Skip to main content
Pashyaa Technologies Pashyaa Technologies
Menu

Work

Three enterprise platforms, and one we run ourselves

Client names are withheld — enterprise agreements generally prohibit naming them in marketing without written consent. The engagements below are described accurately in every other respect.

Client engagements

Enterprise Java, REST APIs and microservices work

Cross-border VAT Compliance Platform

Context
A cross-border VAT compliance and reporting platform for multinational enterprises, processing financial transaction data sourced from enterprise SAP systems.
Pashyaa’s role
Senior backend engineering on Spring Boot microservices, REST APIs, Hibernate/JPA data access and PostgreSQL optimization for high-volume VAT processing.
Stack
Java Spring Boot microservices REST APIs Hibernate/JPA PostgreSQL optimization JUnit GitLab CI

Engagement history independently verifiable through Upwork.

Global Partner & Retailer Portal

Context
A global agri-nutrition multinational’s B2C partner and retailer portal, spanning web, Android, iOS and desktop.
Pashyaa’s role
Full-stack engineering including Spring Boot REST APIs, NestJS middleware, third-party integrations, testing and SonarQube remediation.
Stack
Java 8 Spring Boot REST APIs NestJS middleware PostgreSQL SonarQube remediation CircleCI

Engagement history independently verifiable through Freelancer.

US Pharmacy Benefits Platform

Context
A US pharmacy benefits platform where the engineering work supported benefit eligibility, prescription and pharmacy-service workflows.
Pashyaa’s role
Spring Boot APIs and microservices, Kafka-driven asynchronous workflows, third-party integrations and security improvements across backend services.
Stack
Java Spring Boot Microservices REST APIs Kafka Security hardening

Delivered through a partner vendor.

Independently verifiable client history

Selected historical engagements have independently verifiable client history through platforms such as Upwork and Freelancer. The first two engagements above were contracted through those platforms, where the work history and client feedback are recorded by the platform rather than written by us. The third was delivered through a partner vendor, so it carries no platform record and is marked differently for that reason.

Production proof

InfoYog — an AI assistant we designed, built and operate

InfoYog is Pashyaa’s production proof of applied AI engineering: a retrieval-backed assistant designed, built and operated on Java 21 and Spring Boot 3.x. It shows how we integrate AI into a Java/Spring system — retrieval architecture, authentication and data boundaries, testing, cost control and production deployment.

Retrieval, not just a prompt

Answers are grounded in a corpus stored in PostgreSQL with pgvector, so retrieval and vector search live in the same database as the rest of the application rather than in a separate vector service. One datastore, one backup story, one set of credentials to protect.

The hard part was never the embedding call. It was deciding what belongs in the corpus, and keeping what the retriever can reach aligned with what the assistant is allowed to say.

Answer routing

Not every question should be answered from the corpus. InfoYog routes between retrieval-grounded answers and web-backed answers depending on whether the retrieved context actually supports the question being asked.

A retrieval system that answers confidently from weak context is worse than one that declines and goes elsewhere. Most of the engineering effort went into that judgment.

Authentication and data boundaries

Authentication runs through Firebase Auth; credentials and API keys live in Secret Manager, never in configuration files or the container image.

The retrieval boundary is treated as a security boundary: what the model can reach is scoped deliberately, because an assistant with broad read access is an exfiltration path waiting to be found. This is the same review we sell as our LLM/RAG Integration Security Design Review.

Testing and log-based QA

The backend is covered by automated tests, and answer quality is checked through log-based QA: reviewing what the system actually did, rather than relying on spot checks.

Cost-aware token usage

Token consumption is treated as an engineering constraint, not an afterthought. Cost-aware refinements have reduced per-query token consumption.

Multilingual, on Android and web

InfoYog supports English, Hindi and Marathi, and ships to Android and the web from a single Flutter codebase, served by REST APIs on the Spring Boot backend.

Deployment & clients

The backend runs on GCP App Engine against Cloud SQL. The client is a single Flutter codebase shipping to Android and the web, with Firebase Analytics and Crashlytics for release health. Pashyaa builds, deploys and operates the product in-house.

Stack
Java 21 Spring Boot 3.x REST APIs PostgreSQL + pgvector RAG answer routing Flutter (Android + Web) GCP App Engine Cloud SQL Secret Manager Firebase Auth Firebase Analytics Crashlytics

Ongoing research

Insecure Lab — application and AI security writing

Insecure Lab is where we publish application and AI security research: prompt injection, RAG security, MCP security, and the OWASP LLM and Agentic Top 10.

It is not a product and we do not sell it. It is how we stay current on the failure modes we are hired to prevent — and it is public, so you can read the thinking before you hire us.

Topics covered

  • Prompt injection
  • RAG security
  • MCP security
  • OWASP LLM Top 10
  • OWASP Agentic Top 10

Want this kind of work on your system?

Tell us about the application. Most engagements start with a modernization assessment or a defined workstream.