I'm Aditya Chooramani — I ship full-stack applications on AWS and Azure, then turn around and attack them
until they hold. Writing the code and breaking the code are the same skill, pointed in opposite directions.
Each of these shipped, got measured, and got tested by someone trying to get in. Usually me.
Dustinel AI
Lead full-stack developer · 3-person team · Mar 2026
A worker-safety platform with real-time WebSocket dashboards and role-based access. React and Next.js on the
front, Node and Express behind it, GPT-4o and Azure AI Vision handling hazard assessment. Eighteen Azure
services provisioned through infrastructure-as-code, identity through Entra External ID, and not one
hardcoded credential in the tree.
A Flask API with eight security bugs planted in it deliberately, pushed through a CI/CD pipeline gated by
Gitleaks, Semgrep, Bandit, Trivy, Checkov and OWASP ZAP — to find out which bugs the scanners catch and which
ones sail straight through. A companion branch fixes every finding. It's the honest version of a security
pipeline: here is exactly what automation misses.
Lead backend & cloud developer · 3-person team · Feb 2026
A geospatial analytics backend on AWS: REST endpoints over MySQL, automated ingestion pipelines out of S3,
and event-driven SNS alerting on infrastructure change. Least-privilege IAM from the first commit rather than
bolted on afterwards.
Maritime monitoring, built for Smart India Hackathon's national security track. A Django backend swallowing
high-frequency sensor data, parsing unstructured hardware payloads into clean REST responses, and holding up
through field testing. It took the team to the national grand finals.
99%uptime in field testing
Top 2%of national entries
PythonDjangoPostgreSQLRESTHardware integration
Falter — network hardening
Open-source contribution · Freifunk Berlin
A merged contribution to the Falter mesh-networking ecosystem: a UCI-to-Bird2 configuration translator in C
and shell that shrinks attack surface on OpenWrt nodes, with tamper triggers and RAM-backed volatile
execution. Someone else's codebase, real maintainers, real review.
I'm a final-year BCA student in Mathura, and I've spent most of it running the same loop: build something
real, deploy it properly, then sit down and try to get past my own authentication.
It started as curiosity and turned into a method. Since school I've wanted to know how attackers break
websites, and that pulled me into building things and then breaking the things I build. The gap is what I care
about — the one between it works and it holds.
So I do both sides. I ship full-stack applications on AWS and Azure, then run them through the same scanners,
the same proxy and the same assumptions an attacker would. Completed Practical Ethical Hacking with TCM
Security; currently working through PortSwigger's Web Security Academy.
Based inMathura, India
DegreeBCA · 2027
Average75%
CertifiedPEH · TCM Security
StudyingPortSwigger Academy
Writing atdev.to
Contact
Got something that needs building — or testing?
I read everything that lands in my inbox and reply to the ones that are real. Tell me what you're working on.