Abdul Rehman A.
AI SaaS Architect | Azure & AWS | DevOps Engineer
I build and secure AI-powered SaaS platforms that handle regulated data, the kind where a mistake isn't a bug, it's a breach notification. Most recently I've been technical lead on a HIPAA-oriented telehealth platform: AI-generated clinical notes from session transcripts, Microsoft Teams integration, Stripe billing, and end-to-end data residency between Canadian and US regions. What I do: Compliance-grade architecture. HIPAA, PHIPA and PIPEDA controls built into the system rather than bolted on afterwards. Audit trails, retention policies, PII scrubbing before data reaches any AI model, and data residency enforced in code so it cannot silently fail. Security engineering. I run full application security audits, then make the findings impossible to reintroduce. Automated CI gates that block unauthenticated routes, cross-tenant access bugs, leaked secrets and vulnerable dependencies before they ever merge. Cloud and DevOps. Azure and AWS: managed databases, object storage, secrets management, identity and access. CI/CD pipelines with federated authentication and deployment gates, so releases are gated on tests and security checks rather than on someone remembering. AI integration that's safe to ship. Azure OpenAI, transcription pipelines, and PII anonymisation, so sensitive content is scrubbed before it reaches a model. How I work: I verify claims rather than assume them. When I tell you something is fixed, I'll tell you how I confirmed it, and if I couldn't confirm it I'll say that too. Most production incidents I've dealt with came from something that looked correct and was never actually checked. Stack: TypeScript, Node.js, Express, React, .NET, Azure, AWS, Docker, GitHub Actions. If you're building something where security and compliance aren't optional, I'd like to hear about it.