All work
Case study · NDA — details on request
Financial analysis and financing platform for small businesses
A rewrite of a live fintech product: statement analysis with 14 ratios and a score, a catalogue of 595 loan offers from 31 banks, report import from tax forms, and an AI consultant that only explains numbers the engine computed.
- Client
- Fintech product for small businesses (Uzbekistan)
- Role
- Architect & lead engineer of the rewrite
- Timeline
- Rewrite · on staging, migration in progress
- Stack
- PythonFastAPIPostgreSQLRedisSQLAlchemyReact RouterTypeScriptOpenAIDocker
Problem
The first version, built without a real backend, had reached its limits: business logic lived in the browser, the scoring engine could not be verified, and every new feature risked silently changing results users had already seen.
The rewrite had to move to a proper backend without changing a single score for existing users.
Approach & architecture
- Audited the old system first, then wrote 14 design documents: architecture, data model, backend and frontend specs, the engine port plan, security and compliance, and step-by-step implementation plans.
- A layered FastAPI backend (api / core / domain / infra / jobs) over PostgreSQL, Redis for caching and rate limits, and a server-rendered React frontend.
- Report import from the platform's Excel template, from official tax forms (Excel or PDF, matched by line code) and from scanned documents read by AI.
- The AI consultant sits behind a provider interface and never calculates: it explains numbers the engine already produced, and the product works fully without it.
Result
- The ported scoring engine matches the original on a 10,000-case parity corpus — 100% identical results.
- Analysis without sign-up, financing matching, a project marketplace with moderation, regional statistics and exchange rates — in three languages.
What made it robust
- CI runs ruff, mypy in strict mode, migration checks, the parity job, pytest with a coverage floor, a dependency audit and secret scanning.
- Argon2id passwords, rotating refresh tokens with theft detection, a full set of security headers, IP hashing and log masking.
- 11,500+ backend test cases (with parametrisation) and 170+ frontend tests.
Have a similar problem?
Tell me about it — I'll reply with an honest view of scope, approach and what a first milestone could look like.