Aaron Dsilva
Hands on CTO. Architecture, engineering, team, security and delivery, across healthcare, e-commerce and security.
I own the whole technology problem, from architecture down to the code. Eight years across healthcare (HIPAA, FDA, SOC 2), e-commerce and security: designing the architecture, writing production code, hiring and leading the team, passing the audits, and getting it shipped. Currently co-founder of The Lean Product Studio and CTO at Aplify.
In practice that has meant cutting a healthcare client's AWS bill by 33%, holding 99.9% uptime, and clearing FDA, HIPAA, SOC 2 and ISO 27001 audits without a single security incident. Most of the work sits in AI and RAG systems (Neo4j, Pinecone, Claude API), security remediation where findings get fixed in production code rather than written up in a report, and architecture built for industries that get inspected.
Delivered systems used by teams at King’s College London, Johnson & Johnson, and European hospital networks as a technical partner. AWS Certified Solutions Architect and Professional Scrum Master I. Based in Pune, India, serving global clients across US, Europe, UK, and Africa markets.
- — AWS Cost Optimization: cut a client's AWS bill by 33% through architecture optimization and right-sizing
- — Healthcare Scale: hospital organizations across the US and India with 99.9% uptime, zero security incidents, and FDA/HIPAA/SOC 2/ISO 27001 compliance
- — E-commerce Recovery: rebuilt a failing multi-vendor marketplace (constant crashes, broken UI) from scratch to 100% uptime and a modern Flutter/Node architecture
- — AI/RAG Production Systems: shipped 4+ healthcare AI systems including ambient clinical listening (AWS Comprehend Medical + Claude + Neo4j), MCP research servers, and HIPAA-compliant RAG pipelines used by teams at King’s College London and European hospitals
- — Security Leadership: led pen testing remediation implementing all security fixes in production code (React Native/Flask), built an ISO 27001 pen testing platform, and passed every audit (FDA/HIPAA/SOC 2/GDPR)
- — Team Leadership: built and led a distributed team of 10 engineers across time zones, shipping 6 products to production spanning healthcare, e-commerce, security, and research tools
Aplify · Chief Technology Officer (CTO)
- — Architect scalable e-commerce platform infrastructure supporting a multi-vendor marketplace model with real-time inventory, payments, and vendor management systems
- — Lead technical roadmap and engineering team structure, establishing development processes, CI/CD pipelines, and quality assurance standards
- — Build cloud-native architecture on AWS with a focus on cost optimization, security, and 99.9% uptime SLA for mission-critical e-commerce operations
- — Drive technical decision-making for mobile (React Native/Flutter), backend (Node.js), database (MongoDB/PostgreSQL), and cloud infrastructure choices
The Lean Product Studio · Co-Founder and Technical Lead
- — Shipped products used by teams at King’s College London and European hospital networks, delivered as a technical partner
- — Cut a client’s AWS bill by 33% through architecture and instance-level optimization: right-sizing EC2 instances, auto-scaling, and RDS optimization
- — Building a HIPAA-compliant AI ambient listening system for clinical documentation, currently in pre-deployment with hospital teams in the US and Europe: AWS Comprehend Medical for PHI extraction/anonymization, Claude API for summarization, Neo4j knowledge graphs for relationship mapping
- — Rebuilt a failing multi-vendor e-commerce marketplace from constant crashes to 100% uptime: complete Flutter mobile app rewrite, Node.js backend with MongoDB, vendor management dashboards, real-time inventory sync
- — Developed an ISO 27001-compliant pen testing workflow platform connecting security testers to development teams: NestJS backend, centralized vulnerability tracking, regression testing, remediation verification for enterprise clients
- — Created an MCP (Model Context Protocol) server for healthcare research, delivered as a technical partner to King’s College London and European hospital networks: real-time analytics, HIPAA-compliant data handling, GDPR consent management
- — Rebuilt a women’s health platform V2 (UK/Africa markets) in Flutter: cycle tracking, telemedicine provider connections, multi-language support (English, French, Swahili), GDPR compliance with right-to-be-forgotten implementation
OpsFuse Technologies Pvt. Ltd. · Senior Full-Stack Developer
- — Led pen testing remediation across the entire codebase: identified and fixed security vulnerabilities in the React Native mobile app and Flask backend, implemented all recommendations from third-party security audits, passed FDA/HIPAA/SOC2 compliance audits with zero critical findings
- — Architected AWS infrastructure for secure multi-tenant SaaS: PostgreSQL with Row-Level Security (RLS) for organization data isolation, encrypted data at rest and in transit, role-based access control (RBAC), audit logging for compliance
- — Achieved and maintained 99.9% uptime for hospital organizations across the US and India processing thousands of daily transactions: built monitoring and alerting systems, implemented disaster recovery procedures, automated backups with point-in-time recovery
- — Built HIPAA compliance into every layer: PHI encryption (AES-256), access controls, audit trails, disaster recovery, data retention policies, and incident response procedures passing SOC2 Type II and ISO 27001 audits
- — Developed mission-critical features for hospital workflows: offline-first mobile architecture for unreliable hospital networks, real-time data sync, patient data management, reporting dashboards, and administrative tools
Avegen · Mobile Developer
- — Architected a multi-tenant SaaS platform: complete data isolation between organizations, white-label customization through admin dashboards (logos, colors, features), zero-code configuration for new clients reducing onboarding from weeks to hours
- — Implemented GDPR compliance controls: data encryption at rest and in transit, user consent management, right-to-be-forgotten workflows, data portability, privacy-by-design architecture passing European regulatory requirements
- — Built an internationalization (i18n) framework supporting 10+ languages for European markets: English, German, French, Spanish, Italian, with right-to-left (RTL) support for Arabic, dynamic content translation, locale-specific date/time/currency formatting
- — Led the full product development lifecycle: requirements gathering with European healthcare clients, technical architecture design, React Native mobile development, Ruby on Rails API backend, PostgreSQL database design, AWS deployment, production monitoring
Kalyani Studio / Sense It Out · Full Stack & Technology Engineer
- — Full Stack Engineer, Kalyani Studio (Mar 2020 - Jun 2021): developed web and mobile applications using Laravel, PHP, and JavaScript frameworks
- — Technology Engineer, Kalyani Studio (Jan 2020 - Mar 2020): full-stack development with Laravel and IoT integrations
- — Technical Development Engineer, Sense It Out Intelligent Solutions (Aug 2018 - Jan 2020): built IoT solutions and web applications using PHP, Laravel, and cloud platforms
- — Intern, Sense It Out Technologies (Aug 2016 - May 2018): contributed to web development projects and learned full-stack engineering fundamentals
AI Clinical Documentation System
In development (pre-deployment): an AI clinical documentation system for hospital teams in the US and Europe. Processes physician–patient conversations to generate clinical notes while preserving patient privacy.
- — Stack: AWS Comprehend Medical (PHI extraction/anonymization), Claude API (summarization), Neo4j (knowledge graphs), Python, HIPAA-compliant AWS architecture
- — Compliance: built-in PHI anonymization, encrypted data pipeline, and audit logging
Multi-Vendor E-commerce Marketplace Rebuild
Rescued a failing multi-vendor marketplace plagued by constant crashes and poor UX. Complete rebuild from the ground up with modern architecture, reaching 100% uptime and significantly improved vendor and customer satisfaction.
- — Stack: Flutter (mobile apps), Node.js (backend), MongoDB, AWS, real-time inventory sync, payment gateway integration
- — Impact: crash rate reduced from daily to zero, app performance improved 300%, rebuilt UI/UX increasing conversion by 40%, vendor admin dashboards reducing support tickets by 60%
- — Features: multi-vendor onboarding, product catalog management, real-time inventory, payment processing, order tracking, and admin analytics
ISO 27001 Penetration Testing Platform
A SaaS platform connecting penetration testers to development teams for enterprise security workflows — centralized vulnerability tracking, remediation verification, and regression testing for ISO 27001 compliance.
- — Stack: NestJS (TypeScript backend), PostgreSQL (secure data storage), AWS, role-based access control, encrypted storage
- — Capabilities: automated regression testing that prevents re-occurrence of fixed vulnerabilities, and a centralized dashboard for real-time security-posture visibility
- — Compliance: ISO 27001-compliant architecture, audit trails, secure credential management, and encrypted communications
CTO / Head of Engineering, Technical Leadership, Team Building (10+ engineers), AWS Solutions Architecture, System Design, Multi-Tenant SaaS, Microservices
HIPAA, FDA 510(k), SOC 2 Type II, ISO 27001, GDPR, Penetration Testing Remediation, Security Architecture, Encryption (AES-256), RBAC, Audit Logging
RAG Pipelines, Neo4j (Knowledge Graphs), Pinecone (Vector DB), LangChain, Claude API, Gemini, OpenAI, AWS Comprehend Medical, Embeddings, MCP (Model Context Protocol)
React Native, Flutter (Dart), Offline-First Architecture, Real-Time Sync, iOS/Android Deployment, App Store Optimization
Node.js (Express, NestJS), Ruby on Rails, Laravel (PHP), Flask (Python), RESTful APIs, GraphQL, WebSockets, Microservices, Serverless (AWS Lambda)
AWS (EC2, Lambda, RDS, S3, CloudFront, API Gateway, CloudWatch, Comprehend Medical), Infrastructure as Code, CI/CD Pipelines, Docker, Kubernetes
PostgreSQL (Row-Level Security), MongoDB, Neo4j (Graph DB), Pinecone (Vector DB), Redis (Caching), MySQL, SQLite (Offline Mobile)
JavaScript / TypeScript, Python, Dart / Flutter, Ruby, PHP, SQL
Healthcare IT, E-commerce Platforms, Multi-Vendor Marketplaces, Security / SaaS, Telemedicine, Clinical Documentation, Disaster Recovery, Multi-Language / i18n
Agile / Scrum (PSM I), AWS Solutions Architect, DevOps, Test-Driven Development, Code Review, Technical Documentation