Sahil Mittu

I find what breaks AI-built apps and slow SQL systems, before your customers do.

Built your app with Antigravity, Cursor, Lovable or Bolt, or running a database that reports slowly or "too clean"? I review the code, test every key flow and give you a plain-English fix list. 11+ years building and testing enterprise software.

Taking projects now: a few audit slots and one monthly QA retainer.

AUD-003 · Critical

SQL is built by joining strings, so input can change the query

Steps to reproduce
Call the search endpoint with status=x' OR '1'='1 on a test database. Every order comes back.
Fix
Parameterized queries, allowed-value checks and a least-privilege database login.

This is how every finding in my reports reads: where, how to reproduce, why it matters, how to fix. Example from a sample report.

Services

Fixed scopes and written quotes. Tell me what you need and I will send a price before any work starts.

AI-built app audit

Code review, full manual test pass, security basics and a prioritized report with screenshots and steps to reproduce. A walkthrough call and one retest are included.

SQL Server tuning and data checks

Slow queries and stored procedures, indexing, data cleanup, migrations and reconciliation checks, with measured before and after results.

Part-time QA lead

Test plans, regression and exploratory testing, bug triage and release sign-off, as a monthly retainer or per release.

Claude and Gemini integration

One practical AI feature or workflow added to your app, with fallbacks, logging, cost limits and tests.

Release automation with Ansible

Templates, inventories and config-driven deployments for application teams, so releases are repeatable and manual errors drop.

Projects

Personal projects I designed and built myself.

Personal project

Autonomous social marketing pipeline

An engine that uses Google Gemini to write product campaigns and publishes them through the Meta Graph API. I built a prompt-packaging and context-parsing workflow to keep token use down, and checked the REST and SOAP feeds with SoapUI.

I verified output on web and mobile for layout, attribution tracking and link behavior.

It includes a short-link service I built on Cloudflare Workers, which creates social link previews and sends readers on to the destination page.

See it running on its public Facebook page (posts contain affiliate links).

Python, Gemini API, Meta Graph API, Cloudflare Workers, REST, SoapUI

Personal engineering project

Low-latency market-data and order engine

An event-driven Python application that handles live price ticks and order dispatch with asyncio and WebSockets. It has multi-broker authentication (TOTP and OAuth2), risk controls, an SQLite telemetry store and a desktop analytics screen.

Python 3.12, asyncio, PyQt6, SQLite. Engineering showcase only; not investment advice or a product for sale.

Work you can check

Both pieces below are built so you can see how I think. Neither is a client project.

Lab case study · synthetic data

A reconciliation report that said "0 missing" while thousands were missing

On a 5-million-row ledger, one NOT IN and a few NULLs hid every ledger-only record. The same job also scanned both tables because of a date function and a text-type mismatch.

I show the fix, the scripts, and a row-by-row check that proves the new query matches the old one where it should.

Ask for the case study
Worked sample · fictional app

A full audit report for a meal-subscription app

Fifteen findings from critical to low: customers reading each other's orders, prices accepted from the browser, exposed secrets and duplicate payments. Each has a fix and a ready prompt for your AI tool.

It shows what you receive: summary, findings, action plan and retest terms.

Ask for the sample report

How it works

Four steps, all in writing.

  1. Share the problemSend the app link, repo or the slow query. A short call if needed.
  2. Get a fixed quoteScope, price, timeline and an NDA before I touch anything.
  3. Receive the reportPrioritized findings, evidence and fixes, with a walkthrough call.
  4. Fix and retestI retest the critical items and confirm what is closed.

About

I'm Sahil. For 11+ years I have built, led and tested enterprise software, with a focus on data accuracy, SQL performance and release quality. I led a development team through Agile releases and received several Star Performer awards. My M.Tech thesis and a 2015 conference paper were on information security.

Today I work with founders and small teams. I use AI development tools myself, so I know where they go wrong, and I test the output the way a QA lead would.

A review like this is a quality check with security basics. It is not a penetration test or a security certification, and I say so in every report.

  • MS SQL Server and C#
  • M.Tech, Computer Science & Engineering
  • Manual and automated testing, code review
  • Claude and Gemini API integrations
  • Python automation and AI pipelines, built with AI-assisted tools and tested
  • Ansible: templates, inventories, config-driven deployments
  • NDA on request; staging data preferred

Send me your app link or your slow query

I'll reply with how I would approach it and, where possible, the first issues I would check.