$ whoami
Sergey Zakharevich — Senior Backend Developer & Software Architect
$ cat about.txt
8+ years designing, building and scaling secure, high-load web applications.
Architect on several projects: system design, stack selection, key technical decisions.
Security by design: payments, banking and real-money gaming taught me to build safe systems from day one.
AI integrations: OpenAI, Claude and Gemini inside real business products.
$ cat domains.txt
iGaming (sportsbook, casino, poker) · FinTech & banking · Crypto payments · E-commerce · Healthcare · Media
$ status
Open to remote opportunities — full-time and contractAlso: Laravel Nova · OctoberCMS · Beanstalkd · Memcached · Apache · REST · GraphQL · PHPUnit · Pest · PHPStan · Rector · CI/CD
I build LLM-powered features into products and use AI-assisted development daily for prototyping, refactoring and tests — so I can focus on architecture, security and quality.
Modular security for Laravel Nova: start with the core and add only the modules you need. Available on Nova Packages and Packagist.
| Package | What it does |
|---|---|
| 🛡️ nova-aegis | Core suite: hardens sessions, passwords and HTTPS, security checks, composer audit, exposed files, open ports and expiring TLS |
| 🔐 nova-aegis-admin-ip-access | Opens Nova only to whitelisted IPv4/IPv6 addresses and CIDR subnets |
| 🚫 nova-aegis-ip-blocker | Blocks listed IPs and subnets from the whole application |
| 🚦 nova-aegis-smart-ip-blocker | Rate-limits every IP and bans abusers with 429 and Retry-After |
| 🧱 nova-aegis-csp | Content-Security-Policy for the site and Nova, edited per directive |
| 🧹 nova-aegis-input-sanitizer | Blocks XSS, template and command injection, path traversal and null bytes |
The same security toolkit for October CMS, published on the October CMS Marketplace.
| Plugin | What it does |
|---|---|
| 🛡️ oc-fortify-plugin | Core suite: system diagnostics, vulnerability checks, protection tools |
| 🧱 oc-fortify-csp-plugin | Content Security Policy headers against XSS and data injection |
| 🧹 oc-fortify-input-sanitizer-plugin | Sanitization of user input against XSS and injection |
| 🔐 oc-fortify-admin-ip-access-plugin | Admin panel access restricted to whitelisted IPs |
| 🚫 oc-fortify-ip-blocker-plugin | Manual blocking of specific IP addresses |
| 🚦 oc-fortify-smart-ip-blocker-plugin | Automatic blocking of IPs that exceed a request rate — against brute-force and traffic abuse |
| 🧰 oc-ide-helper | Better IDE autocompletion for October CMS projects |
Quality bar for every Aegis and Fortify module: PHPStan at max level · Pest with 90% coverage · Rector · PHP CS Fixer · Docker toolchain · GitHub Actions CI with automated releases to the marketplace.
Code: KISS · DRY · YAGNI · SOLID · clean, readable, maintainable code
Architecture: separation of concerns · loose coupling · idempotency · scalability first
Security: security by design · least privilege · defense in depth · never trust user input
Delivery: tests before refactoring · code review · automate everything (CI/CD)




