Dheerendra Rahul
Profile
Solution Architect with 25+ years of experience designing, modernizing, and rescuing large-scale distributed systems across Healthcare, FinTech, ERP, Retail, and AI-driven platforms. I treat software architecture as a system-thinking discipline — the same way banks, insurers, and supply chains do — and apply it to bring messy, expensive, hard-to-change platforms back to a clean, scalable, cost-controlled, secure, and AI-ready baseline.
I am a hands-on architect: I write the migration scripts, prove the new pattern in code, set up the deployment, and only then hand it to the team. Most engagements end with a smaller cloud bill, a smaller team needed to run the system, and a documented playbook for the next round of change.
Problem-Solution Framework
The six recurring problems I am brought in to solve, and how I approach each.
Scalability
Profile real usage first; right-size to the actual user base, not a hypothetical one. Identify the 3–5 services that truly need to scale horizontally; keep the rest as a tight monolith. Avoid premature microservice sprawl.
Legacy System Mess
Document the legacy first (often AI-assisted), draw the table-to-table and endpoint-to-endpoint mapping, then rewrite in slices behind a feature flag. Old runs while the new takes over module by module. Always reversible.
Cloud Cost Explosion
Scaling is not free. Measure cost-per-user before and after, kill components running for show, collapse over-fragmented services, set ceilings (auto-scale max, RIs, lifecycle policies). Typical: 60–90% reduction.
Security & Compliance
Reduce external surface area before adding controls. Replace third-party auth/email/search with in-process equivalents where the trade-off makes sense. Cookie-based permissions → JWT + server-side RBAC. Compliance as a phase, not an afterthought.
Integration Chaos
Design a clean integration boundary up-front: ROPC for service-to-service, OAuth2/OIDC for human, webhooks for outbound. Document every contract. New partners onboard in days, not quarters.
AI Adoption & Confusion
Use AI where it pays for itself (legacy code analysis, lead qualification, content drafting, support automation), and don't where it doesn't (deterministic transactions, billing, regulated decisions). Pair every LLM with a deterministic rule layer.
Core Architecture Expertise
Modernization & Migration
- Legacy → modern stack migrations: Java 6 → 21, .NET Framework → .NET 8, VB.NET → modern frameworks, Spring Boot → Python FastAPI
- AI-assisted code translation: VS Code plugins for legacy documentation, agent-driven module-by-module porting
- Database evolution tracking: auto-generated table-to-table mapping, change diffs registered into release notes
- Modular monolith from over-fragmented microservices (40 → 1 done at Inara; preserved boundaries for re-extraction)
Cloud & Cost Engineering
- AWS-native: EC2, EKS, RDS, S3, CloudFront, SES, SNS, KMS, ALB, Route 53
- Cost discipline: 85–90% infra reduction (Inara: $3.5–5.5K/mo → $340–545/mo)
- Auto-scaling design with explicit ceilings to prevent runaway costs
- CDN-first asset strategy (S3 + CloudFront) replacing managed CMS pods
Security & Compliance
- HIPAA, SOC 2 readiness: PostgreSQL RLS, field-level PHI encryption via AWS KMS, audit logging, vendor security review
- Multi-tenant SaaS isolation at schema, query, and row-level (RLS)
- Auth migration: cookie-based → JWT + server-side RBAC; ROPC for service-to-service
- OAuth2, OIDC, SAML/SCIM federation for enterprise SSO
AI Engineering
- Agentic AI: LangChain, LangGraph, custom agent loops with tool/function calling
- RAG pipelines: chunking, embeddings (OpenAI text-embedding-3), vector DBs (Chroma, pgvector, FAISS)
- Multi-provider LLM orchestration with fallback and cost/latency routing (OpenAI GPT-4o, Anthropic Claude, Google Gemini, AWS Bedrock)
- Prompt-engineering standards, regression evaluation harnesses, agent observability
- Conversational AI on WhatsApp Business Cloud API; voice agents (browser STT/TTS today, Twilio + Deepgram + ElevenLabs path planned)
Backend & Data
- Java: Spring Boot 3.x, Spring Cloud, WebFlux, JPA/Hibernate, Maven/Gradle
- Python: FastAPI, asyncio, SQLAlchemy async, Pydantic, Celery
- .NET: 4.x and 8.x, ASP.NET, EF Core, IIS deployment automation (WiX)
- Databases: PostgreSQL (RLS, tsvector, pg_trgm, JSONB), MySQL/SQL Server enterprise tuning, MongoDB, Neo4j, OpenSearch/Elasticsearch
- Event-driven: Apache Kafka, WebSockets, Server-Sent Events, idempotent consumers, DLQ
DevOps & Delivery
- CI/CD: Jenkins, GitHub Actions, Docker, Kubernetes, Helm
- Single-script installers (WiX + Python) replacing manual multi-step deployments — full uninstall/install/config-restore in one command
- Observability: structured logging, Prometheus, Grafana, Sentry
- Multi-environment promotion with feature flags and reversible rollouts
Featured Solutions
Each project is framed as Problem → Solution → Outcome. Stack and role stated up front.
Sales & Logistics Multi-Agent Platform — End-to-End AI Sales Pipeline
Stack: Python (FastAPI, LangChain, LangGraph), OpenAI / Claude / Gemini, WhatsApp Business Cloud API, Meta Ads API, Google Ads API, Zoho CRM, IndiaMART, Tally, Razorpay, AWS (S3, SNS), Twilio (planned)
Sales team works 9:30–6, half their time goes to qualifying leads instead of closing them. People leave; training cycles eat into output. Lead-to-cash takes too long and too much human glue.
- Marketing Agent — automated campaigns on Meta (Instagram + Facebook), WhatsApp, Google Ads, YouTube; auto-boosts reels and ads
- Lead Capture & CRM Sync — pulls leads from IndiaMART and Zoho on a schedule; deduplicates and normalises
- Lead Qualifying Agent — WhatsApp AI conversation with real-time product/pricing data; only warm leads escalate to humans
- Callback Voice Agent — calls back qualified leads, walks pricing, captures objections; every call transcribed and summarised by a second LLM
- Counter-Offer Engine — extends a pre-approved counter-offer if buyer hesitates; final logic is deterministic, not LLM-decided, to protect margin
- Bulk-Deal Closure Agent — for B2B bulk orders, computes the best-allowed counter-offer; escalates with full context
- Payment Link Generator — generates a payment link only after manual amount-verification
- Logistics Agent — gate-camera image, barcode scan, vehicle/porter photo, way-bill via Tally
- Live Tracking Agent — Porter live-tracking link sent to buyer; closes the loop on delivery
- Sales team focuses only on high-intent leads — qualifying time dropped to near zero
- 24/7 lead engagement (was 9:30–6 only); follow-up latency went from hours to seconds on WhatsApp
- Counter-offer logic kept deterministic so margin is preserved even when LLMs are creative
- Logistics handoff fully traced — image, barcode, way-bill, tracking link — with no manual data entry
Inara AI — Healthcare & Caregiving Platform Re-engineering
Stack: Python FastAPI, Next.js 15 (App Router, SSR), PostgreSQL (RLS, tsvector, pg_trgm), AWS (EKS → EC2, KMS, S3, CloudFront), Redis (replaced by TTLCache), Kafka (replaced by asyncio.Queue + APScheduler), Auth0 (replaced by JWT + bcrypt + pyotp)
40-microservice platform (Java/Go/Node, 500+ endpoints) burning $3.5–5.5K/mo to serve a real-world userbase of <5K. Long deployment cycles, test pyramid impossible to keep green, multiple databases (Neo4j, Postgres, Elasticsearch, MySQL), HIPAA gaps, no clear B2B story.
- Right-sized to actual usage (10–15K users target) — collapsed 40 services into a single FastAPI modular monolith with preserved service boundaries for future re-extraction
- Replaced heavy components with in-process Python equivalents — Auth0 → JWT+bcrypt+pyotp, Elasticsearch → PostgreSQL tsvector + pg_trgm, Redis → TTLCache, Kafka → asyncio.Queue + APScheduler, Neo4j → PostgreSQL recursive CTEs
- Removed Ghost CMS — moved to S3 + CloudFront for CMS delivery
- Authored Phase 7 HIPAA / SOC 2 plan: PostgreSQL RLS, field-level PHI encryption via AWS KMS, SAML/SCIM federation, external pen-test, vendor security review
- Converted to a B2B multi-tenant platform: 45+ per-organisation feature flags, 7-role / 58-permission RBAC, per-tenant theming and white-labeling, on-the-go onboarding
- Internationalisation including Arabic right-to-left layout
- Delivered using AI-accelerated / spec-based development — compressed a projected 1–3 month rewrite into focused multi-week sprints
- Infrastructure cost: $3.5–5.5K/mo → $340–545/mo (85–90% reduction)
- Engineering team needed to run the platform: 4–8 → 1–2 (75% reduction)
- Deployment time: hours → minutes (single container vs 40)
- Platform now sellable to organisations as a white-labeled B2B product
Jobscope CRM/ERP — Legacy .NET Modernization with AI-Assisted Migration
Stack: VB.NET → .NET 8, React (Vite + Axios + Redux), MS SQL Server, WiX Toolset, IIS, Python automation, AI agents for code translation
Legacy ERP shipped as a Windows installer; on-site DBA needed for every release; integration partners shared a single cookie-based session; oversized cookie containing every permission breaking the app; old VB.NET code with no documentation; client install took hours.
- Auth split for integration partners — ROPC flow for service-to-service; web-app sessions retained for human users; partners no longer need browser cookies
- AI-driven legacy → modern migration — VS Code plugin auto-documents legacy VB.NET; "Code Gini" agent emits .NET 8 + React equivalents; module-by-module parallel run until parity
- React performance fix — Axios + Redux replacing fetch sprawl; Vite for fast dev cycles; coarse-grained API replaced with focused endpoints
- Single-script installer + auto-config — Python+WiX builds and ships a fresh installer per run; auto-uninstalls old, restores config, opens admin UI on first start
- Database-change tracking & release notes — AI+Python tool diffs schema between releases; output flows into release notes automatically — DBA dependency removed
- JWT migration to fix cookie-bloat — cookie permissions moved to server-side RBAC; cookie shrinks to a single token; permission size no longer a request-size constraint
OffPeakBreak — India-Only Platform → Multi-Country (UK, US, Singapore, UAE)
Stack: Spring Boot 3.2, Java 17, MySQL, React, Razorpay (India) + Stripe (UK/US/SG/AE), AWS CloudFront (GeoIP), nginx, react-i18next
India-only travel booking platform (Razorpay, INR, English-IN, single domain). Wanted to expand to UK, US, Singapore, UAE on the same domain with country-specific content, pricing, payments, and SEO — without forking the codebase.
- URL pattern
offpeakbreak.com/{in,uk,us,sg,ae}/— single SSL cert, single deploy, country path prefix - GeoIP detection at CloudFront edge (free, accurate); cookie + manual switcher always available
- Country-wise multi-tenancy at the data layer — added
country_codeto all customer-facing tables; JPA aspect injects the WHERE clause automatically - Country and CountryConfig tables — adding a new country becomes a config change, not code
- Payment provider abstraction — Razorpay for India, Stripe for everyone else, future providers plug in cleanly
- User-identity and PII segregated in the schema — paves the way for in-country data residency without code changes
- i18n with react-i18next and per-country English variants (en-IN, en-GB, en-US, en-SG, en-AE); hreflang tags for proper Google country-targeting
- 5 countries live in 6–8 calendar weeks at ~10 person-weeks of engineering
- Forward-compatible migration — India site behaves identically until the multi-country flag is enabled
- Per-country data residency now achievable without downtime if compliance demands it later
- Per-country SEO ranking properties on Google Search Console from day one
Earlier Professional Experience
Inara Platform re-engineering, WhatsApp Sales Agent, Crimson getConnect migration, Jobscope modernization. Detailed in Featured Solutions above.
- RTS — competitive online exam app: Spring Boot microservices, JWT auth, real-time exam engine, scalable result analytics, AWS containerised deployment
- Institute Management System with online exam + GST simulator: REST APIs, modular exam engine, automated grading, role-based access
- E-commerce platform: catalog/cart/order/payment microservices, JWT, transactional order lifecycle, payment gateway, caching for high-traffic listings
- OffPeakBreak (hotel & event booking): B2B booking microservices, bidding engine for hotel owners (event-driven), advanced filtering + geo-search, on-prem → AWS migration
- Tap to Shop — plug-and-play e-commerce SDK: Java backend, JAX-RS + Spring REST, high-concurrency request handling, traffic-spike optimisation
- Inventory & Vendor Management: microservices for inventory + order, vendor lifecycle, Tally accounting integration, scalable barcode generation
- My Hi-Street-Shopping: modular Java backend, role-based REST services, transactional schema optimisation, payment + notification integration, AWS deployment
- Secure Society (Android/iOS): modular Java backend, role-based REST services, payment integration, AWS deployment
- Eureka m-Commerce (Android): scalable mobile-advertising backend, AI-driven targeting engine, event-driven campaign processing, real-time idle-screen engagement
- Imed-Go: REST services for GPS-based emergency alerting, real-time location handling, scalable backend for panic events, clustered HA deployment
- MediaMath (Project Manager): scalable Java backend for ad delivery, high-volume request processing, performance optimisation under heavy traffic, structured logging & monitoring
- Document Management System for Citi Bank (Project Lead): secure document upload APIs, encrypted storage, access control + audit trails, enterprise-grade compliance
- J2EE enterprise modules using EJB, JPA, Servlets
- Secure RESTful web services
- Oracle / SQL Server performance optimisation
- Clustered JBoss deployments
- Transaction management & ORM best practices
- Led small engineering teams & code reviews
Education
- MMS (Systems) — Devi Ahilya University, Indore (M.P.) — 1999
- B.Sc. (Mathematics) — Barkatullah University, Bhopal (M.P.) — 1997
- Higher Secondary — CBSE (M.P.) — 1994
- Secondary — CBSE (M.P.) — 1992