Hashim Ruan

Brand, website, app and security · Anguilla, UTC−4

From idea to published app, built to survive contact with production.

I take founders from a sketch to a brand, a website and an app on the App Store, then attack what I built from HeliusOS and hand you the report. Two of my own encrypted apps went through exactly that process. You can install them right now.

Day rate
US$500
Contracting via
Helius Network Ltd, UK
Overlap
London PM & New York AM
Hashim Ruan, security consultant, Anguilla
Hashim Jordon Ruan Founder & CTO, Helius Network Ltd · CTO, Versatech

How I work · one person, start to finish

From an idea on a napkin to an app on the App Store.

Brand, website and app, built by the same person who will later have to defend them. Seven stages, each with a named deliverable, a fixed scope and a point where you can stop, and your code, IP and data protected the whole way. Scroll, or pick a stage.

01

Discover

One week · fixed price · you can stop here

What are we actually building, for whom, and what would make it dangerous?

Before any pixels, a working week together. We write down the product in plain language, draw the first threat model next to the first user journey, and decide what version one must do and what it must refuse to do. If you have minors, payments or private messages anywhere in the idea, this is where that gets designed in rather than bolted on.

You get
  • Product brief and scope, in one document
  • Threat model, version one
  • NDA signed, Helius Connect set up as our channel, your repository created
  • Architecture sketch and stack decision
  • A fixed quote for every later stage
You can stop here with
  • A plan any competent team can build from
  • An honest answer on whether the idea needs an app at all
02

Brand

One to two weeks · fixed price

A name people can say, a mark they can recognise, and a voice that sounds like you.

Identity work done with the product in view, so the brand survives the move from a landing page to an app icon to an App Store listing. Colour, type and tone are set as a system, not a mood board, which means the website and the app will look like they belong to the same company six months from now.

You get
  • Logo, wordmark and app icon in every size Apple and Google ask for
  • Colour and type system with accessibility contrast already checked
  • A short brand sheet: voice, dos and do nots
  • Social and App Store listing assets
Already have a brand?
  • Skip this stage. I will work inside yours and tell you where it will strain on a small screen.
03

Design

Two to three weeks · fixed price

Every screen, every state, clickable on your phone before a line of code exists.

The website and the app are designed together. You get a prototype you can hand to a friend and watch them use. Empty states, error states, what a user sees when the network drops on a ferry: all designed, because those are the screens that decide whether people trust the product.

You get
  • Clickable prototype of the app and the website
  • Design system: components, spacing, motion
  • All copy written, including onboarding and consent flows
  • Accessibility pass against WCAG 2.2 AA
Security is in the design
  • Age gates, permissions prompts and recovery flows are designed here, where they are cheap to change
04

Build

Four to ten weeks · fixed price per milestone · weekly demo

Built secure by construction, demonstrated to you every week on a real device.

The same stack I ship my own products on: React Native and Expo for iOS and Android, a fast static or server-rendered website, Supabase or an equivalent backend with row level security written and tested policy by policy, and encryption that fails closed. Anything with money or identity in it lives server-side. You get a TestFlight build every Friday and the source lives in your repository from day one.

You get
  • Working builds on TestFlight and a password-protected staging website, weekly
  • Source code in your own GitHub organisation, with CI
  • Automated audit scripts that gate every release
  • Plain-English changelog each week
What I will not do
  • Ship a client-side ledger, a self-declared age gate, or a secret in the app bundle, however much faster it would be
05

Harden

One to two weeks · fixed price · also sold on its own

Before launch, I attack what I built, from HeliusOS, and write up everything I find.

This is the stage most studios skip, and the one I would do even if you asked me not to. The finished app, website and backend go through a full assessment from HeliusOS, the hardened operating system I built at Helius for exactly this work. You get an extensive written report, every finding gets fixed, and the fixes get retested. If you already have a product built by someone else, this stage on its own is where we start.

You get
  • The full assessment report, typically 40 to 80 pages
  • Executive summary for your board or investors
  • Every finding fixed, with a retest letter you can show a customer
  • Evidence pack for insurers, auditors and security questionnaires
06

Launch

One to three weeks, mostly waiting on Apple · included

Through App Store review, onto your domain, with the headers and monitoring already in place.

I have taken two security-critical apps through Apple review and been rejected enough times to know what the reviewer is actually asking for. Listing, screenshots, privacy labels, review notes and the demo account are prepared before submission, not after the first rejection. The website goes live with a strict content security policy, HSTS, and the same configuration this site scores A on.

You get
  • App live on the App Store and Google Play
  • Website live on your domain, with DNS, certificates and headers done
  • Launch checklist, runbook and credentials handover
  • Monitoring and error reporting switched on
If Apple rejects it
  • That is my problem, not yours. Resubmission is included until it is approved.
07

Care

Monthly · from US$350 · cancel any month

Someone who built it, keeps it patched, and answers when it breaks.

Dependencies move, operating systems update, certificates expire, and a library you never heard of gets a critical CVE on a Friday evening. The care plan covers patching, backups, uptime, small changes and a named person to call. Add security cover and you get a yearly re-assessment and a security person your customers can ask about.

You get
  • Patching and supply chain updates, with a monthly note on what changed
  • Uptime monitoring and verified backups
  • Small changes and content updates
  • Optional: fractional security cover and a yearly re-assessment
Then

Comfortable for the whole journey

Your idea, your code and your data stay yours at every stage.

You are handing a stranger an unreleased product. Here is exactly how it is handled, from the first call to the retest letter, and none of it costs you anything.

Every conversation on Helius Connect

Calls, messages, files and voice notes for the whole engagement happen on Helius Connect, my own end-to-end encrypted messenger. Keys are generated on your phone and never leave it, there is no server-side plaintext to breach or subpoena, and if encryption cannot be established nothing sends. It is free on the App Store, and you can inspect it before you trust it: it is one of the two apps on this page.

Free on the App Store

A password-protected draft site

Every website and web app is built on a private staging address behind a password, hidden from search engines, with its own test keys and no production data. You and the people you choose can watch it take shape; nobody else can find it. It goes public once, on launch day, when you say so.

Source in your repository from day one

The code lives in a GitHub organisation you own, from the first commit. I am a collaborator you can remove in one click, the history is yours, and when the engagement ends there is nothing to hand over because you already have it. App Store and Play accounts are opened in your name, never mine.

NDA first, then signed scope

I will sign your NDA before the first substantive conversation, or send you mine. Assessment work only starts under a signed scope and written authorisation, which is also what makes the report usable with insurers and customers. Contracts are with Helius Network Ltd, a UK registered company.

Secrets and customer data, handled like evidence

Credentials are never sent by email; they go through Helius Connect or a shared vault, and staging uses separate keys that are rotated at launch. Anything sensitive captured during an assessment is redacted in the report, stored encrypted on HeliusOS, and deleted after the retest unless you ask me to keep it.

The idea itself

I do not build competing products, take equity you did not offer, or reuse your brand, screens or code for anyone else. The only thing I keep is the right to say I worked with you, and only once you are public and only if you agree.

1person, so nothing is lost in handover
7stages, each with a fixed quote and an exit
2of my own apps through this exact process and live
Tell me about the idea

Rather than tell you

This page is encrypting your text right now.

Type into the panel. Your browser generates two ECDH P-256 keypairs, agrees a shared secret, derives an AES-256 key through HKDF, and seals what you wrote with a fresh nonce on every keystroke. No network calls, nothing stored, nothing simulated.

It is a small thing, deliberately. The point is that I would rather show you working cryptography than a page of adjectives about my expertise.

Free tool · no signup

Check what your website is telling attackers.

Enter an address and I will fetch it exactly as a browser would, then grade what the server sends back against OWASP, ISO 27001, PCI DSS and Cyber Essentials expectations. Results in about five seconds.

Graded against
  • OWASP Top 10 & Secure Headers
  • OWASP ASVS
  • ISO/IEC 27001:2022 Annex A 8.x
  • PCI DSS 4.0
  • NCSC Cyber Essentials
  • NIST CSF 2.0

HeliusOS · the assessment platform

The free check reads the surface. HeliusOS goes underneath.

Every paid assessment I run, on something I built for you or something you already have, runs from HeliusOS: a hardened, image-based Linux operating system I built at Helius for exactly this work. The machine that judges your product has to be more trustworthy than the product, and it has to be able to prove it. A consultant’s laptop with four hundred unvetted packages on it cannot.

CIS RHEL 10 Level 2
96.9%

374 of 386 scored rules passing, OpenSCAP

Lynis hardening index
84

a standard install usually lands near 60

SELinux
Enforcing

kernel lockdown on, inbound default deny

Automated tests
71

plus SBOM and CVE scan on every build

Measured on HeliusOS v0.1, 1 October 2026, in a virtual machine. The full OpenSCAP and Lynis reports are the evidence pack, and you can rerun them yourself. See the full HeliusOS flow.

Hardened at build, not after

A CentOS Stream 10 image built from a single definition, with the CIS Level 2 Server benchmark applied while the image is built. SELinux enforcing, kernel lockdown, a default-deny firewall, audit rules, file integrity monitoring and USB device allow-listing are in the image, not a checklist someone forgot.

Encrypted and rollback-safe

Full-disk encryption (LUKS2) sealed to the TPM, so the disk only unlocks on the hardware it was enrolled on. The root filesystem is immutable, updates are signed images verified before they apply, and a boot health check rolls back automatically if an update misbehaves.

It reports its own gaps

Its status tool says partial or not installed when something is not on, instead of a reassuring 100. The same rule applies to your report: a finding I could not verify is marked as such, and a control that works is given its due.

Evidence a sceptic can rerun

Every release ships an evidence pack: OpenSCAP report, Lynis report, software bill of materials, CVE scan and the signature verification command. Your assessment uses the same method, so your security team or an auditor can reproduce every number rather than take my word for it.

Honest about what is next. Runtime monitoring (eBPF, in preview), TPM remote attestation, a Helius-built kernel, a signed unified kernel image and eBPF-LSM policy enforcement are on the roadmap, in that order. They are described here as roadmap because they are not shipped yet.

What an assessment looks like

Twelve surfaces, one pass, nothing assumed.

The free checker above grades the headers your server publishes. A HeliusOS assessment goes through every surface an attacker would, with your written authorisation, and ends in a report rather than a score. Press run to watch the shape of one.

This is a simulation drawn on the page. Nothing is scanned, no network calls are made, and the findings are illustrative. Real assessments run only under a signed scope.

Surfaces
0/12
Checks
0
Findings
0
Report
—
heliusos · assess · scope HR-2026-041 idle
  1. Press run. The log fills in here.
  • Transport
  • Headers & CSP
  • Authentication
  • Sessions
  • Access control
  • Cryptography
  • Mobile binary
  • Dependencies
  • Secrets
  • Storage
  • AI surface
  • Infrastructure

The report

Extensive, and written to be acted on.

Typically forty to eighty pages, and the first one is the only page your board needs to read. Pick a section to see what is in it.

Security assessment reportPage 1 of 52

YourBrand: iOS app, website and backend

Authorisation
Signed scope HR-2026-041, 14 Oct 2026
In scope
iOS build 14 (TestFlight), yourbrand.com, Supabase project prod-eu-1, edge functions, AI assistant feature
Out of scope
Payment provider internals, third-party analytics, social sign-in providers
Method
Authorised grey-box assessment from HeliusOS v0.1, OWASP ASVS 4.0 level 2, MASVS, manual code review; OpenSCAP, Lynis, SBOM and CVE scan on anything you host
Window
14 to 22 October 2026 · retest 5 November

Why it matters: a report with no scope statement cannot be relied on by anyone, which is why most security questionnaires ask for this page first.

Every report is written by me, not generated. The simulation above and the sample pages are illustrative. The structure is exactly what you receive.

Free, and nothing leaves your browser

And if you have minors on your platform, so does this.

Age assurance is where the same discipline gets tested hardest, because the client is hostile and a regulator is watching. Twelve questions, about two minutes, scored against the findings actually appearing in UK and EU enforcement. Grade and gap list immediately, before you give me anything.

The scoring reflects Ofcom and ICO expectations and the Commission’s DSA guidance on minors. It is a triage tool, not legal advice, and it is deliberately strict: I would rather flag something you have already handled than miss something you have not.

Why this is urgent

And the deadlines are set by regulators, not by your roadmap.

  1. Nov 2025

    Ofcom’s enforcement powers go live. Fines up to ten percent of global turnover, or £18 million.

  2. Jan 2026

    Mandatory age assurance takes effect for age-restricted content in the UK.

  3. Mar 2026

    The Commission opens a formal investigation into a major messaging platform over under-13 access. Ofcom and the ICO issue a joint enforcement statement.

  4. Apr 2026

    The Commission preliminarily finds one of the largest social platforms in breach of the DSA over minors reaching its services.

  5. Dec 2026

    EU Member States urged to have age verification rolled out.

  6. Spring 2027

    UK enforcement begins on the under-16 social media ban announced in June 2026.

The pattern in every one of these actions is the same. The policy existed. The implementation did not hold. The tech giants being investigated do not lack lawyers, they shipped controls that failed under contact with real users. That gap is engineering work, and it is the work I do.

Live products

Download the work.

Two products through Apple review and live on the App Store. You can install them, inspect them, and see the security decisions for yourself before you hire me.

Helius Network

Social impact platform with a value ledger, age assurance and child safety controls.

React Native · Expo · Supabase · server-authoritative ledger

Download on the App Store

Helius Connect

End-to-end encrypted messenger. Keys never leave the device.

TweetNaCl · E2E encrypted media and voice · fail-closed by design

Download on the App Store

The encryption practice

HeliusOS: encrypted systems that work when the network does not.

The architecture

Keys are generated on the device and never leave it. There is no server-side plaintext to subpoena, breach or mishandle, because the server never holds the material to decrypt anything. Messages, media and voice are sealed before they reach the transport, and the system fails closed: if encryption cannot be established, nothing sends. That last decision costs you a working feature in edge cases, which is exactly why most products quietly do the opposite.

Why it is unusual

The cryptography itself is standard and deliberately so. What is uncommon is the operating envelope: this runs on mobile hardware, under React Native, across Starlink backhaul and LoRa mesh fallback, on an island where connectivity drops without warning. Most encrypted messengers are built assuming a stable network and a modern device. Ours could not be. That constraint is where the interesting engineering lives, and it is what I bring to a review of yours.

If you are building encrypted messaging, encrypted storage, or anything where key handling on a mobile device has to survive real conditions, this is the work I have spent years on.

Also building

Olo, and the Zeus verification layer.

Olo

An assistant platform that puts AI and a vetted expert community under one roof. The AI handles what it can handle. When it cannot, the question is handed to a real expert rather than answered badly with confidence. Most assistants fail quietly at the edge of their competence. Olo is built to hand over instead.

Zeus 3.0

The verification layer underneath. Claims are checked before they reach the user, and the boundary between what the system knows and what it is guessing is made explicit rather than hidden. It is the same instinct that runs through the security work: assume the confident answer is the dangerous one until something has verified it.

If you are building on top of a model and worried about what it asserts when it should not, this is the problem I have spent the past year on. Ask me about it.

Services

Cryptography first, then everything around it.

The work I am best at is where the cryptography meets the platform it has to survive on. Everything else here surrounds that. If your problem is somewhere else entirely, I will say so.

Idea to published app

Brand, website and app from one person: discovery, identity, design, build, a HeliusOS assessment of the result, App Store submission and a care plan afterwards. Each stage is fixed price with a point where you can stop. See the seven stages.

Discovery week first · then quoted per stage

HeliusOS security assessment

A full authorised assessment of your app, website and backend, run from the hardened operating system I built for the job, ending in a forty to eighty page report your engineers can act on and your board can read. What is in it.

1 to 2 weeks · report, fixes, retest letter

Cryptography implementation and review

End-to-end encrypted messaging, key exchange and rotation, encryption at rest, media and voice handling. Most failures I find are not broken primitives. They are correct primitives wired up wrongly, or a library that behaves differently on device than it does in your test suite.

5 to 10 days · or ongoing retainer

Age assurance and child safety systems

Design and review of age verification, minor-safety controls, and platform integrity, built for real regulatory pressure rather than a policy page. I have implemented this, not only advised on it.

5 days design review · longer if building

Mobile application security review

iOS and React Native. Key storage and keychain use, certificate handling, deep link and IPC surface, what the binary leaks, and what the app actually sends when you watch the traffic rather than read the docs.

4 to 8 days · written report and a working session

Fractional CTO and security leadership

The technology function without a full-time hire. Architecture and threat modelling, build versus buy calls, vendor selection, hiring and technical interviewing, security questionnaires answered properly, and translating all of it for a board that does not speak engineering. Eleven years doing the job, not advising on it from outside.

Two to six days a month · ongoing

Supabase and backend security review

Row Level Security that does not do what the team believes it does. Service role keys reachable from the client. Edge functions trusting input they should not. Storage buckets open to anyone holding a URL. These are the failures I find most often in startups built on Supabase or Firebase, and they are usually invisible until someone looks specifically. Run the free Supabase check.

3 to 6 days · policy-by-policy review

AI feature security review

You shipped a model into your product. Now: what can a user make it say, what tools can they reach through it, what leaks into the context window, and what happens when it answers confidently and wrongly. Prompt injection, tool-use boundaries, data exposure, and the verification layer that should sit between the model and the user.

4 to 8 days · adversarial testing and written findings

Website security audit

Headers, transport, authentication, exposed endpoints, dependency and supply chain risk, form and upload handling, and what your third-party scripts are quietly doing. You get a prioritised list you can hand straight to a developer, not a scanner dump.

Fixed price · report within five working days

Websites built and maintained

Fast, accessible, secure by construction. No page builder bloat, no third-party scripts you did not ask for. Then a care plan afterwards: patching, dependency updates, uptime, backups, and someone who answers when something breaks at an inconvenient hour.

Project fee · then monthly care plan

Track record

What broke, what I did, what happened.

Specifics, because in this field the detail is the credential. These are systems I designed and built, not slides about them.

Helius Connect

Approved on the App Store

Encrypted messenger · React Native, Expo SDK 52, Supabase

The problem

End-to-end encryption passed every test in development and failed silently on device. Voice notes arrived corrupted. Apple rejected the build repeatedly.

What I did

Traced the failure to Web Crypto under Hermes and rebuilt the entire E2E layer on TweetNaCl. Found a buffer-aliasing bug corrupting audio in transit, and replaced the Supabase client for binary upload with direct FileSystem.uploadAsync.

Outcome

v1.0 approved and live. Encryption verified working on real devices, not just in CI.

Helius Network

Approved on the App Store

Social impact platform with a token ledger and minors on the platform

The problem

A platform carrying both a value ledger and under-18 users. Two things you cannot get wrong, and a client you must assume is hostile.

What I did

Built age assurance and child safety infrastructure, moved the entire earnings ledger server-side behind edge functions, locked the trust and identity model against client writes, and added anti-inflation controls so engagement cannot be manufactured.

Outcome

Approved and live. Seven automated audit scripts now gate every release.

Helius Mesh

Licence application with the regulator

WiFi-first Caribbean ISP · Starlink backhaul, LoRa mesh fallback, wholesale eSIM

The problem

Reliable connectivity across an island where the incumbent infrastructure fails in weather.

What I did

Designed the network and took it into a formal licence application with the Public Utilities Commission of Anguilla.

Outcome

Application live with the regulator. Evidence I can build inside a compliance regime and answer to a regulator, not only to a product manager.

Helius Impact Intelligence

Built and deployed

B2B SaaS platform · TypeScript, Vite, React, Tauri, Supabase

The problem

Organisations needed to report verified impact to funders without hand-assembling every deck.

What I did

Built the platform end to end: Stripe billing, six edge functions, export workers, and a versioned public REST API with the authentication and rate limiting that implies.

Outcome

Deployed, with a desktop wrapper for offline use.

About

I did not arrive at security through a certificate.

I arrived by shipping things, watching them break in ways the documentation did not predict, and having to understand the cryptography properly to fix them.

Eleven years as Chief Technology Officer at Versatech and Associates in Anguilla, and founder and CTO of Helius Network Ltd in the United Kingdom. I am most useful to teams who need someone who can read the code, argue with the architecture, and then write the finding up so a non-technical board can act on it.

I work from Anguilla, four hours behind London and one ahead of New York. In practice that means a London afternoon call and a New York morning call fit in the same day.

Kokorozashi. Purpose held steadily enough that the work and the life point the same way.

The idea I build everything against
Qualification NCFE Level 3 Certificate in Cyber Security Practices, Ofqual regulated. Distinction.
Reading BSc (Hons) Design Engineering, The Open University. Completing November 2026, currently on web technologies and security.
Also Project Management, Distinction. Level 6 solar PV, European Energy Centre.
Service Director and Chairperson of Public Image, Rotary Club of Anguilla, 2026 to 2027. Also active with the Red Cross and MASA.

Engage me

Clear pricing, because opaque pricing wastes your time and mine.

Fixed-price where the scope is knowable. Monthly where the value is ongoing. Day rate for everything else.

Fixed scope

Website security audit

US$950

Headers, transport, auth, endpoints, dependencies, third-party scripts. Prioritised findings within five working days.

Book for US$950Secure checkout by Stripe

Fixed scope

App Store rejection rescue

US$1,500

Your build was rejected and you do not know why. I have been through the cycle repeatedly and got two apps approved. Diagnosis, fix plan, and the resubmission language.

Book for US$1,500Secure checkout by Stripe

Most requested

Age assurance readiness assessment

from US$6,500

Everything the free check flags, verified against your actual implementation rather than your answers. Adversarial testing of the gate, a prioritised remediation plan, and an evidence pack you can hand a regulator.

Pay the US$3,250 deposit50% to start, final price confirmed before work begins

Fixed scope

Mobile app security audit

from US$3,500

Full review of an iOS or React Native app. Key storage, cryptography, transport, deep link and IPC surface, what the binary leaks. Written report and a working session with your engineers.

Pay the US$1,750 deposit50% to start, final price confirmed before work begins

Fixed scope

Supabase security review

from US$2,800

Every RLS policy tested against the access it actually permits, key handling traced from client to database, edge functions and storage rules reviewed. Findings with the SQL to fix them. Run the free check first.

Pay the US$1,400 deposit50% to start, final price confirmed before work begins

Fixed scope

Technical due diligence

from US$5,000

For investors and acquirers. An honest read on a target’s architecture, security posture, key-person risk and what the technical debt will cost to service. Delivered before you wire the money, not after.

Pay the US$2,500 deposit50% to start, final price confirmed before work begins

Idea to published app

Discovery week

US$2,500

Five days. Product brief, threat model, architecture and a fixed quote for brand, design, build, assessment and launch. If we stop there, you keep everything.

Start Discovery: US$1,250 deposit50% to start, balance on delivery

Project

Website built

from US$4,500

Designed, built, and shipped. Fast, accessible, no page builder bloat, no third-party scripts you did not ask for. This site is the sample.

Pay the US$2,250 deposit50% to start, final price confirmed before work begins

Monthly

Care plan

US$350 / month

Patching, dependency and supply chain updates, uptime and backups, small changes, and someone who answers when it breaks at an inconvenient hour.

Subscribe for US$350 a monthCancel any month

Monthly

Fractional security cover

from US$3,500 / month

Two days a month of security only. Architecture review, threat modelling, vendor questionnaires, and a named security person your customers can ask about.

Subscribe for US$3,500 a monthBilled monthly

New · for AI-built apps

AI-built app security check

US$595

Built with Lovable, Bolt, Cursor or Supabase? Row level security, auth and storage rules, keys exposed in the frontend, and prompt injection in your AI features. A written report with the fix for every finding, within 72 hours.

Book for US$595Paid upfront. Only apps you own and authorise in writing

EU Cyber Resilience Act

CRA readiness kit

£299

Eight editable documents: applicability and class check, the 24 hour reporting runbook and templates, disclosure policy, SBOM guide, support period and the Annex I and Annex VII checklists. Download straight after payment.

Buy the kit for £299Or done with you: £1,500, £750 deposit

For agencies · monthly

Security on call

from £500 / month

A white-label security partner for studios. Pre-launch reviews of your client releases, reported under your brand. Essential: up to two reviews a month, three working day turnaround. Partner (£800): up to four, 48 hours, and a monthly call.

Start Essential, £500Or Partner, £800 a month

The whole technology function

Fractional CTO

Senior technology leadership without the US$300,000 salary, equity, recruiter fee and mis-hire risk. Eleven years doing the job across two companies, with products through App Store review and a national regulator. Priced by how much of me you actually need.

AdvisoryAbout 2 days a monthStart Advisory
US$3,000/ month
EmbeddedAbout 1 day a weekStart Embedded
US$7,500/ month
ScalingAbout 2 days a weekStart Scaling
US$13,500/ month

Three month minimum. Nothing useful happens faster than that. Billed monthly through Stripe.

Every engagement includes
  • A weekly standing call with you, plus asynchronous access in between
  • Architecture ownership: system design, build versus buy, and the trade-off written down so the decision survives you changing your mind
  • Technical roadmap tied to your commercial plan, not a wishlist
  • Code and security review of what your team ships
  • Hiring: job specs, technical interviews, and an honest read on candidates
  • Vendor and contract review, including security questionnaires answered properly
  • Board and investor material translated out of engineering and into English
  • A named technical leader your customers, insurers and auditors can ask about
Not included
  • Full-time availability or on-call. I am fractional, and pretending otherwise fails both of us
  • Production feature delivery. I review, architect and unblock. Sustained implementation is quoted separately
  • Equity-only arrangements. A reduced retainer alongside equity is negotiable, equity instead of a retainer is not
US$500 per day Pay for agreed days

Anything outside those shapes bills at the day rate, and fixed-scope work is quoted up front from it, so you always know the number before anything starts.

  • Invoiced by Helius Network Ltd, a UK registered company. No employer of record needed, and procurement can onboard me as a vendor.
  • Half-day calls available for architecture reviews and second opinions.
  • Happy to sign your NDA before the first substantive conversation.
  • Anguilla based, UTC minus 4. A London afternoon call and a New York morning call fit in the same day.

Start a conversation

Tell me what you are building and what worries you about it. If I am not the right person, I will tell you that quickly and point you somewhere better.

Or email hashim@heliusnetwork.com, or message me on LinkedIn.

I reply within one business day.