Architected and engineered an enterprise-grade multi-tenant, multi-warehouse B2B SaaS platform powering point-of-sale (POS), procurement, inventory control, automated billing, and ledger accounting with strict organization-level data isolation.
Key Impact & Engineering
Architected a 'Two-Lock Door' authorization engine decoupling Subscription Entitlements (Limit Engine) from Enterprise RBAC across 50+ protected REST API routes with sub-millisecond permission checks and zero-downtime instant revocation.
Cut API latency from 7s–9s to 300–800ms (and repeat lookups to 1–20ms) using a dual-layer waterfall cache (L1 In-Memory LRU <1ms + L2 Remote Redis) backed by a Promise Coalescing Stampede Shield preventing thundering herd database overload.
Engineered an append-only immutable StockMovement accounting ledger tracking Purchase, Sale, Return, Adjustment, and Multi-Warehouse Transfer operations with zero-ghost immutability.
Built an ACID-compliant POS checkout & revision pipeline using MongoDB $session transactions for split payments, atomic stock deductions, and strict bounds checking preventing overselling.
Integrated Razorpay subscription billing with a deterministic state machine, HMAC-SHA256 webhooks, automated PDF invoice generation, and an institutional Tally Prime XML export engine for CPA balance-sheet reconciliation.
Designed a direct-to-cloud media upload pipeline using HMAC-SHA1 signatures and client-side HTML5 canvas interception, compressing 5MB smartphone photos down to ~150KB WebP assets before transit.
Developed real-time cross-device & tab synchronization via browser BroadcastChannel API and tab-visibility heartbeat polling (/api/v1/sync/version), eliminating stale state without hard refreshes.
Built serverless background worker queues and cron endpoints for Redis Audit Log Flushing, Subscription Expiration Sweeping (with Redis mutex locks), and Nightly MongoDB Aggregation Usage Reconciliation.
Engineered an automated Fraud & Anti-Abuse engine featuring O(1) Redis Token Bucket velocity tracking, disposable email domain filtering, and a Mongoose Change Data Capture (CDC) audit system pushing pre-mutation snapshots to a Redis Outbox (batch-processed at 1,000 logs/batch).