Curriculum Vitae

Resume

Software and AI systems work across multi-agent platforms, secure backends, developer tooling, and production products. This page is the source of truth. Use Download PDF to print or save this CV.

Email

Hamza Hafeez

Software and AI Systems Engineer

Lahore, Pakistan·Remote-ready · Open to relocate

Summary

I design and ship production software at the intersection of multi-agent AI, backend systems, and application security. My work ranges from research on executive-control architectures to live products with billing, auth, observability, and developer tooling. I care about systems that are measurable, operable, and honest about their trade-offs.

Focus

AI systems

Multi-agent pipelines, LLM routing with fallbacks, evaluation/judgment loops, RAG, and chat orchestration with intent routing and token budgets.

Backend

Go and FastAPI services, PostgreSQL with RLS, Redis caching and Pub/Sub, WebSockets, async workers, multi-tenant schemas, API design.

Security

OWASP/CWE-oriented analysis, SAST integrations, sandboxing, secure auth, webhook verification, audit logging, and local-first security tooling.

Product delivery

End-to-end ownership from architecture to production: Next.js apps, SDKs, billing, CI/CD, docs, and client delivery across multiple countries.

Experience

Founder and Software Engineer

Histeeria

June 2026 to PresentLahore, Pakistan

Python · TypeScript · FastAPI · PostgreSQL · Redis · LLM APIs · SDKs

  • Building trust infrastructure for AI agents: SDK ingest, async evaluation, dashboards, alerts, reports, and public agent profiles.
  • Implemented a three-tier judgment pipeline: rule-based checks, LLM judge, and adjudicator scoring across eight dimensions.
  • Shipped zero-dependency client SDKs on PyPI and npm, with a FastAPI backend and multi-tenant schema.
  • Pivoted from an earlier social-platform direction (Asteria) into agent observability and runtime evaluation.

Founder and Chief Engineer

Cortex EDR

Jan 2025 to presentLahore, Pakistan

Next.js 15 · TypeScript · Supabase · NextAuth · Paddle · Multi-provider LLM routing

  • Built a multi-agent security auditing platform (~29k lines of TypeScript) that scans GitHub repositories and produces scored, CWE/OWASP-classified reports.
  • Designed a 7-agent sequential pipeline: recon, security, architecture, quality, debt, AI-pattern detection, and orchestrator synthesis with shared scan memory in PostgreSQL.
  • Implemented provider-agnostic AI routing with fallbacks (OpenAI, OpenRouter, Gemini, Groq, DeepSeek), usage logging, and tier-gated model selection.
  • Shipped Cortex Chat: intent classification, scoped context retrieval, token-budgeted compression, tool loops, and sanitization for post-scan codebase Q&A.
  • Delivered production SaaS surfaces: auth, RLS, Paddle billing, PDF reports, CI/CD (lint, typecheck, build, CodeQL), and Railway deploys.

Software Engineer

Upvista Digital

Jan 2025 to PresentLahore, Pakistan · Remote International

Go · FastAPI · Next.js · PostgreSQL · Redis · Docker · Cloud

  • Delivered full-stack and AI systems for clients in Japan, the United States, Germany, New Zealand, Singapore, and Pakistan.
  • Own technical discovery, architecture, implementation, and production handoff as the primary engineering contact.
  • Build multi-tenant backends, secure APIs, and cloud deployments using Go/FastAPI, PostgreSQL, Redis, and Docker.

Engineer

Cortex Attack

Jan 2026 to March 2026Lahore, Pakistan

TypeScript · Node CLI · Docker · nmap · nikto · semgrep · trivy · Ollama

  • Built a terminal-native security orchestration engine that coordinates host scanners and falls back to Docker when tools are missing.
  • Runs a local-first, non-destructive audit pipeline: service discovery, route discovery, header analysis, vuln scan, dependency audit, attack-graph reasoning, and remediation narrative.
  • Supports local Ollama models by default, with optional OpenAI/Anthropic providers for deeper exploit-path analysis and code patches.
  • Available on npm (https://www.npmjs.com/package/cortex-attack) use 'npm install -g cortex-attack' to install

Engineer, Architect, & Creator

Anya

March 2026 to June 2026Lahore, Pakistan

TypeScript · Python · NATS · WebSockets · CV · TTS/STT · Memory systems

  • Building an open-source companion-robot OS that combines perception, memory, cognition, and expressive behavior.
  • Designed an event-driven NATS architecture so subsystems stay in continuous communication without blocking each other.
  • Used practical hardware constraints: Raspberry Pi as onboard compute, phone as sensors and face.

Founder and Engineer

Asteria (early Histeeria)

Sep 2025 to Jan 2026Lahore, Pakistan

Go · Next.js · Flutter · PostgreSQL · Redis · WebSockets · E2EE

  • Built a privacy-first social platform spanning Go backend, Next.js web, and Flutter mobile with end-to-end encrypted messaging.
  • Designed for high concurrency: Redis Pub/Sub for multi-instance WebSockets, async workers, feed caching, and modular-monolith boundaries.
  • Implemented OTP/OAuth auth, real-time messaging, feeds, statuses, notifications, and GDPR-oriented data export paths before pivoting the company thesis toward AI agent trust.

Research

Project Cortex: A Prefrontal-Cortex-Inspired Orchestrated Architecture for Artificial General Intelligence

Self-published research article · 36 pages · reviewed by 57 researchers

Nov 2025
  • Proposed an executive-control architecture for multi-agent systems: orchestrator, specialized agents, shared memory, risk evaluation, and hierarchical task decomposition.
  • Applied the same model in production systems such as Cortex EDR, where agents map to narrow functions and an orchestrator synthesizes shared working memory into a final report.

Skills

Languages

Go · TypeScript · Python · SQL · C# · Dart

Systems and backend

FastAPI · Gin · Next.js · PostgreSQL · Redis · NATS · WebSockets · Docker · CI/CD · Distributed systems

AI systems

Multi-agent pipelines · LLM routing and fallbacks · LangGraph / LangChain · RAG · Runtime evaluation · Prompt contracts and structured output · Usage and cost observability

Security

OWASP / CWE analysis · SAST · Semgrep · Secure API design · AuthN/AuthZ · RLS · Webhook verification · Local-first security tooling

Delivery

System architecture · Technical scoping · SDK and CLI packaging · Billing and multi-tenant SaaS · Client delivery · Documentation

Education

BS, Computer Science

National University of Modern Languages

Won 5 hackathons

Sep 2024 to April 2028