Open to new projects
Practice

How I engineer software.

The same eight stages on every project, from the first conversation to years of running. Each one lists the practices I use and a project where you can see them.

01

Idea

Start with the problem, not the code.

I talk to the people who will use it and write down the one job it has to do. Then I cut the first release down to what proves the idea.

  • Problem interviews
  • User stories
  • First-release scope
  • Success measures
  • Cost and timeline
  • Risks up front
You get
A one-page brief: problem, users, first-release scope and estimate.
Seen in
PhotoDrop, ErrandGo
Idea evidence
PhotoDrop began as one problem: guests waiting days for event photos. The first release did one thing. Scan a QR code, see your photos.
02

Design

Settle the hard parts on paper first.

Data model, system architecture, API contracts and screen flows, before the first line of code. Multi-tenancy and payments get designed early, because they are expensive to change later.

  • Data modelling
  • Architecture diagrams
  • API contracts (OpenAPI)
  • Multi-tenant design
  • Screen flows
  • Payment flows
You get
An architecture diagram, a data model and API documentation.
Seen in
PhotoDrop, Prepaid Water Vending
Browser / appweb or phone APINode · TypeScript Object storageS3 · photos, zips PostgreSQL Redis queueBullMQ Workersphoto · video · zip upload goes straight to storage
PhotoDrop's architecture. Uploads go straight from the browser to storage, so the API never carries the files. Workers scale on their own.
03

Build

Code the next engineer can pick up and own.

I use the stack that fits the job. Laravel or plain PHP for business systems, Node and TypeScript for real-time and media, Django for data-heavy work, React and Flutter for the front end.

  • Service and policy layers
  • Versioned migrations
  • Code review
  • Modules switched per client
  • Setup scripts safe to re-run
  • Docs written alongside
You get
Source code in your repository, a README and a setup that works first time.
Seen in
HR & Payroll Platform, SmartPOS
Build evidence
HR & Payroll: 129 models and 210 migrations, with modules switched on per client business.
04

Test

Money, permissions and data get tested first.

Automated tests cover the rules that cost the most when they break: payroll, payments, who can see what, and one client's data staying out of another's.

  • Feature tests on business rules
  • Tenant isolation tests
  • Slow-query regression tests
  • Seeded test data
  • Payment callback tests
  • Acceptance runs with users
You get
A test suite that runs on every change.
Seen in
ErrandGo, HR & Payroll Platform, ISMS Station Management
$ php artisan test

PASS  Tests\Feature\BusinessRoleScopingTest
PASS  Tests\Feature\EmployeePortalScopingTest
PASS  Tests\Feature\EntitlementUnifiedFormulaTest
PASS  Tests\Feature\LeaveApplicationLifecycleTest
PASS  Tests\Feature\BiometricDeviceAttendanceTest
PASS  Tests\Feature\ClientImpersonationTest
PASS  Tests\Feature\CustomRoleBuilderTest
…
# 100 feature test files · HR & Payroll platform
Tests that check each business only sees its own employees, leave follows its rules, and biometric clock-ins land on the right person.
05

Deploy

Releases should be boring, on purpose.

Every change goes through the same automated path to production. Servers, workers and scheduled jobs are set up the same way each time and written down.

  • GitHub Actions CI/CD
  • AWS EC2 and S3
  • nginx and Apache
  • Cloudflare in front
  • Docker for test stacks
  • PM2, systemd, Supervisor
You get
A repeatable, documented deployment you can hand to anyone.
Seen in
Prepaid Water Vending, Kazi-chapchap, PhotoDrop
name: CI & Deploy   # water vending frontend
on:
  push: { branches: [main] }

jobs:
  build-and-deploy:
    runs-on: ubuntu-latest
    steps:
      ✓ checkout
      ✓ setup node 20        npm ci
      ✓ build                npm run build
      ✓ deploy               rsync → AWS EC2
      ✓ restart apache
Every push to main builds the water vending dashboard and ships it to AWS EC2. No one copies files by hand.
06

Secure

Designed in from the start, then checked.

Access rules, login protection and payment safety are part of the design. They aren't a patch before launch. Where the law applies, like Kenya's Data Protection Act, the system is built to meet it.

  • Role-based access
  • Two-factor login
  • Rate limits and lockout
  • Secure headers (CSP, HSTS)
  • Token rotation, reuse detection
  • Encrypted payment keys
  • Audit logs
  • Verified M-Pesa callbacks
You get
A system that protects your users' data and your money.
Seen in
ISMS Station Management, MtaaLex Platform, HR & Payroll Platform
$ curl -I https://pos.tafity.com

strict-transport-security: max-age=31536000; includeSubDomains
content-security-policy: default-src 'self'; …
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
referrer-policy: strict-origin-when-cross-origin
permissions-policy: geolocation=(), microphone=(), payment=()
Live response headers from SmartPOS. Browsers are told to use HTTPS only, block framing and load nothing from unknown sources.
07

Scale

Measured under load, then tuned.

I don't guess at capacity. I build a throwaway copy of the system, hit it with realistic traffic, break parts of it on purpose, and fix what gives way.

  • Load and resilience tests
  • Queues and workers
  • Direct-to-storage uploads
  • Indexes, slow-query logs
  • Caching
  • Independent scaling
You get
Known limits, and a system that stays up on your busiest day.
Seen in
PhotoDrop, ISMS Station Management
ScenarioLoadResult
owner10kOne photographer uploads 10,000 photosGallery and downloads hold at 10k
read100k110,000 photos in one eventGallery reads stay paged and fast
crowd200 guests uploading, 1,000 viewingGuest uploads jump the queue
resilienceKill API and worker, restart Redis, freeze PostgresRecovers with no lost photos
bulk20,000-row import~1 min → a few seconds
capacity12-second video clips6 → 9.7 per minute (+62%)
PhotoDrop's load-test suite runs against a disposable Docker stack. Every scenario resets its own database and storage.
08

Maintain

I stay after launch.

Software keeps changing after it ships. Tax rules change, clients ask for new modules, payments need reconciling. I keep systems current and keep them honest.

  • Migrations and backfills
  • M-Pesa reconciliation jobs
  • Retries with backoff
  • Backups
  • Health checks, monitoring
  • Runbooks
You get
A system that keeps working, and an engineer who answers.
Seen in
HR & Payroll Platform, SmartPOS, Prepaid Water Vending
250commits over 14 months
12of 14 months with active changes
Commits per month on the HR & Payroll platform (whole team), from launch to today.
Engineering disciplines

What I bring to every system.

The practices that cut across every stage, each with a project that shows it working.

Performance

10,000photos per event, load-tested

I measure first, then fix the slowest thing. Heavy work goes to background queues so pages stay quick.

Load testsQuery tuningCachingBackground jobs
Proof: PhotoDrop

Security

2FAaudit logs, role-based access

Least privilege by default. Every login, change and payment leaves a trail you can check.

RBACSecure headersRate limitsEncryption at rest

Scalability

Multi-tenantone codebase, many businesses

Built so the tenth client costs almost nothing to add. The API and workers scale separately.

Tenant isolationPer-client modulesStateless APIsWorker pools

Reliability

Retrieswith exponential backoff

Networks fail and payment callbacks arrive twice. The system expects both and recovers without anyone stepping in.

Idempotent callbacksStuck-job recoveryHealth checksGraceful shutdown

Testing & quality

227automated tests on ErrandGo

Tests guard the rules that matter, and catch slow database patterns before users feel them.

Feature testsUnit testsQuery-count checksCode review

Payments & integrations

M-PesaSTK, C2B, payouts, reconciliation

I connect software to the real world: mobile money, SMS, WhatsApp, prepaid meters, biometric clocks and receipt printers.

DarajaStronpowerAfrica's TalkingZKTecoESC/POS

AI engineering

400+receipts read by AI

AI where it saves real work: reading receipts and CVs, drafting reports, answering questions over company data with a human approving any change.

GeminiOpenAIClaudeMCP agentsSwappable providers

Observability

Logsstructured and searchable

When something goes wrong I want to know before the client calls. Structured logs, slow-query logs and admin health dashboards.

Structured loggingSlow-query logsHealth endpointsAdmin monitoring
Toolbox
Languages
  • PHP
  • TypeScript / JavaScript
  • Python
  • Dart
  • SQL
Frameworks
  • Laravel
  • Django, DRF
  • Node, Express, Fastify, NestJS
  • React
  • Flutter, React Native
Data
  • MySQL, MariaDB
  • PostgreSQL
  • MongoDB
  • Redis
  • Prisma, Eloquent
Infrastructure
  • AWS EC2, S3
  • Docker
  • nginx, Apache
  • Cloudflare
  • GitHub Actions
Integrations
  • M-Pesa Daraja
  • Paystack, Stripe, Pesapal
  • Africa's Talking, WhatsApp
  • Gemini, OpenAI, Claude
  • Biometrics, ESC/POS
Contact

Have an idea or a system to build?

Tell me what you need. I'll reply within a day with questions, a rough approach, or a time to talk.

Phone+254745600377
Based inNairobi, Kenya · working worldwide
What do you need?