Full Stack Engineer & Tech Lead | TypeScript, React, Next.js · Node (Hono, Express) · Python/Django · PHP/Symfony
I build and run production systems for real businesses: a Mexican non-bank lender (SOFOM), a Bay Area delivery company, an SF e-commerce site and a SaaS for veterinary clinics. Most of my time goes to shipping features, hardening security, keeping things observable, and writing runbooks other people can execute.
Loan-origination platform for payroll-deduction lending: credit applications, contract PDF generation, biometric identity verification (national-ID OCR, facial liveness), MFA/OTP, and legally binding document signing. Private repos; ~2,800 commits across 20+ services since Feb 2025.
Stack: React 18/19 · Vite · Node 22 · Hono 4 · Drizzle ORM · Python/Django 3.2 · PHP 8.2/Symfony 7 · MySQL 8 · PostgreSQL 15 · AWS (S3, EC2) · Docker · MediaPipe · Vitest · Playwright · PHPUnit/PHPStan
Highlights:
- Leading the migration of a Django + PHP backend to a TypeScript API (Hono + Drizzle) against the same databases, verified with shadow tests that replay real requests side by side
- Built a PDF document engine on
pdf-lib(overlay/stamp, idempotent markers, barcodes, biometric signature stamps) replacing DOCX/reportlab templating - Facial liveness app with MediaPipe, embedded via iframe in the main SPA; national-ID OCR and verification flows
- Planned and coordinated the production migration from a self-hosted VPS/PaaS to AWS (S3 mirror, DB migration, VPN, staged cutover), executed by the client's ops team from our runbooks
- Security hardening after an intrusion: safe model registry instead of dynamic code execution, host IDS + honeypot, WAF with IP bans, CSP, CORS/authz lockdown, MFA/OTP, PDF sanitization
- Observability: Prometheus/Grafana/Loki/Alertmanager stack, Sentry/GlitchTip across 6 apps, custom health dashboard
- Scale in production: 24K+ credit applications, 95K+ attached documents, 30K+ national-ID verifications and 2,100+ digitally signed contracts in 2026 alone, used daily by ~140 advisors across 90 branches
- Mentoring a small dev team (1:1s, PR review, requirements refinement with the Scrum/BA side)
On-demand courier and catering delivery platform for the Bay Area (Food Safety and HIPAA certified). Lead developer since May 2025; ~1,400 commits, currently at v2.7.0.
Stack: Next.js 15.5 · React 19 · TypeScript 5.9 · Prisma 6 · Supabase (Postgres + Auth) · Stripe · Sanity CMS · Twilio · Resend · Mapbox · Cloudinary · Upstash Redis · Sentry-compatible tracking (GlitchTip) · Jest 30 · Playwright
Highlights:
- Driver app: GPS tracking, shift management, delivery state machine, idempotent shift starts
- Catering integrations (ezCater, CaterValley) and a partner API with authenticated endpoints
- Delivery pricing calculator, role-based access control, admin task boards
- Security sweeps (auth on all API routes, path-traversal removal, weekly
pnpm audit+ CodeQL) - CI/CD: release-please versioning, multi-arch Docker images on GHCR, self-hosted on Dokploy, daily
pg_dumpbackups with retention
E-commerce and catering platform for a San Francisco specialty food business. ~900 commits since March 2025.
Stack: Next.js 15.5 · React 19 · TypeScript 5.9 · Prisma 6 · Supabase · Square (payments + catalog) · Shippo · Resend + React Email · Google Maps · Mixpanel · Upstash Redis · Sentry · Jest 30 · Playwright + axe-core · Lighthouse CI
Highlights:
- Square as source of truth: catalog/inventory sync, webhooks, cron queues, payment processing
- Shippo shipping and database-backed delivery zones for catering
- Accessibility and performance gates in CI (axe, Lighthouse, bundle-size baseline)
- Weekly DB backups and security audits that auto-open tracking issues
- Diagnosed and fixed a production outage caused by a cron job disconnecting the shared Prisma client
Multi-tenant SaaS for veterinary clinics: scheduling, medical records, billing. ~850 commits, currently at v1.11.
Stack: Next.js 15.5 · React 19 · Prisma 6 · Kinde Auth · Stripe + Square · FullCalendar · Sentry · Playwright
Highlights: subscription billing in local currency (MXN/CLP/COP/USD), trial lifecycle emails, tenant onboarding, PWA install flow, weekly E2E smoke suite.
- Full stack TypeScript: Next.js App Router (Server Components, Server Actions), React 18/19 SPAs with Vite, Node APIs with Hono and Express, Zod validation end to end
- Legacy modernization: porting Django and PHP services to TypeScript against live databases, with shadow testing and behavior-parity gates instead of big-bang rewrites
- Payments and commerce: Stripe subscriptions and multi-currency billing, Square payments and catalog sync, Shippo shipping, order lifecycles with webhooks and queues
- Identity and documents: biometric liveness (MediaPipe), national-ID OCR, MFA/OTP over SMS and WhatsApp, PDF generation and digital signing
- Security: authz lockdowns, CSP, WAF and IDS, credential externalization, dependency audits and CodeQL in CI, incident response with commit-level timelines
- Operations: AWS migrations, Docker self-hosting (Coolify, Dokploy), Prometheus/Grafana/Loki, Sentry/GlitchTip, automated DB backups with retention, disaster-recovery plans
- Quality: Jest, Vitest, PHPUnit, Playwright (including accessibility and visual checks), PHPStan, coverage thresholds enforced in CI, release-please and Conventional Commits
- Runbooks as a deliverable: when someone else runs production, the numbered steps, idempotent scripts, verification criteria and rollback plan are the product
- Conventional Commits, CHANGELOGs and semver across every repo I touch
- Tests before push, CI as the gate: lint, typecheck, unit, E2E, security audit, build checks
- Observability first: every app reports errors with fingerprints and has a health endpoint before it ships
- Small team leadership: dailies, 1:1s, PR reviews, written agreements, and requirement refinement before code starts
- Email: emmanuel@alanis.dev
- Website: www.alanis.dev
- Location: Mexico · open to remote work
Open to: full-time positions, contract work, and interesting collaborations in financial services, logistics, e-commerce and SaaS.



