inventory, payments, and vendor management systems
- — Lead technical roadmap and engineering team structure, establishing development processes, CI/CD pipelines, and quality assurance standards
- — Build cloud-native architecture on AWS with a focus on cost optimization, security, and 99.9% uptime SLA for mission-critical e-commerce operations
- — Drive technical decision-making for mobile (React Native/Flutter), backend (Node.js), database (MongoDB/PostgreSQL), and cloud infrastructure choices
The Lean Product Studio · Co-Founder and Technical Lead
- — Shipped products used by teams at King’s College London and European hospital networks, delivered as a technical partner
- — Cut a client’s AWS bill by 33% through architecture and instance-level optimization: right-sizing EC2 instances, auto-scaling, and RDS optimization
- — Building a HIPAA-compliant AI ambient listening system for clinical documentation, currently in pre-deployment with hospital teams in the US and Europe: AWS Comprehend Medical for PHI extraction/anonymization, Claude API for summarization, Neo4j knowledge graphs for relationship mapping
- — Rebuilt a failing multi-vendor e-commerce marketplace from constant crashes to 100% uptime: complete Flutter mobile app rewrite, Node.js backend with MongoDB, vendor management dashboards, real-time inventory sync
- — Developed an ISO 27001-compliant pen testing workflow platform connecting security testers to development teams: NestJS backend, centralized vulnerability tracking, regression testing, remediation verification for enterprise clients
- — Created an MCP (Model Context Protocol) server for healthcare research, delivered as a technical partner to King’s College London and European hospital networks: real-time analytics, HIPAA-compliant data handling, GDPR consent management
- — Rebuilt a women’s health platform V2 (UK/Africa markets) in Flutter: cycle tracking, telemedicine provider connections, multi-language support (English, French, Swahili), GDPR compliance with right-to-be-forgotten implementation
OpsFuse Technologies Pvt. Ltd. · Senior Full-Stack Developer
- — Led pen testing remediation across the entire codebase: identified and fixed security vulnerabilities in the React Native mobile app and Flask backend, implemented all recommendations from third-party security audits, passed FDA/HIPAA/SOC2 compliance audits with zero critical findings
- — Architected AWS infrastructure for secure multi-tenant SaaS: PostgreSQL with Row-Level Security (RLS) for organization data isolation, encrypted data at rest and in transit, role-based access control (RBAC), audit logging for compliance
- — Achieved and maintained 99.9% uptime for hospital organizations across the US and India processing thousands of daily transactions: built monitoring and alerting systems, implemented disaster recovery procedures, automated backups with point-in-time recovery
- — Built HIPAA compliance into every layer: PHI encryption (AES-256), access controls, audit trails, disaster recovery, data retention policies, and incident response procedures passing SOC2 Type II and ISO 27001 audits
- — Developed mission-critical features for hospital workflows: offline-first mobile architecture for unreliable hospital networks, real-time data sync, patient data management, reporting dashboards, and administrative tools
Avegen · Mobile Developer
- — Architected a multi-tenant SaaS platform: complete data isolation between organizations, white-label customization through admin dashboards (logos, colors, features), zero-code configuration for new clients reducing onboarding from weeks to hours
- — Implemented GDPR compliance controls: data encryption at rest and in transit, user consent management, right-to-be-forgotten workflows, data portability, privacy-by-design architecture passing European regulatory requirements
- — Built an internationalization (i18n) framework supporting 10+ languages for European markets: English, German, French, Spanish, Italian, with right-to-left (RTL) support for Arabic, dynamic content translation, locale-specific date/time/currency formatting
- — Led the full product development lifecycle: requirements gathering with European healthcare clients, technical architecture design, React Native mobile development, Ruby on Rails API backend, PostgreSQL database design, AWS deployment, production monitoring
Kalyani Studio / Sense It Out · Full Stack & Technology Engineer
- — Full Stack Engineer, Kalyani Studio (Mar 2020 - Jun 2021): developed web and mobile applications using Laravel, PHP, and JavaScript frameworks
- — Technology Engineer, Kalyani Studio (Jan 2020 - Mar 2020): full-stack development with Laravel and IoT integrations
- — Technical Development Engineer, Sense It Out Intelligent Solutions (Aug 2018 - Jan 2020): built IoT solutions and web applications using PHP, Laravel, and cloud platforms
- — Intern, Sense It Out Technologies (Aug 2016 - May 2018): contributed to web development projects and learned full-stack engineering fundamentals
Also completed (8)
RAG Pipelines, Neo4j (Knowledge Graphs), Pinecone (Vector DB), LangChain, Claude API, Gemini, OpenAI, AWS Comprehend Medical, Embeddings, MCP (Model Context Protocol)
HIPAA, FDA 510(k), SOC 2 Type II, ISO 27001, GDPR, Pen Testing Remediation, Encryption (AES-256), RBAC, Audit Logging
Node.js (Express, NestJS), Ruby on Rails, Laravel (PHP), Flask (Python), RESTful APIs, GraphQL, WebSockets, Microservices, Serverless (AWS Lambda)
AWS (EC2, Lambda, RDS, S3, CloudFront, API Gateway, CloudWatch, Comprehend Medical), Infrastructure as Code, CI/CD Pipelines, Docker, Kubernetes
PostgreSQL (Row-Level Security), MongoDB, Neo4j (Graph DB), Pinecone (Vector DB), Redis (Caching), MySQL, SQLite (Offline Mobile)
React Native, Flutter (Dart), Offline-First Architecture, Real-Time Sync, iOS/Android Deployment, App Store Optimization
JavaScript/TypeScript, Python, Dart/Flutter, Ruby, PHP, SQL
I'm open to co-founding conversations for the right product. If you're building something in healthcare or AI, get in touch.
Start a conversation ↗