Mumbai, India · Available for new work

Vatsal
Soni.

I build |

Senior Full Stack Developer with 4+ years shipping NDA-bound, compliance-grade products for media, fintech and e-commerce — and the person who also racks, configures and secures the server they run on.

  • 4+years of professional experience
  • 5companies & clients served
  • 99%+production uptime on AWS / GCP
  • 5+apps shipped from greenfield (3 Minds)
  • Tier 1brand — Jio Creative Labs

01 / About

Frontend craft. Backend rigour. Infrastructure ownership.

I'm a full stack developer who is comfortable at every layer of a product — from a GSAP scroll timeline in the browser, to an encrypted data pipeline in the API, to the EC2 instance or in-house server it all runs on.

My work has been for a Tier 1 media brand, government-linked e-commerce, fintech and enterprise clients, so I'm used to NDAs, security reviews, compliance requirements and stakeholders from Security, Architecture and Network Ops.

I'm trusted with direct client communication — gathering requirements, presenting progress, and turning business needs into technical specs — and I like owning a product from first call to production deployment.

✦

Rare frontend depth

Advanced GSAP animation, 3D integrations and performance-minded interfaces that still ship on schedule.

⚙

Robust backends

REST APIs with Node and Express, JWT auth, validation, SQL and NoSQL data layers.

☁

Hands-on cloud

AWS & GCP provisioning, repeatable infra patterns, 99%+ uptime — plus a self-hosted stack I run myself.

⚑

Product ownership

Solo delivery, client relationships and deployment owned end to end, under NDA and on deadline.

02 / What I do

Four areas I can take off your plate

01

Frontend & Motion

Responsive, accessible interfaces in React and Next.js with TypeScript. Scroll-driven GSAP experiences, 3D elements, and state management with Redux Toolkit & RTK Query.

ReactNext.jsGSAPMUISCSS

02

Backend & APIs

Clean REST APIs, role-based dashboards, real-time features via Pusher, file uploads, validation with Joi/YUP, and SQL/NoSQL modelling with Sequelize and Mongoose.

Node.jsExpressMySQLMongoDBJWT

03

Cloud & Self-hosting

AWS (EC2, RDS, S3, Route 53, IAM, Elastic IP) and GCP deployments, PM2 & CertBot setups — and full self-hosted stacks with Ubuntu, Coolify, Garage S3 and Cloudflare Zero Trust.

AWSGCPCoolifyCloudflareUbuntu

04

Security & Compliance

AES-encrypted data pipelines, automated data purging for retention policies, identity-gated access with Cloudflare Access, and coordination with Security & Compliance teams.

AESData purgingZero TrustreCAPTCHA

03 / Featured build · Infrastructure

An in-house server for our internal CRM

I set up and run the entire local server that hosts the company's internal CRM — from the bare Ubuntu install to identity-gated public access — and I also test the CRM running on it. Click through the layers below.

Traffic flows from the user or AI test agent through Cloudflare Access and a Cloudflare Tunnel into the Ubuntu server running Coolify, the CRM, Garage S3 and the Garage UI. Internetstaff · AI test agent Cloudflare AccessService Auth policyEmail allow policyidentity checked first Tunnelroute → service Ubuntu server · in-house Coolifydeploys & manages apps Internal CRMthe app being tested GarageS3 buckets Garage UIcustom · SSO-gated no inbound ports opened

    Custom Garage UI — two Cloudflare Access policies

    Garage doesn't ship with the login experience I wanted, so I built my own UI for it and put it behind Cloudflare-style SSO. Two policies cover the two kinds of callers:

    Policy 1

    Service Authentication

    For non-human clients. A service presents its credentials with the request and Cloudflare Access validates them at the edge — no interactive login. This is the path that let me authenticate an AI model against the protected routes to test the CRM.

    • Machine-to-machine access
    • Credentials checked before the request reaches the server
    • Revocable without touching the app
    Policy 2

    Email Allow

    For people. Only email addresses on the allow-list can sign in; everyone else is stopped at Cloudflare and never sees the Garage UI or the CRM.

    • SSO-style login for staff
    • Explicit allow-list of identities
    • One consistent login across tools

    How I tested the CRM with an AI model

    1. 1

      Create a tunnel route

      Expose the CRM through Cloudflare Tunnel on a dedicated hostname.

    2. 2

      Protect the access point

      Attach an Access application and validate who is allowed through.

    3. 3

      Authenticate the AI model

      Use an access code / service credential so the model passes the Service Auth policy.

    4. 4

      Test & iterate

      Exercise CRM flows through the real, protected route and fix what breaks.

    04 / Experience

    Career timeline

    1. Jun 2024 — PresentMumbai · Contractcurrent

      Full Stack Developer · Jio Creative Labs

      Tier 1 media brand. NDA-bound work with UI/UX, Art, Security, Compliance, Architecture and Network Ops teams.

      • Architected and shipped 2 NDA-bound full stack applications end-to-end — immersive, responsive, visually rich experiences delivered on schedule.
      • Engineered AES-encrypted data pipelines with automated purging, meeting data-retention, privacy and regulatory standards across multiple governance frameworks.
      • Owned cloud infrastructure on AWS and GCP (EC2, RDS, S3, Route 53, Elastic IP), sustaining 99%+ production uptime.
      • Built jiocreativelabs.com with advanced GSAP scroll animations and integrated 3D elements.

      ReactNode.jsGSAP3DAESAWSGCP

    2. Jan 2024 — Jun 2024Mumbai · Contract

      Full Stack Developer · Finnowski

      Government-linked e-commerce enablement platform, delivered solo under strict NDA in a 6-month contract.

      • Delivered a full-featured vendor dashboard: product catalogue management, real-time order tracking and core seller operations.
      • Owned the whole stack alone — Next.js + MUI frontend; Node.js, Express, REST API and MySQL backend.

      Next.jsMUINode.jsExpressMySQL

    3. Nov 2022 — Dec 2023Mumbai

      Full Stack Developer · 3 Minds Digital

      Agency delivery with close client collaboration and weekly feedback loops.

      • Delivered 5+ web and mobile applications from greenfield with React, Node.js, MongoDB and MySQL — each on deadline.
      • Spearheaded AWS deployments (EC2, S3, Route 53, RDS) across multiple production environments, establishing repeatable patterns that cut setup time on each successive project.
      • Designed RESTful APIs with Express, Sequelize and Mongoose; active in code reviews, debugging sessions and architecture planning.
      • Ran direct client channels: requirements, progress demos and translating business needs into technical specs.

      ReactNode.jsMongoDBMySQLAWSSequelize

    4. Jul 2022 — Oct 2022Mumbai

      Web Developer · Aurus IT Solutions

      • Built interactive HTML/CSS/JavaScript prototypes for client presentations and integrated third-party APIs to extend platform functionality and improve user engagement.

      HTMLCSSJavaScriptREST APIs

    5. Jun 2021 — Jun 2022Mumbai

      MERN Stack Developer · Contriver Tech

      • Independently built full stack MERN applications, developing strong product-ownership instincts alongside cross-functional collaboration.

      MongoDBExpressReactNode.js

    05 / Projects

    Selected work

    06 / Skills

    Technical toolbox

    Frontend

    React.jsNext.jsTypeScriptGSAPRedux ToolkitRTK QueryMUIBootstrapSass/SCSSYUP

    Backend

    Node.jsExpress.jsREST APIMySQLMongoDBSequelize ORMMongooseJWTBcryptPusherMulterJoiStrapi CMS

    Cloud & DevOps

    AWS EC2S3Route 53RDSIAMElastic IPGCPAzurePM2CertBotreCAPTCHA

    Self-hosting & Zero Trust

    Ubuntu ServerCoolifyGarage S3Cloudflare TunnelCloudflare AccessService Auth / Email policies

    Security & Other

    AES encryptionCompliance systemsAutomated data purgingDrupal CMSStakeholder managementClient communication

    Education

    2021 – 2022

    Master of Computer Applications

    TIMSCDR, Mumbai University

    CGPA 8.7 / 10

    2017 – 2020

    BSc Information Technology

    UPGASC

    CGPA 7.46 / 10

    07 / Contact

    Let's build something.

    Open to full stack, frontend-animation and cloud / self-hosting work. Reach out and I'll reply quickly.